alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST"; nocase; http_method; content:".php"; http_uri; content:"Mozilla/3.0|20|(compatible|3b 20|Indy|20|Library)"; http_user_agent; depth:38; content:"Nick+Key+Ativado"; fast_pattern; http_client_body; reference:url,doc.emergingthreats.net/2008338; classtype:trojan-activity; sid:2008338; rev:11; metadata:created_at 2010_07_30, former_category MALWARE, updated_at 2020_11_02;)
Added 2020-11-02 18:29:13 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST"; nocase; http_method; content:".php"; http_uri; content:"Mozilla/3.0|20|(compatible|3b 20|Indy|20|Library)"; http_user_agent; depth:38; content:"Nick+Key+Ativado"; fast_pattern; http_client_body; reference:url,doc.emergingthreats.net/2008338; classtype:trojan-activity; sid:2008338; rev:11; metadata:created_at 2010_07_30, former_category MALWARE, updated_at 2020_02_24;)
Added 2020-08-05 19:05:21 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST"; nocase; http_method; content:".php"; http_uri; content:"Mozilla/3.0|20|(compatible|3b 20|Indy|20|Library)"; http_user_agent; depth:38; content:"Nick+Key+Ativado"; fast_pattern; http_client_body; metadata: former_category MALWARE; reference:url,doc.emergingthreats.net/2008338; classtype:trojan-activity; sid:2008338; rev:11; metadata:created_at 2010_07_30, updated_at 2020_02_24;)
Added 2020-02-24 20:10:48 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST"; nocase; http_method; content:".php"; http_uri; content:"Mozilla/3.0 (compatible|3b 20|Indy Library)"; http_user_agent; depth:38; content:"Nick+Key+Ativado"; fast_pattern; metadata: former_category MALWARE; reference:url,doc.emergingthreats.net/2008338; classtype:trojan-activity; sid:2008338; rev:10; metadata:created_at 2010_07_30, updated_at 2019_10_11;)
Added 2019-10-11 19:56:27 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST"; nocase; http_method; content:".php"; http_uri; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b| Indy Library)"; http_header; content:"Nick+Key+Ativado"; fast_pattern; metadata: former_category MALWARE; reference:url,doc.emergingthreats.net/2008338; classtype:trojan-activity; sid:2008338; rev:9; metadata:created_at 2010_07_30, updated_at 2010_07_30;)
Added 2019-09-26 19:56:13 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST"; nocase; http_method; content:".php"; http_uri; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b| Indy Library)"; http_header; content:"Nick+Key+Ativado"; fast_pattern; reference:url,doc.emergingthreats.net/2008338; classtype:trojan-activity; sid:2008338; rev:9; metadata:created_at 2010_07_30, updated_at 2010_07_30;)
Added 2018-09-13 19:39:50 UTC
Added 2018-09-13 17:53:51 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST"; nocase; http_method; content:".php"; http_uri; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b| Indy Library)"; http_header; content:"Nick+Key+Ativado"; fast_pattern; reference:url,doc.emergingthreats.net/2008338; classtype:trojan-activity; sid:2008338; rev:9; metadata:created_at 2010_07_30, updated_at 2010_07_30;)
Added 2017-08-07 21:01:30 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST"; nocase; http_method; content:".php"; http_uri; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b| Indy Library)"; http_header; content:"Nick+Key+Ativado"; fast_pattern; reference:url,doc.emergingthreats.net/2008338; classtype:trojan-activity; sid:2008338; rev:8;)
Added 2011-12-19 18:45:32 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST"; nocase; http_method; content:".php"; http_uri; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b| Indy Library)"; http_header; content:"Nick+Key+Ativado"; reference:url,doc.emergingthreats.net/2008338; classtype:trojan-activity; sid:2008338; rev:7;)
Added 2011-10-12 19:24:55 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST"; nocase; http_method; content:".php"; http_uri; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b| Indy Library)"; http_header; content:"Nick+Key+Ativado"; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2008338; sid:2008338; rev:7;)
Added 2011-09-14 22:38:23 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST"; nocase; http_method; content:".php"; http_uri; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b| Indy Library)"; http_header; content:"Nick+Key+Ativado"; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2008338; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/VIRUS/TROJAN_Klog; sid:2008338; rev:7;)
Added 2011-02-04 17:27:27 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST "; depth:5; uricontent:".php"; content:"|0d 0a|User-Agent\: Mozilla/3.0 (compatible\; Indy Library)"; content:"Nick+Key+Ativado"; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2008338; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/VIRUS/TROJAN_Klog; sid:2008338; rev:3;)
Added 2009-03-13 20:47:16 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST "; depth:5; uricontent:".php"; content:"|0d 0a|User-Agent\: Mozilla/3.0 (compatible\; Indy Library)"; content:"Nick+Key+Ativado"; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2008338; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/VIRUS/TROJAN_Klog; sid:2008338; rev:3;)
Added 2009-03-13 20:47:16 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST"; depth:5; uricontent:".php"; content:"|0d 0a|User-Agent\: Mozilla/3.0 (compatible\; Indy Library)"; content:"Nick+Key+Ativado"; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2008338; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/VIRUS/TROJAN_Klog; sid:2008338; rev:2;)
Added 2009-02-13 19:15:24 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST"; depth:5; uricontent:".php"; content:"|0d 0a|User-Agent\: Mozilla/3.0 (compatible\; Indy Library)"; content:"Nick+Key+Ativado"; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2008338; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/VIRUS/TROJAN_Klog; sid:2008338; rev:2;)
Added 2009-02-13 19:15:24 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN KLog Nick Keylogger Checkin"; flow:established,to_server; content:"POST"; depth:5; uricontent:".php"; content:"|0d 0a|User-Agent\: Mozilla/3.0 (compatible\; Indy Library)"; content:"Nick+Key+Ativado"; classtype:trojan-activity; sid:2008338; rev:1;)
Added 2008-06-25 15:19:57 UTC