""ET TROJAN Download Request Containing Suspicious Filename - Crypted""

SID: 2022491

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2016_02_04, updated_at 2016_02_04

Reference:

  • md5

  • 1e2fa2e401cd2295a03ba8d8d3d3698b

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "GET"

  • Value: "crypted.exe"

  • Value: !"Referer|3a|"

Within:

PCRE: "/crypted.exe$/Ui"

Special Options:

  • http_method

  • nocase

  • fast_pattern

  • http_uri

  • http_header

source