""ET TROJAN Parallax CnC Activity M9 (set)""

SID: 2030027

Revision: 1

Class Type: trojan-activity

Metadata: affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2020_04_25, deployment Perimeter, malware_family Parallax, signature_severity Major, updated_at 2020_04_25

Reference:

  • md5

  • 1b3f8c92d5d1ace34fa4dc2dd80c3eb7

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "|a5 20 94 f5|" Depth: 4

  • Value: "|6d 54 21|"

Within: 3

PCRE:

Special Options:

  • fast_pattern

source