""ET TROJAN Parallax CnC Activity M10 (set)""

SID: 2030180

Revision: 2

Class Type: trojan-activity

Metadata: affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2020_05_18, deployment Perimeter, signature_severity Major, updated_at 2020_05_18

Reference:

  • md5

  • 9d60d8928bc0478b3029e59024b5f407

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "|29 f5 98 f5|" Depth: 4

  • Value: "|65 b3 b3|"

Within: 3

PCRE:

Special Options:

  • fast_pattern

source