""ET TROJAN Comfoo Outbound Communication""
SID: 2009125
Revision: 16
Class Type: trojan-activity
Metadata: created_at 2010_07_30, updated_at 2015_11_13
Reference:
Protocol: tcp
Source Network: $HOME_NET
Source Port: any
Destination Network: $EXTERNAL_NET
Destination Port: any
Flow: established,to_server
Contents:
-
Value: "Accept-Language|3a 20|en-en|0d 0a|"
-
Value: "|3b|Windows|20|"
Within:
PCRE:
Special Options:
- nocase