""ET TROJAN Kazy/Kryptor/Cycbot Trojan Checkin""

SID: 2012939

Revision: 6

Class Type: trojan-activity

Metadata: created_at 2011_06_07, updated_at 2012_03_20

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "GET"

  • Value: "?v"

  • Value: "&tq="

  • Value: "User-Agent|3a| mozilla/2.0|0d 0a|"

Within:

PCRE: "/.(jpg|png|gif)\?v[0-9]{1,2}=[0-9]+&tq=/U"

Special Options:

  • nocase

  • http_method

  • http_uri

  • http_uri

  • http_header

source