alert http $HOME_NET any -> $EXTERNAL_NET any (
msg:"ET MALWARE Kuluoz Activity";
flow:established,to_server;
http.method;
content:"POST";
http.uri;
pcre:"/\/[A-F0-9]+$/";
http.header_names;
content:!"Referer|0d 0a|";
http.request_body;
content:"name=|22|key|22|"; nocase;
content:"filename=|22|key.bin|22|"; nocase;
content:"name=|22|data|22|"; nocase;
content:"filename=|22|data.bin|22|"; nocase;
reference:md5,c71416a9ec5414fe487167b5bfd921ec;
classtype:trojan-activity;
sid:2017620; rev:5;
metadata:created_at 2013_10_21, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_04_27;
)