""ET TROJAN TinyLoader.B1 Sending Processes""

SID: 2020852

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2015_04_08, updated_at 2015_04_08

Reference:

  • md5

  • bd69714997e839618a7db82484819552

Protocol: udp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow:

Contents:

  • Value: "Sy|5c|"

  • Value: "wininit|5c|"

  • Value: "winlogon|5c|"

Within:

PCRE:

Special Options:

source