How to find malicious communication leaving your network
ID: c113659c-b17e-50f4-99e7-14e352a05f0c
STIX ID: report--c113659c-b17e-50f4-99e7-14e352a05f0c
Feed Name: Fox-IT blog
Threat Score
The report explains how Zeus trojan variants use HTTP POSTs to contact C2 servers and commonly leave the Referer header empty; it provides example POST requests and recommends detecting these malicious patterns by observing absent referer fields and abnormal POST frequency, noting that the same heuristic can catch other HTTP-based malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
