alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET MALWARE Suspicious User Agent - Possible Admoke Admware (bdsclk)"; flow: to_server,established; content:"|0d 0a|User-Agent\: bdsclk"; nocase; classtype: trojan-activity; sid:2008743; rev:2;)
Added 2008-11-12 09:15:22 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET MALWARE Suspicious User Agent - Possible Admoke Admware (bdsclk)"; flow: to_server,established; content:"|0d 0a|User-Agent\: bdsclk"; nocase; classtype: trojan-activity; sid:2008743; rev:2;)
Added 2008-11-12 09:15:22 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET MALWARE Suspicious User Agent - Possible Admoke Admware (bdwinrun)"; flow: to_server,established; content:"|0d 0a|User-Agent\: bdsclk"; nocase; classtype: trojan-activity; sid:2008743; rev:1;)
Added 2008-11-08 20:06:45 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET MALWARE Suspicious User Agent - Possible Admoke Admware (bdwinrun)"; flow: to_server,established; content:"|0d 0a|User-Agent\: bdsclk"; nocase; classtype: trojan-activity; sid:2008743; rev:1;)
Added 2008-11-08 20:04:09 UTC