alert tcp $HOME_NET any -> $EXTERNAL_NET 1024: (msg:"ET TROJAN Backdoor.Win32.VB.fdi Bot Reporting to Controller"; flow:established,to_server; content:"state\: 0 - zombie is ready for control"; depth:38; classtype:trojan-activity; sid:2008507; rev:1;)
Added 2008-08-17 00:01:47 UTC
From an outbound packet on port 2222 like:
state: 0 - zombie is ready for control | 1.0.0
--
MattJonkman - 17 Aug 2008