""ET TROJAN W32/UltimateDefender.FakeAV Checkin""

SID: 2014566

Revision: 2

Class Type: trojan-activity

Metadata: created_at 2012_04_16, updated_at 2012_04_16

Reference:

  • md5

  • cec40236236466a1acb33aca3220eebe

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "/show_module.php?IsAutoGeneratedPage="

  • Value: "&asked_billing_id="

  • Value: "&original_asked_billing_id="

  • Value: "&brokerid="

  • Value: "&country="

  • Value: "&customid="

  • Value: "&product="

  • Value: "&custom_param="

  • Value: "&extparam="

  • Value: "&nums="

Within:

PCRE:

Special Options:

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

source