""ET TROJAN CryptoWall Check-in""

SID: 2018452

Revision: 13

Class Type: trojan-activity

Metadata: created_at 2014_05_05, updated_at 2020_09_17

Reference:

  • md5

  • 3c53c9f7ab32a09de89bb44e5f91f9af

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "=" Depth: 1 Offset: 1

  • Value: " MSIE "

  • Value: "Accept|3a 20|/|0d 0a|Content-Type|3a 20|application/x-www-form-urlencoded|0d 0a|" Depth: 62

  • Value: !"|0d 0a|Accept-"

  • Value: !"Referer|3a|"

Within:

PCRE: "/^[a-z]=[a-f0-9]{80,}$/P"

Special Options:

  • http_client_body

  • fast_pattern

  • http_header

  • http_header

  • nocase

  • http_header

  • http_header

source