SPYWARE: ZXShell
This signature detects the runtime behavior of the spyware ZXShell. ZXShell is a backdoor Trojan, also known as Backdoor.Sensode. It can take remote control of victim's computer with functions such as get system info, download files, obtain remote shell, list/kill processes, reboot/shutdown machine, etc.
mx-19.3
vmx-19.3
vsrx-19.2
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vmx-19.4
mx-19.4
srxevo-25.4
vsrx-26.2
srx-26.2
srx-branch-26.2
vsrx3bsd-26.2
mx-12.3
srx-12.3
srx-branch-12.3
vsrx-12.3