""ET TROJAN HB_Banker16 Get""

SID: 2019608

Revision: 2

Class Type: trojan-activity

Metadata: created_at 2014_10_30, updated_at 2014_10_30

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "GET"

  • Value: "Content-Type|3a 20|text/html|0d 0a|Host|3a|" Depth: 30

  • Value: !"Referer|3a|"

  • Value: !"Accept-"

  • Value: !"Indy Library"

  • Value: "Firefox/12.0"

Within:

PCRE: "/^Content-Type\x3a\x20text\/html\r\nHost\x3a\x20[^\r\n]+?\r\nAccept\x3a\x20text\/html,\x20*\/*\r\nUser-Agent\x3a\x20[^\r\n]+?\r\n(?:\r\n)?$/H"

Special Options:

  • http_method

  • http_header

  • http_header

  • http_header

  • http_header

source