""ET TROJAN Gamaredon APT Backdoor Related Activity""
SID: 2038973
Revision: 1
Class Type: trojan-activity
Metadata: attack_target Client_Endpoint, created_at 2022_09_26, deployment Perimeter, malware_family Gamaredon, performance_impact Low, signature_severity Major, updated_at 2022_09_26
Reference:
-
md5
-
5c645e5dcb6bec4ab1bcb3f68421445a
Protocol: tcp
Source Network: $HOME_NET
Source Port: any
Destination Network: $EXTERNAL_NET
Destination Port: $HTTP_PORTS
Flow: established,to_server
Contents:
-
Value: "user-agent|3a 20|mozilla/5.0"
-
Value: "|3b 3b|"
-
Value: "|3b 3b 2f|"
-
Value: "|2e 0d 0a|"
-
Value: "|20|HTTP/1."
Within:
PCRE: "/^User-Agent\x3a\x20[^\r\n]+\x3b\x3b[^\r\n]+\x3b\x3b\x2f[^\r\n]+\x2e[\r\n]+$/Hmi"
Special Options:
-
http_header
-
http_header
-
http_header
-
fast_pattern
-
http_header