""ET MOBILE_MALWARE Android/TrojanDropper.Agent.GWO Checkin""

SID: 2035432

Revision: 2

Class Type: trojan-activity

Metadata: created_at 2022_03_10, updated_at 2022_03_10

Reference:

  • md5

  • dcfa846ca56e14e720d4a743ac5c9f0f

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: to_server,established

Contents:

  • Value: "POST " Depth: 5

  • Value: "okhttp/"

  • Value: !"Referer|3a 20|"

  • Value: "|0d 0a 0d 0a|{|22|logType|22 3a|"

  • Value: ",|22|msg|22 3a 22|{|5c 22|auth|5c 22 3a|"

  • Value: "|5c 22|appVersionName|5c 22|"

Within:

PCRE:

Special Options:

  • fast_pattern

source