alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET VIRUS Worm.Pyks HTTP C&C Traffic (User-Agent skw00001)"; flow:established,to_server; content:"User-Agent\: skw000"; depth:50; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2003588; sid:2003588; rev:4;)
Added 2008-01-31 10:12:24 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET VIRUS Worm.Pyks HTTP C&C Traffic (User-Agent skw00001)"; flow:established,to_server; content:"User-Agent\: skw000"; depth:50; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2003588; sid:2003588; rev:4;)
Added 2008-01-31 10:12:24 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"BLEEDING-EDGE VIRUS Worm.Pyks HTTP C&C Traffic (User-Agent skw00001)"; flow:established,to_server; content:"User-Agent\: skw000"; depth:50; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2003588; sid:2003588; rev:3;)
Added 2008-01-09 17:42:41 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"BLEEDING-EDGE VIRUS Worm.Pyks HTTP C&C Traffic (User-Agent skw00001)"; flow:established,to_server; content:"User-Agent\: skw000"; depth:50; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2003588; sid:2003588; rev:3;)
Added 2008-01-09 17:42:41 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"BLEEDING-EDGE VIRUS Worm.Pyks HTTP C&C Traffic (User-Agent skw00001)"; flow:established,to_server; content:"User-Agent\: skw000"; depth:50; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2003588; sid:2003588; rev:3;)
Added 2008-01-09 15:15:19 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"BLEEDING-EDGE VIRUS Worm.Pyks HTTP C&C Traffic (User-Agent skw00001)"; flow:established,to_server; content:"User-Agent\: skw000"; depth:50; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2003588; sid:2003588; rev:3;)
Added 2008-01-09 15:15:19 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"BLEEDING-EDGE VIRUS Worm.Pyks HTTP C&C Traffic (User-Agent skw00001)"; flow:established,to_server; content:"User-Agent\: skw000"; depth:50; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2003588; sid:2003588; rev:3;)
Added 2008-01-08 20:25:20 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"BLEEDING-EDGE VIRUS Worm.Pyks HTTP C&C Traffic (User-Agent skw00001)"; flow:established,to_server; content:"User-Agent\: skw000"; depth:50; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2003588; sid:2003588; rev:3;)
Added 2008-01-08 20:25:20 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"BLEEDING-EDGE CURRENT EVENTS Worm.Pyks HTTP C&C Traffic (User-Agent skw00001)"; flow:established,to_server; content:"User-Agent\: skw000"; depth:50; classtype:trojan-activity; reference:url,doc.bleedingthreats.net/2003588; sid:2003588; rev:1;)
Added 2007-10-29 01:31:02 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"BLEEDING-EDGE CURRENT EVENTS Worm.Pyks HTTP C&C Traffic (User-Agent skw00001)"; flow:established,to_server; content:"User-Agent\: skw000"; depth:50; classtype:trojan-activity; reference:url,doc.bleedingthreats.net/2003588; sid:2003588; rev:1;)
Added 2007-04-15 19:30:23 UTC
More here:
WormPyks
--
MattJonkman - 15 Apr 2007