""ET TROJAN Win32/Pykspa.C Public IP Check""

SID: 2018773

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2014_07_24, updated_at 2014_07_24

Reference:

  • md5

  • 324ff262da1233ef874ff29213cf8f19

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: !"Accept-"

  • Value: !"Referer"

  • Value: "myip"

  • Value: "User-Agent|3a 20|Mozilla/5.0 (Windows|3b| U|3b| Windows NT 5.1|3b| en-US|3b| rv|3a|1.9.1.3) Gecko/20090824 Firefox/3.5.3|0d 0a|Connection|3a 20|close"

Within:

PCRE: "/^Host\x3a[^\r\n]+myip/Hmi"

Special Options:

  • http_header

  • http_header

  • http_header

  • nocase

  • http_header

source