""ET MALWARE MultiPlug.A checkin""

SID: 2018867

Revision: 2

Class Type: trojan-activity

Metadata: created_at 2014_08_01, updated_at 2019_08_14

Reference:

  • md5

  • 69e28b658520528a1473f51e62698c87

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "get/?ver="

  • Value: "&aid="

  • Value: "&hid="

  • Value: "&rid="

  • Value: "&data="

  • Value: "&report="

  • Value: !"Referer|3a 20|"

Within:

PCRE: "/^\/get\/\?ver=.+?\&aid=\d{8,12}\&hid=[a-f0-9]{15,17}&rid=\d{13}\&data=.*?&report=/U"

Special Options:

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_uri

  • http_header

source