#alert tcp $HOME_NET 1024: -> $EXTERNAL_NET 1024: (msg:"ET DELETED Vipdataend C&C Traffic Checkin"; flow:established,to_server; dsize:<20; content:"|3a 20|"; offset:2; depth:6; content:"|20 7c 20|"; within:10; reference:url,doc.emergingthreats.net/2007962; classtype:trojan-activity; sid:2007962; rev:9; metadata:created_at 2010_07_30, updated_at 2010_07_30;)

Added 2017-08-07 21:01:10 UTC


#alert tcp $HOME_NET 1024: -> $EXTERNAL_NET 1024: (msg:"ET TROJAN Vipdataend C&C Traffic Checkin"; flow:established,to_server; dsize:<20; content:"|3a 20|"; offset:2; depth:6; content:"|20 7c 20|"; within:10; reference:url,doc.emergingthreats.net/2007962; classtype:trojan-activity; sid:2007962; rev:8;)

Added 2014-06-02 16:55:09 UTC


#alert tcp $HOME_NET 1024: -> $EXTERNAL_NET 1024: (msg:"ET TROJAN Vipdataend C&C Traffic Checkin"; flow:established,to_server; dsize:<20; content:"|3a|"; depth:5; offset:2; content:"|7c| "; within:12; reference:url,doc.emergingthreats.net/2007962; classtype:trojan-activity; sid:2007962; rev:7;)

Added 2011-10-12 19:24:10 UTC


#alert tcp $HOME_NET 1024: -> $EXTERNAL_NET 1024: (msg:"ET TROJAN Vipdataend C&C Traffic Checkin"; flow:established,to_server; dsize:<20; content:"|3a|"; depth:5; offset:2; content:"|7c| "; within:12; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2007962; sid:2007962; rev:7;)

Added 2011-09-14 22:37:39 UTC


#alert tcp $HOME_NET 1024: -> $EXTERNAL_NET 1024: (msg:"ET TROJAN Vipdataend C&C Traffic Checkin"; flow:established,to_server; dsize:<20; content:"|3a|"; depth:5; offset:2; content:"|7c| "; within:12; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2007962; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/VIRUS/TROJAN_Vipdataend; sid:2007962; rev:7;)

Added 2011-02-04 17:27:03 UTC


alert tcp $HOME_NET 1024: -> $EXTERNAL_NET 1024: (msg:"ET TROJAN Vipdataend C&C Traffic - Checkin"; flow:established,to_server; dsize:<20; content:"|3a|"; depth:5; offset:2; content:"|7c| "; within:8; depth:12; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2007962; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/VIRUS/TROJAN_Vipdataend; sid:2007962; rev:6;)

Added 2009-02-13 19:47:26 UTC


alert tcp $HOME_NET 1024: -> $EXTERNAL_NET 1024: (msg:"ET TROJAN Vipdataend C&C Traffic - Checkin"; flow:established,to_server; dsize:<20; content:"|3a|"; depth:5; offset:2; content:"|7c| "; within:8; depth:12; classtype:trojan-activity; sid:2007962; rev:5;)

Added 2009-01-02 17:30:23 UTC

FP - ICA traffic (see pcap)

-- RickChisholm - 05 Feb 2009


alert tcp $HOME_NET any -> $EXTERNAL_NET 1024: (msg:"ET TROJAN Vipdataend C&C Traffic - Checkin"; flow:established,to_server; dsize:<20; content:"|3a|"; depth:5; offset:2; content:"|7c| "; within:8; depth:12; classtype:trojan-activity; sid:2007962; rev:4;)

Added 2008-06-24 23:26:43 UTC


alert tcp $HOME_NET 1024: -> $EXTERNAL_NET 1024: (msg:"ET TROJAN Vipdataend C&C Traffic - Checkin"; flow:established,to_server; dsize:<20; content:"|3a|"; depth:5; offset:2; content:"|7c| "; within:8; depth:12; classtype:trojan-activity; sid:2007962; rev:3;)

Added 2008-05-14 15:47:37 UTC


alert tcp $HOME_NET 1024: -> $EXTERNAL_NET 1024: (msg:"ET TROJAN Vipdataend C&C Traffic - Checkin"; flow:established,to_server; dsize:<20; content:"|3a|"; depth:3; offset:2; content:"|7c| "; within:8; depth:12; classtype:trojan-activity; sid:2007962; rev:2;)

Added 2008-05-14 14:36:14 UTC



alert tcp $HOME_NET 1024: -> $EXTERNAL_NET 1024: (msg:"ET TROJAN Vipdataend C&C Traffic - Checkin"; flow:established,to_server; dsize:<20; content:"HX|3a|212|7c|win "; offset:0; classtype:trojan-activity; sid:2007962; rev:1;)

Added 2008-03-09 20:49:17 UTC

re 0f5a56e87c9c7a328dcd29e012e3f0f8 and fc7538d589ee77929e107f444c038aad

-- MattJonkman - 10 Mar 2008


Topic revision: r7 - 2009-02-24 - MattJonkman
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats