Research Article

Characterizing Anomalies in Malware-Generated HTTP Traffic

Table 12

Top 10 headers present in requests (malicious traffic) sorted by % of all categories where they appeared.

CategoryPercentage of requests in category
“Host”“User-Agent”“Connection”“Accept”“Accept-Encoding”“Cache-Control”“Content-Length”“Content-Type”“Accept-Language”“Cookie”

Backdoor100.00100.0045.4545.4527.2754.5545.4554.5527.279.09
Banker100.0073.6075.2013.601.6077.6060.8019.204.804.80
Bruteforce100.00100.0087.50100.0012.500.0087.5087.500.0025.00
Clicker100.00100.0030.777.697.6946.1561.5446.150.000.00
DDoS100.0083.3387.500.000.008.334.174.170.000.00
Downloader100.0090.3075.3755.2232.8444.0336.5730.6020.150.75
Downloader/JS100.0083.33100.0083.3383.330.000.000.008.330.00
IP check100.0067.8675.0032.1428.5714.290.000.0028.577.14
Keylogger100.0066.670.000.000.0016.6766.6766.670.000.00
Maldoc100.00100.0081.2581.2581.256.250.000.0025.000.00
Malicious download100.0075.0080.0060.0040.0035.0010.0010.005.000.00
Miner100.0077.7850.0011.1127.780.0038.8938.890.000.00
Other100.0075.0062.5012.5012.5012.5012.5025.0012.5012.50
PUA/Adware100.0080.0066.6723.3313.3343.3340.0033.330.003.33
Ransomware100.0080.0071.7662.3547.0670.5977.6571.7642.351.18
RAT100.0088.8955.5622.2222.2233.3344.4444.440.0011.11
Spambot100.0070.0045.005.005.0040.0075.0035.005.000.00
Stealer100.0057.7886.6735.5613.3311.1166.6768.8926.670.00
Trojan100.0090.6074.3647.8612.8253.8552.1435.909.402.56
UA problem96.1592.3180.7711.5415.3819.2311.5411.540.007.69

Note. The header was present in all requests of a particular request group in the malware category.