""ET TROJAN MWI Maldoc Stats Callout Oct 28""

SID: 2022008

Revision: 2

Class Type: trojan-activity

Metadata: created_at 2015_10_28, updated_at 2016_10_18

Reference:

  • md5

  • 2c9f2a84a346e29c3b262ca1d2d2f123

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "/pict."

  • Value: "?id="

  • Value: "office"

  • Value: !".money-media.com|0d 0a|"

Within:

PCRE: "/^User-Agent\x3a\x20[^\x0d\x0a]+?ms-?office/Hmi"

Special Options:

  • http_uri

  • http_header

  • nocase

  • nocase

  • http_header

source