""ET TROJAN Win32/Vundo.OD Checkin""

SID: 2016424

Revision: 4

Class Type: trojan-activity

Metadata: created_at 2011_12_17, updated_at 2013_02_16

Reference:

  • md5

  • 8840a0d9d7f4dba3953ccb68b17b2d6c

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "/get.php?"

  • Value: "id="

  • Value: "key="

  • Value: "&os="

  • Value: "&av="

  • Value: "&vm="

  • Value: "&al="

  • Value: "&p="

  • Value: "&z="

  • Value: !"User-Agent|3a|"

Within:

PCRE: "/\/get.php\?(id|key)\x3d/Ui"

Special Options:

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_header

source