Advertisement
James_inthe_box

HVNC unencrypted traffic sigs

Aug 9th, 2019
1,450
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.58 KB | None | 0 0
  1. alert tcp any any -> any 443 (msg:"Trojan HVNC USR Init Detected"; flow:established,to_server; content:"|3b 00 00 00 19 00 00 00 12 01 00 00 2d 55 53 52|"; within:20; reference:md5,4abde768b70e94093970901438e51cbd; classtype:trojan-activity; sid:20166302; rev:1; metadata:created_at 2019_08_09;)
  2.  
  3. alert tcp any any -> any 443 (msg:"Trojan HVNC BOT Detected"; flow:established,to_server; content:"|3b 00 00 00 19 00 00 00 13 01 00 00 2d 42 4f 54|"; within:20; reference:md5,4abde768b70e94093970901438e51cbd; classtype:trojan-activity; sid:20166303; rev:1; metadata:created_at 2019_08_09;)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement