""ET TROJAN Possible BlackEnergy Accessing SMB/SMB2 Named Pipe (Unicode)""

SID: 2021180

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2015_06_04, updated_at 2015_06_04

Reference:

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: any

Destination Port: [139,445]

Flow: to_server,established

Contents:

  • Value: "SMB" Depth: 3 Offset: 5

  • Value: "{|00|A|00|A|00|0|00|E|00|E|00|D|00|2|00|5|00|-|00|4|00|1|00|6|00|7|00|-|00|4|00|C|00|B|00|B|00|-|00|B|00|D|00|A|00|8|00|-|00|9|00|A|00|0|00|F|00|5|00|F|00|F|00|9|00|3|00|E|00|A|00|8|00|}"

Within:

PCRE:

Special Options:

  • nocase

source