TROJAN: Wiper Backdoor C&C Activity

This signature detects the Command and Control traffic of the Wiper trojan. The source IP host is infected and should be removed from the network for analysis.

Short Name
TROJAN:WIPER-BACKDOOR-ACT
Severity
Major
Recommended
False
Recommended Action
Drop
Category
TROJAN
Keywords
Activity Backdoor C&C Wiper
Release Date
12/22/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/488
False Positive
Unknown

Found a potential security threat?