""ET TROJAN Win32/Zemot Fake Search Page""

SID: 2021107

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2015_05_15, updated_at 2015_05_15

Reference:

  • md5

  • 38cad3170f85c4f9903574941bd282a8

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,from_server

Contents:

  • Value: "background|3a 20|url(btn_search.png|29 2f 2a|tpa=http"

Within:

PCRE:

Special Options:

  • file_data

source