SCAN: Canvas Helium Agent (2)
This signature detects Helium, a python-based Trojan installed after a system is exploited by the Canvas Framework from Immunitysec. By default, Canvas uses port 31337, but an attacker can configure Canvas to use any port. Remote attackers can use the Helium Trojan to gain full access to the infected host, including loading programs such as port scanners, exploits, and distributed computing modules.
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3