alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"BLEEDING-EDGE TROJAN Win32.Agent.ajx Trojan Reporting to Server"; flow:established,to_server; uricontent:"/count.php?fid="; nocase; uricontent:"&cid="; nocase; uricontent:"&ver="; nocase; uricontent:"&tid="; nocase; uricontent:"&sn="; nocase; uricontent:"&wc="; nocase; classtype:trojan-activity; sid:2006448; rev:1;)
Added 2007-07-30 22:45:40 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"BLEEDING-EDGE TROJAN Win32.Agent.ajx Trojan Reporting to Server": flow:established,to_server; uricontent:"/count.php?fid="; nocase; uricontent:"&cid="; nocase; uricontent:"&ver="; nocase; uricontent:"&tid="; nocase; uricontent:"&sn="; nocase; uricontent:"&wc="; nocase; classtype:trojan-activity; sid:2006448; rev:1;)
Added 2007-07-30 22:30:59 UTC
Topic revision: r1 - 2007-08-29
- ShirkDog?