SID: 2019539

Revision: 2

Class Type: trojan-activity

Metadata: created_at 2014_10_28, updated_at 2014_10_29

Reference:

  • md5

  • 272f0fde35dbdfccbca1e33373b3570d

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "POST"

  • Value: "/~xh/sn.cgi?"

Within:

PCRE: "/\/~xh\/sn.cgi\?(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=|[A-Za-z0-9+/]{4})+$/Ui"

Special Options:

  • http_method

  • http_uri

  • fast_pattern

source