""ET TROJAN W32/Madness Checkin""

SID: 2018028

Revision: 5

Class Type: trojan-activity

Metadata: created_at 2014_01_28, updated_at 2017_06_13

Reference:

  • md5

  • f1ed53c4665d2893fd116a5b0297fc68

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "GET"

  • Value: "&mk="

  • Value: "&rs="

  • Value: "&rq="

  • Value: "&ver="

Within:

PCRE: "/\?uid=\d{8}&ver=\d.\d{2}&mk=[0-9a-zA-Z]{6}&os=[A-Za-z0-9]+&rs=[a-z]+&c=\d+&rq=\d/U"

Special Options:

  • http_method

  • http_uri

  • http_uri

  • http_uri

  • http_uri

source