""ET TROJAN Zalupko/Koceg/Mandaph HTTP Checkin (2)""

SID: 2010765

Revision: 8

Class Type: trojan-activity

Metadata: created_at 2010_07_30, updated_at 2019_09_27

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "/manda.php?"

  • Value: "id="

  • Value: "&v="

Within:

PCRE: "/\/manda.php\?id=(-)?\d{8,10}&v=\w/U"

Special Options:

  • http_uri

  • nocase

  • http_uri

  • nocase

  • http_uri

source