""ET INFO Terse Unencrypted Request for Google - Likely Connectivity Check""

SID: 2036303

Revision: 3

Class Type: trojan-activity

Metadata: created_at 2022_04_22, performance_impact Moderate, updated_at 2022_04_29

Reference:

  • md5

  • 7ca63bab6e05704d2c7b48461e563f4c

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: 80

Flow: established,to_server

Contents:

  • Value: "google.com|0d 0a|"

  • Value: "GET /|20|" Depth: 6

  • Value: !"Referer|3a 20|"

  • Value: !"User-Agent|3a 20|"

  • Value: !"Accept"

Within:

PCRE: "/^Host\x3a\x20[^\r\n]*.?google.com[\r\n]+$/Hmi"

Special Options:

  • http_header

  • fast_pattern

  • http_header

  • http_header

  • http_header

source