""ET TROJAN Medfos Connectivity Check""

SID: 2016800

Revision: 3

Class Type: misc-activity

Metadata: created_at 2013_05_01, updated_at 2013_05_01

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "/uploading/id="

  • Value: !"Referer|3a 20|"

Within:

PCRE: "/^\/uploading\/id=\d{2,20}&u=(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=|[A-Za-z0-9+/]{4})$/I"

Special Options:

  • http_uri

  • http_header

source