""ET TROJAN Possible DEEP PANDA C2 Activity""

SID: 2020373

Revision: 3

Class Type: trojan-activity

Metadata: created_at 2015_02_06, updated_at 2015_02_06

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "POST /" Depth: 6

  • Value: "User-Agent|3a 20|Mozilla/4.0+(compatible|3b|+MSIE+8.0|3b|+Windows+NT+5.1|3b|+SV1|29 0d 0a|"

  • Value: !"Referer|3a|"

  • Value: !"Content-Type|3a|"

  • Value: !"Accept"

  • Value: "|0d 0a 0d 0a|"

  • Value: "|00 00 00 00 00|"

Within:

PCRE:

Special Options:

source