""ET CURRENT_EVENTS KaiXin Landing M5 1 Oct 05 2015""

SID: 2021905

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2015_10_06, updated_at 2015_10_06

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,from_server

Contents:

  • Value: "str2long"

  • Value: "long2str"

  • Value: "0xffffffff"

Within:

PCRE: "/^(?P[^\s\x3b\x22\x27])(?=.+?(?P=sep)str2long(?P=sep)).+?(?P=sep)long2str(?P=sep)/Rs"

Special Options:

  • file_data

source