""ET TROJAN Win32/Ficker Stealer Activity M2""
SID: 2031131
Revision: 1
Class Type: trojan-activity
Metadata: attack_target Client_Endpoint, created_at 2020_10_28, deployment Perimeter, performance_impact Low, signature_severity Major, updated_at 2020_10_28
Reference:
Protocol: tcp
Source Network: $EXTERNAL_NET
Source Port: any
Destination Network: $HOME_NET
Destination Port: any
Flow: established,to_client
Contents:
- Value: "|04 19 00 00 00 1a 00 00 00 17 25 75 73 65 72 70 72 6f 66 69 6c 65 25 5c 44 6f 63 75 6d 65 6e 74 73 00 00 00 08 55 54 43 2d 2d|" Depth: 42
Within:
PCRE:
Special Options: