Sagan critical stable other
[ZSCALER] Win.Trojan.Darkcpn outbound connection
[ZSCALER] Win.Trojan.Darkcpn outbound connection
Detection Logic
alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[ZSCALER] Win.Trojan.Darkcpn outbound connection"; content:"requestClientApplication
| 3d
| Mozilla/4.0+(compatible
| 3B
| +MSIE+6.0
| 3B
| +Windows+NT+5.1
| 3B
| +SV1
| 3B
| +.NET+CLR+2.0.50727)
| 0D 0A
| "; reference:url,virustotal.com/file/cab7cd418b1114c277f84c4fe59d05bcf53babf64f16ebe86ab11641bd6bbd94/analysis/; parse_src_ip: 2; parse_dst_ip: 1; program: CEF; content: "Zscaler"; content:"act=Allowed"; default_dst_port: $HTTP_PORT; default_proto: tcp; xbits: set,exploit_attempt,track ip_src, expire 86400; classtype:trojan-activity; sid:5003134; rev:3; metadata: mitre_technique_id T1043, mitre_technique_id T1105;) Field Validations
Loading…
Comments (0)
Loading comments...