alert http $HOME_NET any -> $EXTERNAL_NET any (
msg:"ET MALWARE Win32.Trojan.Agent.U3D7V0 Checkin";
flow:established, to_server;
http.method;
content:"GET";
http.uri;
content:"/getc";
content:"/?c="; fast_pattern;
pcre:"/^\/getc(?:loud|onf)\/\?c=/i";
http.header_names;
content:!"User-Agent|0d 0a|";
content:!"Referer|0d 0a|";
reference:md5,97572a7a0690ba1643525bf6666b74c6;
classtype:command-and-control;
sid:2018530; rev:5;
metadata:created_at 2014_06_05, signature_severity Major, updated_at 2020_09_24;
)