alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Dialer.Win32.E-Group.n Checkin"; flow:to_server,established; uricontent:"login="; nocase; uricontent:"&brokerid="; nocase; uricontent:"&extlogin="; nocase; uricontent:"&autosize="; nocase; uricontent:"&icp="; nocase; uricontent:"&id_site="; nocase; uricontent:"&referer1="; nocase; uricontent:"&dl_tracker="; nocase; uricontent:"&connection_type="; nocase; classtype:trojan-activity; sid:2008490; rev:2;)
Added 2008-09-10 15:15:21 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Dialer.Win32.E-Group.n Checkin"; flow:to_server,established; uricontent:"login="; nocase; uricontent:"&brokerid="; nocase; uricontent:"&extlogin="; nocase; uricontent:"&autosize="; nocase; uricontent:"&icp="; nocase; uricontent:"&id_site="; nocase; uricontent:"&referer1="; nocase; uricontent:"&dl_tracker="; nocase; uricontent:"&connection_type="; nocase; classtype:trojan-activity; sid:2008490; rev:2;)
Added 2008-09-10 15:15:21 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Dialer.Win32.E-Group.n Checkin"; flow:to_server,established; uricontent:"login="; nocase; uricontent:"&brokerid="; nocase; uricontent:"&extlogin="; nocase; uricontent:"&autosize="; nocase; uricontent:"&icp="; nocase; uricontent:"&id_site="; nocase; uricontent:"&referer1="; nocase; uricontent:"&dl_tracker="; nocase; uricontent:"&connection_type="; nocase; sid:2008490; rev:1;)
Added 2008-08-02 17:00:22 UTC