""ET TROJAN [PTsecurity] Trojan.Downloader VBA Script obfuscation (binary_getter)""

SID: 2025202

Revision: 2

Class Type: trojan-activity

Metadata: affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2018_01_16, deployment Perimeter, signature_severity Major, updated_at 2018_01_16

Reference:

  • md5

  • bad07f85a7baaeaa8aeb72997712aa98

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,to_client

Contents:

  • Value: "200"

  • Value: "(Chr((((asc(Mid(" Depth: 300

  • Value: ",1,1))-65))*25+(asc(Mid("

  • Value: ",2,1))-65)-"

Within: 100

PCRE:

Special Options:

  • http_stat_code

  • file_data

source