""ET TROJAN ELF/FontOnLake Related CnC Domain in DNS Lookup (hm2 .yrnykx .com)""
SID: 2034222
Revision: 1
Class Type: attempted-admin
Metadata: created_at 2021_10_18, updated_at 2021_10_18
Reference:
-
md5
-
5ecf30b7a6221af8f209a7b6681f91f9
Protocol: udp
Source Network: $HOME_NET
Source Port: any
Destination Network: any
Destination Port: 53
Flow:
Contents:
-
Value: "|01|" Depth: 1 Offset: 2
-
Value: "|00 01 00 00 00 00 00|"
-
Value: "|03|hm2|06|yrnykx|03|com"
Within: 7
PCRE:
Special Options:
- nocase