""ET TROJAN MWI Maldoc Stats Callout Aug 18 2015""

SID: 2021690

Revision: 7

Class Type: trojan-activity

Metadata: created_at 2015_08_19, updated_at 2017_12_07

Reference:

  • md5

  • 2c9f2a84a346e29c3b262ca1d2d2f123

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "/im"

  • Value: "?id="

  • Value: "office"

  • Value: !".money-media.com|0d 0a|"

  • Value: !"ad.payclick.it|0d 0a|"

  • Value: !"sellercore.com|0d 0a|"

Within:

PCRE: "/^User-Agent\x3a\x20[^\x0d\x0a]+?ms-?office/Hmi"

Special Options:

  • http_uri

  • http_uri

  • http_header

  • nocase

  • nocase

  • http_header

  • nocase

  • http_header

  • nocase

  • http_header

source