""ET TROJAN Backdoor.Win32.DarkComet Keepalive Outbound""

SID: 2023091

Revision: 1

Class Type: trojan-activity

Metadata: affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2016_08_25, deployment Perimeter, performance_impact Low, signature_severity Major, updated_at 2016_08_25

Reference:

  • md5

  • d4f949f268d00522cfbae5d18cbce933

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: to_server,established

Contents:

  • Value: "KEEPALIVE" Depth: 9

Within:

PCRE: "/^KEEPALIVE\d+$/"

Special Options:

source