""ET TROJAN Zbot POST Request to C2""

SID: 2019141

Revision: 3

Class Type: trojan-activity

Metadata: created_at 2014_09_09, performance_impact Moderate, updated_at 2024_04_08

Reference:

  • md5

  • c86f7ec18b78055a431f7cd1dca65b82

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "POST"

  • Value: ".php"

  • Value: "HTTP/1."

  • Value: "|0D 0A|Accept|3a| /|0D 0A|User-Agent|3a| Mozilla"

  • Value: !"Accept-"

  • Value: !"Content-Type|3a|"

  • Value: !"Referer|3a|"

Within: 34

PCRE: "/^Accept\x3a *\/*\r\nUser-Agent\x3a[^\r\n]+?\r\nHost\x3a[^\r\n]+?\r\nContent-Length\x3a[^\r\n]+?\r\n(?:Proxy-)?Connection\x3a[^\r\n]+?\r\n(?:Pragma|Cache-Control)\x3a[^\r\n]+?\r\n(?:\r\n)?$/H"

Special Options:

  • http_method

  • http_uri

  • fast_pattern

  • http_header

  • http_header

  • http_header

source