Recently a post by Crowdstrike was released detailing an attack being used, allegedly, by the Chinese Military “PLA Unit 61486″ The VRT can confirm that we’ve had coverage for the malware/tools mentioned in the post, since 2012. The Sourcefire IPS/Snort detects the outbound traffic with rules: 21240 and 21241, along with a similar variant at sid 21242. There are others like it, and the VRT has also been receiving questions if we cover one of them.”]
Source: https://blog.talosintelligence.com/2014/06/detection-for-putterpanda-we-got-this.html

