alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Generic Downloader Checkin Url Detected"; flow:established,to_server; content:"??IP\:"; depth:100; content:"??IP\:"; distance:0; content:"????\:"; distance:0; pcre:"/IP\:\d[1,3]\.\d[1,3]\.\d[1,3]\.\d[1,3]/U"; classtype:trojan-activity; sid:2008766; rev:1;)
Added 2008-11-12 09:15:22 UTC