alert tcp $EXTERNAL_NET 443 -> $HOME_NET any (msg:"ET TROJAN Saturn Proxy C&C Activity"; flow:established,from_server; dsize:12; content:"|2d 00 00 00|"; offset:0; depth:4; content:"|00 00 55 00 00 00|"; distance:2; classtype:trojan-activity; sid:2007753; rev:2;)
Added 2008-01-31 10:12:23 UTC
alert tcp $EXTERNAL_NET 443 -> $HOME_NET any (msg:"ET TROJAN Saturn Proxy C&C Activity"; flow:established,from_server; dsize:12; content:"|2d 00 00 00|"; offset:0; depth:4; content:"|00 00 55 00 00 00|"; distance:2; classtype:trojan-activity; sid:2007753; rev:2;)
Added 2008-01-31 10:12:23 UTC
alert tcp $EXTERNAL_NET 443 -> $HOME_NET any (msg:"BLEEDING-EDGE TROJAN Saturn Proxy C&C Activity"; flow:established,from_server; dsize:12; content:"|2d 00 00 00|"; offset:0; depth:4; content:"|00 00 55 00 00 00|"; distance:2; classtype:trojan-activity; sid:2007753; rev:1;)
Added 2008-01-10 20:12:09 UTC
http://www.emergingthreats.net/index.php?option=com_content&task=view&id=29&Itemid=1
--
MattJonkman - 11 Jan 2008