""ET TROJAN Powershell with Decimal Encoded RUNPE Downloaded""

SID: 2034980

Revision: 3

Class Type: trojan-activity

Metadata: attack_target Client_Endpoint, created_at 2022_01_26, deployment Perimeter, deployment SSLDecrypt, signature_severity Major, updated_at 2022_05_03

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,to_client

Contents:

  • Value: "Content-Type|3a 20|text/plain"

  • Value: "RUNPE"

  • Value: "31,139,8,0,0,0,0,0,4,0,237,189,7,96"

  • Value: "82,101,109,111,116,101,83,105,103,110,101,100"

Within: 50

PCRE:

Special Options:

  • http_header

  • file_data

  • nocase

  • fast_pattern

source