Research Article

Characterizing Anomalies in Malware-Generated HTTP Traffic

Table 14

The standard values of the User-Agent header (benign traffic).

BrowserUser-Agent value

Edge Win10Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116, Safari/537.36 Edge/15.15063
Chrome Win7Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36
Firefox-FP Win7Mozilla/5.0 (Windows NT 6.1; rv:51.0) Gecko/20100101 Firefox/51.0
Firefox Win7Mozilla/5.0 (Windows NT 6.1; rv:51.0) Gecko/20100101 Firefox/51.0
IE11 Win7Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko
Chrome Win8.1Mozilla/5.0 (Windows NT 6.3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36
Firefox Win8.1Mozilla/5.0 (Windows NT 6.3; rv:56.0) Gecko/20100101 Firefox/56.0
IE11 Win8.1Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko