""ET TROJAN EUPUDS.A Requests for Boleto replacement""

SID: 2018793

Revision: 3

Class Type: trojan-activity

Metadata: created_at 2014_07_28, former_category MALWARE, updated_at 2021_12_29

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "POST"

  • Value: "/index.php"

  • Value: "Content-Type|3a|"

  • Value: "Content-Length|3a| "

  • Value: !"Host|3a 20|antia|2d|client|2d|log|2e|puzzleplusgames|2e|net"

  • Value: !"Referer"

  • Value: !"User-Agent|3a| "

  • Value: !"Cache-Control|3a| "

  • Value: !"Accept"

  • Value: !"Connection|3a| "

Within:

PCRE: "/^[a-f0-9]{8}\x3d(?:[A-Za-z0-9-]{4})*(?:[A-Za-z0-9-]{2}==|[A-Za-z0-9-]{3}=|[A-Za-z0-9-]{4})$/Pi"

Special Options:

  • http_method

  • fast_pattern

  • http_header

  • http_header

  • http_header

  • http_header

  • http_header

  • http_header

  • http_header

source