""ET TROJAN Matsnu Checkin""

SID: 2021399

Revision: 3

Class Type: trojan-activity

Metadata: created_at 2015_07_10, performance_impact Significant, updated_at 2024_04_30

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "POST"

  • Value: ".php?"

  • Value: !"Referer|3a| "

  • Value: "User-Agent|3a| Mozilla/4.0 (compatible|3b| MSIE 6.0b|3b| Windows NT 5.0|3b| .NET CLR 1.0.2914|29 0d 0a|"

  • Value: "Connection|3a| Keep-Alive|0d 0a|Cache-Control|3a| no-cache|0d 0a|"

  • Value: "=" Depth: 7

  • Value: "AA"

Within: 2

PCRE: "/^[a-z]{1,7}=(?:[A-Za-z0-9+/]{4})*(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=|[A-Za-z0-9+/]{4})$/P"

Special Options:

  • http_method

  • nocase

  • http_uri

  • http_header

  • http_header

  • http_header

  • http_client_body

  • http_client_body

source