logo

How to find malicious communication leaving your network

ID: c113659c-b17e-50f4-99e7-14e352a05f0c

STIX ID: report--c113659c-b17e-50f4-99e7-14e352a05f0c

Feed Name: Fox-IT blog

Threat Score
65/100

Date Published: 2012-06-21

Date Updated: 2026-04-27

Author: Fox It

...
...

The report explains how Zeus trojan variants use HTTP POSTs to contact C2 servers and commonly leave the Referer header empty; it provides example POST requests and recommends detecting these malicious patterns by observing absent referer fields and abnormal POST frequency, noting that the same heuristic can catch other HTTP-based malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.