""ET TROJAN Confucious APT CnC Checkin""

SID: 2041928

Revision: 1

Class Type: trojan-activity

Metadata: attack_target Client_Endpoint, created_at 2022_12_06, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, updated_at 2022_12_06

Reference:

  • md5

  • 23537d81e9cd285b41185a0e4c3d37c1

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "XOXO"

  • Value: "XOXO"

  • Value: "XOXO|20|Host|20|Name|3a|"

Within: 50

PCRE: "/^(?:[A-F0-9]{2}-){5}[A-F0-9]{2}/R"

Special Options:

  • fast_pattern

source