""ET TROJAN Win32/Agent.RTQ CnC Activity""

SID: 2034193

Revision: 1

Class Type: trojan-activity

Metadata: affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2021_10_15, deployment Perimeter, performance_impact Low, signature_severity Major, updated_at 2021_10_15

Reference:

  • md5

  • 1f2d30b383d332972d8a36b23d1d726e

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "|0b 00 00 00|" Depth: 4

  • Value: "|57 69 6e 64 6f 77 73 20|"

  • Value: "|00 00 00 cc ec b7 a3 20 56 65 72 20|"

Within: 8

PCRE:

Special Options:

  • fast_pattern

source