""ET TROJAN XDR33 CnC Server SSL Certificate Observed""

SID: 2043263

Revision: 1

Class Type: trojan-activity

Metadata: affected_product Any, attack_target Client_and_Server, created_at 2023_01_10, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, updated_at 2023_01_10

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: 443

Destination Network: $HOME_NET

Destination Port: any

Flow: established,to_client

Contents:

  • Value: "|16|"

  • Value: "|0b|"

  • Value: "|06 03 55 04 06|"

  • Value: "|02|RU"

  • Value: "|06 03 55 04 0a|"

  • Value: "|14|Kaspersky Laboratory"

  • Value: "|06 03 55 04 03|"

  • Value: "|0b|Engineering"

  • Value: "|06 03 55 04 03|"

  • Value: "|08|server33"

  • Value: "|06 03 55 04 08|"

  • Value: "|06|Moscow"

  • Value: "|06 03 55 04 07|"

  • Value: "|06|Moscow"

  • Value: "|06 03 55 04 0b|"

  • Value: "|02|IT"

Within: 3

PCRE:

Special Options:

source