""ET TROJAN ASCII Executable Inside of MSCOFF File DL Over HTTP""

SID: 2022303

Revision: 2

Class Type: trojan-activity

Metadata: created_at 2015_12_23, updated_at 2015_12_23

Reference:

  • md5

  • f4ee917a481e1718ccc749d2d4ceaa0e

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,from_server

Contents:

  • Value: "|34 64 35 61|"

  • Value: "|35 34 36 38 36 39 37 33 32 30 37 30 37 32 36 66 36 37 37 32 36 31 36 64 32 30|"

Within:

PCRE:

Special Options:

  • file_data

source