Short Name |
TROJAN:APT1-SSL-NS |
---|---|
Severity |
Critical |
Recommended |
No |
Recommended Action |
Drop |
Category |
TROJAN |
Keywords |
APT1 ns C&C SSL Certificate |
Release Date |
2013/02/19 |
Update Number |
2235 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects an SSL certificate used by the "APT1" family of malicious activity, associated with Unit 61398, a division of the People's Liberation Army of the People's Republic of China. This SSL certificate is used for Command and Control (C&C) channel encryption to evade IPS.