""ET TROJAN Backdoor.Win32.DarkComet Screenshot Upload Successful""
SID: 2021996
Revision: 1
Class Type: trojan-activity
Metadata: created_at 2015_10_23, updated_at 2015_10_23
Reference:
-
md5
-
38abba51bdf98347fc4f91642b21b041
Protocol: tcp
Source Network: $HOME_NET
Source Port: any
Destination Network: $EXTERNAL_NET
Destination Port: any
Flow: established,to_server
Contents:
- Value: "ENDSNAP"
Within:
PCRE:
Special Options: