""ET TROJAN OSX/Mokes.A CnC Heartbeat Request (set)""

SID: 2023182

Revision: 1

Class Type: trojan-activity

Metadata: affected_product Mac_OSX, created_at 2016_09_08, deployment Perimeter, tag OSX_Malware, updated_at 2016_09_08

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "GET"

  • Value: "/v1"

  • Value: "Connection|3a 20|Close|0d 0a|"

  • Value: "Safari/7046A194A|0d 0a|"

  • Value: !"Accept|3a|"

  • Value: !"Referer|3a|"

Within:

PCRE: "/^Connection\x3a\x20Close\r\nUser-Agent\x3a\x20[^\r\n]+\r\nAccept-Encoding\x3a\x20[^\r\n]+\r\nAccept-Language\x3a\x20[^\r\n]+\r\nHost\x3a\x20[^\r\n]+\r\n\r\n$/Hmi"

Special Options:

  • http_method

  • http_uri

  • http_header

  • http_header

  • fast_pattern

  • http_header

  • http_header

source