""ET TROJAN CryptoWall Check-in M2""

SID: 2020855

Revision: 4

Class Type: trojan-activity

Metadata: created_at 2015_04_08, performance_impact Significant, updated_at 2024_04_15

Reference:

  • md5

  • 3c53c9f7ab32a09de89bb44e5f91f9af

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: !"|0d 0a|Accept-"

  • Value: !"Referer|3a|"

  • Value: "=" Depth: 1 Offset: 1

  • Value: " rv|3a|11.0"

  • Value: "Accept|3a 20|/|0d 0a|Content-Type|3a 20|application/x-www-form-urlencoded|0d 0a|" Depth: 62

Within:

PCRE: "/^[a-z]=[a-f0-9]{80,}$/P"

Special Options:

  • nocase

  • http_header

  • http_header

  • http_client_body

  • fast_pattern

  • http_header

  • http_header

source