""ET TROJAN TA577 Style Response (2023-05-15)""

SID: 2048222

Revision: 1

Class Type: trojan-activity

Metadata: attack_target Client_and_Server, created_at 2023_09_25, deployment Perimeter, deployment SSLDecrypt, performance_impact Moderate, confidence High, signature_severity Major, tag TA577, updated_at 2023_09_25, reviewed_at 2023_09_25

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,to_client

Contents:

  • Value: "200"

  • Value: "content-description"

  • Value: "|3a 20|File Transfer|0d 0a|"

  • Value: "content-disposition|3a 20|"

  • Value: "attachment|3b 20|filename|3d|"

  • Value: "cache-control|3a 20|"

  • Value: "must|2d|revalidate|2c 20|post|2d|check|3d|0|2c 20|pre|2d|check|3d|0"

  • Value: "content-transfer-encoding|3a 20|"

  • Value: "binary|0d 0a|"

  • Value: "expires|3a 20|0|0d 0a|"

  • Value: "content-type"

  • Value: "|3a 20|application/octet-stream|0d 0a|"

Within: 28

PCRE:

Special Options:

  • http_stat_code

  • http_header

  • nocase

  • http_header

  • fast_pattern

  • http_header

  • nocase

  • http_header

  • http_header

  • nocase

  • http_header

  • http_header

  • nocase

  • http_header

  • http_header

  • nocase

  • nocase

  • http_header

source