Trojan: Wiper/Flame HTTP POST Data Exfiltration Activity

This signature detects HTTP POST activity for an unknown version of Wiper, also known as Viper, sKyWiper, or Flame during its data exfiltration process. The source IP address is possibly infected and should be investigated.

Short Name
TROJAN:WIPER-FLAME-POST-EXFIL
Severity
Major
Recommended
False
Recommended Action
Drop
Category
TROJAN
Keywords
Activity Data Exfiltration HTTP POST Wiper/Flame
Release Date
05/30/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?