""ET TROJAN UPDATE Protocol Trojan Communication detected on non-http ports 2""

SID: 2014231

Revision: 5

Class Type: trojan-activity

Metadata: created_at 2012_02_16, updated_at 2012_03_27

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: !$HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "POST " Depth: 5

  • Value: "/update?id="

  • Value: "X-Status|3A|"

Offset: 16

  • Value: "X-Size|3A|"

Offset: 16

  • Value: "X-Sn|3A|"

Offset: 16

  • Value: "User-Agent|3a| Mozilla/4.0 |28|compatible|3b| MSIE 6.0|3b| Windows NT 5.1|3b|SV1|3b 0d 0a|"

Offset: 16

Within:

PCRE:

Special Options:

  • nocase

  • fast_pattern

source