BACKDOOR [PTsecurity] SSVagent.APT31 SSL certificate
Sourceptresearch/attackdetection
CreatedDecember 13, 2021
UpdatedDecember 13, 2021
Classificationtrojan-activity
alert tcp any any -> any any (msg:"BACKDOOR [PTsecurity] SSVagent.APT31 SSL certificate"; flow:established,from_server; content:"|550403|"; depth:3000; content:"|10|www.flushcdn.com0"; distance:1; within:18; content:"|55040a|"; depth:3000; content:"|08|GoGetSSL1"; distance:1; within:10; reference:url, github.com/ptresearch/AttackDetection; classtype:trojan-activity; sid:10006685; rev:1;)
References
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!