""ET TROJAN Trojan.Win32.Jorik.Totem.vg HTTP request""

SID: 2015562

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2012_08_03, updated_at 2012_08_03

Reference:

  • md5

  • cf5df13f8498326f1c6407749b3fe160

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "/?xclzve_" Depth: 9

Within:

PCRE:

Special Options:

  • http_uri

source