""ET TROJAN Win32/Urausy.C Checkin""

SID: 2016553

Revision: 2

Class Type: trojan-activity

Metadata: created_at 2013_03_08, updated_at 2013_03_08

Reference:

  • md5

  • 1494b8b9f42753a4bc1762d8f3287db6

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "GET"

  • Value: "User-Agent|3a| Mozilla/5.0 (Windows NT 6.1|3b| WOW64) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.0.1271.97 Safari/537.11|0d 0a|"

  • Value: Depth: 122

  • Value: !"Referer|3a| "

  • Value: !"Accept|3a| "

Within:

PCRE: "/^\/[a-z-_]+?.(php|html)$/Ui"

Special Options:

  • http_method

  • http_header

  • http_header

  • http_header

source