r1 - 30 Sep 2008 - 12:00:21 - TWikiGuestYou are here: TWiki >  Main Web > 2008493

alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Pushdo Checkin"; flow:established,to_server; content:"GET "; depth:4; uricontent:"m="; uricontent:"&a="; uricontent:"&os="; pcre:"/&os=[a-f0-9]{50}/U"; classtype:trojan-activity; sid:2008493; rev:2;)

Added 2008-09-30 08:00:21 UTC

 


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Pushdo Checkin"; flow:established,to_server; content:"GET "; depth:4; uricontent:"m="; uricontent:"&a="; uricontent:"&os="; pcre:"/&os=[a-f0-9]{50}/U"; classtype:trojan-activity; sid:2008493; rev:2;)

Added 2008-09-30 08:00:21 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Cutwail/W32.Small.avu Dropper"; flow:established,to_server; content:"GET "; depth:4; uricontent:"m="; uricontent:"&a="; uricontent:"&os="; pcre:"/&os=[a-f0-9]{50}/U"; classtype:trojan-activity; sid:2008493; rev:1;)

Added 2008-08-05 09:00:21 UTC


Edit | Attach | Printable | Raw View | Backlinks: Web, All Webs | History: r1 | More topic actions
 
Emerging Threats
This site is powered by the TWiki collaboration platformCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback