alert tcp $HOME_NET any -> $EXTERNAL_NET 1433 (msg:"ET TROJAN Bancos.DV MSSQL CnC? Connection Outbound"; flow:to_server,established; flowbits:isset,ET.MSSQL; content:"|49 00 B4 00 4D 00 20 00 54 00 48 00 45 00 20 00 4D 00 41 00 53 00 54 00 45 00 52 00|"; classtype:trojan-activity; sid:2013411; rev:1;)

Added 2011-11-16 19:57:12 UTC


Topic revision: r1 - 2011-11-17 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats