""ET TROJAN US-CERT TA14-353A Proxy Tool 2""

SID: 2020018

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2014_12_23, updated_at 2014_12_23

Reference:

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: any

Destination Port: any

Flow: established

Contents:

  • Value: !"HTTP/1"

  • Value: "|e2 1d 49 49|" Depth: 4

  • Value: "|49 49 49 49|"

Within: 4

PCRE:

Special Options:

  • fast_pattern

source