""ET TROJAN Win32/Gh0st RAT Variant CnC Checkin response""

SID: 2039834

Revision: 2

Class Type: trojan-activity

Metadata: attack_target Client_and_Server, created_at 2022_11_23, deployment Perimeter, performance_impact Significant, confidence High, signature_severity Major, updated_at 2023_09_13, reviewed_at 2023_09_13

Reference:

  • md5

  • 77bd9926a4b41c14259e20c1f90e22aa

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: any

Flow: established,to_client

Contents:

  • Value: "|1b 00 00 00|" Depth: 4

Within:

PCRE: "/(?:\x01\x00\x01$|\x00{3}$)/"

Special Options:

source