""ET TROJAN HompesA Activity""

SID: 2019838

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2014_12_02, updated_at 2014_12_02

Reference:

  • md5

  • 8cc58bc4d63f4b78b635d45aa69108f7

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "/me/"

  • Value: !"Referer|3a|"

  • Value: !"Accept-"

Within:

PCRE: "/^\/me\/(?:get(?:ref|ua).php|videos.txt)$/U"

Special Options:

  • http_uri

  • http_header

  • http_header

source