""ET TROJAN Athena DDoS Bot Checkin""

SID: 2017633

Revision: 3

Class Type: trojan-activity

Metadata: created_at 2013_04_26, updated_at 2015_02_25

Reference:

  • md5

  • 19ca0d830cd7b44e5de1ab85f4e17d82

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "POST" Depth: 4

  • Value: "|20|HTTP/1."

  • Value: !"Referer|3a|"

  • Value: "&b="

  • Value: "&c="

  • Value: "|0d 0a 0d 0a|a="

Within:

PCRE: "/^(%[0-9A-Fa-f]{2})+\x26b=[0-9A-Za-z]+(%3[dD]){0,2}\x26c=(%[0-9A-Fa-f]{2})+$/R"

Special Options:

  • fast_pattern

source