""ET TROJAN Fareit/Pony Downloader Checkin 2""

SID: 2014411

Revision: 8

Class Type: trojan-activity

Metadata: created_at 2012_03_22, updated_at 2018_07_04

Reference:

  • md5

  • 99FAB94FD824737393F5184685E8EDF2

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "POST"

  • Value: "|0d 0a|Content-Encoding|3a| binary|0d 0a|"

  • Value: "|0d 0a|Accept-Encoding|3a 20|identity,|20 2a 3b|q=0|0d 0a|"

  • Value: " MSIE "

  • Value: !"Referer|3a 20|"

  • Value: " HTTP/1.0|0d 0a|"

Within:

PCRE:

Special Options:

  • nocase

  • http_method

  • http_header

  • http_header

  • http_header

  • http_header

source