""ET TROJAN Win32.Chroject.B Receiving ClickFraud Commands from CnC 2""

SID: 2020749

Revision: 3

Class Type: trojan-activity

Metadata: created_at 2015_03_26, updated_at 2015_03_27

Reference:

  • md5

  • 586ad13656f4595723b481d77b6bfb09

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: from_server,established

Contents:

  • Value: ""</p> </li> <li> <p>Value: ""

Within: 13

PCRE: "/^(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=|[A-Za-z0-9+/]{4})<\/title><\/html>$/R"

Special Options:

  • file_data

source