>On Aug 2, 2012, at 9:27 AM, "harry.tuttle" wrote:
>
>> Joel, are you looking at sandbox reports for my MD5, or do you have another? I didn't want to assume that was always static based on my single sample if there was another option. I thought the en by itself might be fairly unique, but I guess not.
>>
>>
>> ---- On Wed, 01 Aug 2012 19:11:08 -0700 Joel Esler wrote ----
>>
>>> The first part of the uri is static up until the underscore.
>>>
>>> --
>>> Joel Esler
>>> Sent from my iPhone
>>>
>>> On Aug 1, 2012, at 7:42 PM, Will Metcalf wrote:
>>>
>>>> Based on the number of hits I got from our test data sets I'm guessing
>>>> FP's are going to be a problem.with this one. Anybody have more
>>>> examples of these? Maybe we can find a pattern in the uri?
>>>>
>>>> Regards,
>>>>
>>>> Will
>>>>
>>>> On Wed, Aug 1, 2012 at 4:15 PM, harry.tuttle wrote:
>>>>> Ah, you're right. The first several GETs in my pcap did not have it, so I didn't look further.
>>>>>
>>>>> I wonder how unique "en" by itself is in the Accept-Language header. That might work on its own.
>>>>>
>>>>> Also, some of the GETs are to just "/", and some of the POSTs are to a URI similar to the one in the GET below.
>>>>>
>>>>>
>>>>> ---- On Wed, 01 Aug 2012 13:35:57 -0700 Joel Esler wrote ----
>>>>>
>>>>>> The User-Agent isn't always absent.
>>>>>>
>>>>>> On Aug 1, 2012, at 3:36 PM, harry.tuttle wrote:
>>>>>>
>>>>>>> I've got a piece of malware, MD5 cf5df13f8498326f1c6407749b3fe160. Names on VT haven't really clustered around any particular name yet.
>>>>>>>
>>>>>>> Its HTTP GETs look pretty unique. Here's a quick rule. More info below.
>>>>>>>
>>>>>>> alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN unknown trojan HTTP GET"; flow:established,to_server; content:"GET"; http_method; nocase; content:"/?"; depth:2; http_uri; content:"Accept-Language|3a 20|en|0d 0a|"; http_header; content:!"User-Agent|3a|"; http_header; reference:md5,cf5df13f8498326f1c6407749b3fe160; classtype:trojan-activity; sid:nnnnnnn; rev:1;)
>>>>>>>
>>>>>>>
>>>>>>> Observed traffic (it does not use the system's proxy if one is configured):
>>>>>>>
>>>>>>> GET /?xclzve_Yekqw17CIOUaflrx28EJPUaflsy49F HTTP/1.1
>>>>>>> Accept: */*
>>>>>>> Accept-Language: en
>>>>>>> Accept-Encoding: gzip, deflate
>>>>>>> Host:
accountaxation.com
>>>>>>> Cache-Control: no-cache
>>>>>>>
>>>>>>> POST / HTTP/1.1
>>>>>>> Accept: */*
>>>>>>> Accept-Language: en-us
>>>>>>> Content-Type: application/octet-stream
>>>>>>> Content-Length: 166
>>>>>>> User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
>>>>>>> Host:
0degree.com
>>>>>>> Connection: Keep-Alive
>>>>>>> Cache-Control: no-cache
>>>>>>>
>>>>>>> There is also some SSL traffic, some of which fails as malformed, and some non-smtp traffic to 25/tcp. If I come up with anything else, I'll let you know, and I'd be curious if anyone else has more info.
>>>>>>>
>>>>>>> Regards,
>>>>>>> Harry
>>>>>>>
>>>>>>> _______________________________________________
>>>>>>> Emerging-sigs mailing list
>>>>>>>
Emerging-sigs-QLpEr2logwxONy2houXFdO9NwHtMwxe5XqFh9Ls21Oc@public.gmane.org
>>>>>>>
http://lists.emergingthreats.net/mailman/listinfo/emerging-sigs
>>>>>>>
>>>>>>> Support Emerging Threats! Subscribe to Emerging Threats Pro
http://www.emergingthreatspro.com
>>>>>>> The ONLY place to get complete premium rulesets for Snort 2.4.0 through Current!
>>>>>
>>>>> _______________________________________________
>>>>> Emerging-sigs mailing list
>>>>>
Emerging-sigs-QLpEr2logwxONy2houXFdO9NwHtMwxe5XqFh9Ls21Oc@public.gmane.org
>>>>>
http://lists.emergingthreats.net/mailman/listinfo/emerging-sigs
>>>>>
>>>>> Support Emerging Threats! Subscribe to Emerging Threats Pro
http://www.emergingthreatspro.com
>>>>> The ONLY place to get complete premium rulesets for Snort 2.4.0 through Current!
>>>
>>
>
>
_______________________________________________
Emerging-sigs mailing list
Emerging-sigs <at> lists.emergingthreats.nethttp://lists.emergingthreats.net/mailman/listinfo/emerging-sigs
Support Emerging Threats! Subscribe to Emerging Threats Pro
http://www.emergingthreatspro.com
The ONLY place to get complete premium rulesets for Snort 2.4.0 through Current!