TROJAN: Subseven (HTTP)
This signature detects the runtime behavior of the Trojan Subseven, a remote administration tool. When remote attackers know the targe's IP address, they can gain complete control over it, including deleting files, adding files, killing processes, scanning screens, recording activities, extracting passwords and so on.
Extended Description
Subseven is a well-known Trojan with a backdoor capabilities. It enables remote attackers to gain full control over an infected machine without the knowledge of the victim.
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
8.8