""ET TROJAN Papras Banking Trojan Checkin""

SID: 2013287

Revision: 4

Class Type: trojan-activity

Metadata: created_at 2011_07_19, updated_at 2012_03_20

Reference:

  • md5

  • 85d82c840f4b90fcb6d5311f501374ca

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "|4e 2a 43 cc 01 c0 2a 77|" Depth: 23

  • Value: "POST"

Within:

PCRE:

Special Options:

  • http_client_body

  • nocase

  • http_method

source