""ET TROJAN Backdoor.Win32/Dervec.gen Connectivity Check to Google""

SID: 2019129

Revision: 9

Class Type: trojan-activity

Metadata: created_at 2012_06_12, updated_at 2014_09_05

Reference:

  • md5

  • 5eaae2d6a4b5d338b83ea5d97af93672

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "HOST|3a|" Depth: 5

  • Value: "www.google.com|0d 0a 0d 0a|"

  • Value: "|00 00 00 00 00 00 00 00 00 00|" Depth: 10 Offset: 39

Within: 19

PCRE:

Special Options:

  • http_header

  • http_header

source