""ET TROJAN P2P Zeus or ZeroAccess Request To CnC""

SID: 2013911

Revision: 9

Class Type: trojan-activity

Metadata: created_at 2011_11_11, updated_at 2012_05_02

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "|E5 AA C0 31|" Depth: 4

  • Value: "|5B 74 08 4D 9B 39 C1|"

Within: 7

PCRE:

Special Options:

source