""ET TROJAN Syrian Malware Checkin""

SID: 2019084

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2014_08_29, updated_at 2014_08_29

Reference:

  • md5

  • a8cf815c3800202d448d035300985dc7

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "|2f|j|7c|n|5c|" Depth: 5 Offset: 2

  • Value: "[endof]"

Within:

PCRE:

Special Options:

  • fast_pattern

source