""ET TROJAN ConstructorWin32/Agent.V""

SID: 2014643

Revision: 6

Class Type: trojan-activity

Metadata: created_at 2012_04_26, updated_at 2012_04_26

Reference:

  • md5

  • 3305ad96bcfd3a406dc9daa31e538902

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "GET http|3A|//" Depth: 11

  • Value: "|0D 0A|Pragma|3A| no-catch|0D 0A|"

  • Value: "|0D 0A|X-HOST|3a| "

  • Value: "|0D 0A|Content-Length|3A| 0|0D 0A|"

Within:

PCRE:

Special Options:

  • http_header

  • http_header

  • http_header

source