""ET TROJAN Book of Eli CnC Checkin""

SID: 2023254

Revision: 3

Class Type: trojan-activity

Metadata: created_at 2013_05_17, updated_at 2017_11_16

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "POST"

  • Value: "CharSet|3a| windows-1256|0d 0a|"

  • Value: !"User-Agent|3a| "

  • Value: "id_serial=" Depth: 10

  • Value: "&id_cpu="

  • Value: "&go_and_fuck_this_life="

  • Value: "&system__="

  • Value: "&hard_id="

Within:

PCRE:

Special Options:

  • http_method

  • nocase

  • http_header

  • http_header

  • http_client_body

  • http_client_body

  • http_client_body

  • http_client_body

  • http_client_body

source