""ET TROJAN CryptoWall CryptoWall 3.0 Check-in""

SID: 2020233

Revision: 2

Class Type: trojan-activity

Metadata: created_at 2015_01_21, updated_at 2015_01_21

Reference:

  • md5

  • 3c53c9f7ab32a09de89bb44e5f91f9af

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "POST http|3a 2f 2f|proxy" Depth: 17

  • Value: "i2p|0d 0a 0d 0a|"

  • Value: !"|0d 0a|Accept-"

  • Value: !"Referer|3a|"

Within:

PCRE:

Special Options:

  • fast_pattern

source