MALWARE-BACKDOOR -- Snort has detected suspicious communication traffic unrelated to commands, such as exfiltration of data from the infected machine, especially larger chunks of data.
MALWARE-BACKDOOR Perl.Backdoor.PULSECHECK variant cnc connection
This rule looks for traffic related to malicious backdoors used on victim Pulse Secure Servers.
This rule looks for traffic related to malicious backdoors used on victim Pulse Secure Servers.
No public information
No known false positives
Cisco Talos Intelligence Group
No rule groups
None
No information provided
None
Tactic: Command and Control
Technique: Standard Application Layer Protocol
For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org