""ET TROJAN Possible Kelihos.F EXE Download Common Structure""

SID: 2017598

Revision: 6

Class Type: trojan-activity

Metadata: created_at 2013_10_15, updated_at 2014_05_01

Reference:

  • md5

  • f5bcc28e7868a68e473373d684a8c54a

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "GET"

  • Value: ".exe"

  • Value: !"Referer|3a 20|"

  • Value: !"Accept|3a 20|"

  • Value: !"User-Agent|3a 20|"

Within:

PCRE: "/^Host\x3A\x20[0-9]{1,3}\x2E[0-9]{1,3}\x2E[0-9]{1,3}\x2E[0-9]{1,3}\x0D\x0A\x0D?\x0A?$/H"

Special Options:

  • http_method

  • http_uri

  • http_header

  • http_header

  • http_header

source