""ET TROJAN W32 Bamital or Backdoor.Win32.Shiz CnC Communication""

SID: 2012299

Revision: 2

Class Type: trojan-activity

Metadata: created_at 2011_02_07, updated_at 2011_04_28

Reference:

  • md5

  • fbcdfecc73c4389e8d3ed7e2e573b6f1

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "/favicon.ico?0="

  • Value: "&1="

  • Value: "&2="

  • Value: "&3="

  • Value: "&4="

  • Value: "&5="

  • Value: "&6="

  • Value: "&7="

Within:

PCRE:

Special Options:

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

source