""ET CURRENT_EVENTS Zbot Generic URI/Header Struct .bin""

SID: 2018052

Revision: 8

Class Type: trojan-activity

Metadata: created_at 2014_02_01, updated_at 2021_09_21

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "GET"

  • Value: ".bin"

  • Value: !"Referer|3a|"

  • Value: !"Accept-Language|3a|"

  • Value: " MSIE "

  • Value: !"AskTbARS"

  • Value: !".passport.net|0d 0a|"

  • Value: !".microsoftonline-p.net|0d 0a|"

  • Value: !".symantec.com|0d 0a|"

  • Value: !".qq.com|0d 0a|"

  • Value: !"kankan.com|0d 0a|"

  • Value: !"aocdn.net"

  • Value: !"conf.v.xunlei.com|0d 0a|"

  • Value: !"burstek.com|0d 0a|"

  • Value: "|0d 0a 0d 0a|"

Within:

PCRE: "/\/[a-z0-9]{1,31}.bin$/U"

Special Options:

  • http_method

  • http_uri

  • http_header

  • http_header

  • http_header

  • http_header

  • http_header

  • http_header

  • http_header

  • http_header

  • http_header

  • http_header

  • http_header

  • http_header

source