TROJAN: Sofacy Malicious HTTP Request

This signature detects the Command and Control traffic for the Sofacy trojan. The source IP host is infected and should be removed from the network for analysis.

Short Name
TROJAN:SOFACY-MALICIOUS-REQUEST
Severity
Major
Recommended
True
Recommended Action
Drop
Category
TROJAN
Keywords
HTTP Malicious Request Sofacy
Release Date
06/09/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?