B20-An5d31
False Positive:
f
Variants:
0
Year:
2019
Description
This strike simulates Andariel-2019 Command and Control traffic after installing ApolloZeus Loader module. This Strike sends data over TCP port 443, although many packet capture tools like Wireshark will call this encrypted data, this is not actually SSL Encrypted Data. These are encrypted/encoded command and control exchanges, but they are not SSL.
CVE
References
MSB
BID
ExploitDB
Secunia
Security Tracker
Metasploit
ZDI
OSVDB
{}