""ET TROJAN ELF/lizkebab CnC Activity (Flooding 1)""

SID: 2022213

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2015_12_03, updated_at 2015_12_03

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "|20|Flooding|20|"

  • Value: "|20|for|20|"

  • Value: "|20|seconds."

Within:

PCRE: "/(?:JUNK|HOLD) Flooding (?:\d{1,3}.){3}\d{1,3} for \d+ seconds.\r?\n/"

Special Options:

source