""ET TROJAN Possible Duqu 2.0 Accessing SMB/SMB2 Named Pipe (Unicode) 4""

SID: 2021239

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2015_06_10, updated_at 2015_06_10

Reference:

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: any

Destination Port: [139,445]

Flow: to_server,established

Contents:

  • Value: "SMB" Depth: 3 Offset: 5

  • Value: "|00|{|00|6|00|C|00|5|00|1|00|A|00|4|00|D|00|B|00|-|00|E|00|3|00|D|00|E|00|-|00|4|00|F|00|E|00|B|00|-|00|8|00|6|00|A|00|4|00|-|00|3|00|2|00|F|00|7|00|F|00|8|00|E|00|7|00|3|00|B|00|9|00|9|00|}"

Within:

PCRE:

Special Options:

  • nocase

source