r1 - 20 Aug 2008 - 04:30:23 - TWikiGuestYou are here: TWiki >  Main Web > 2008515

alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Hupigon.AZG Checkin"; flow:established,to_server; content:"GET "; depth:4; nocase; content:"|0d 0a|User-Agent|3a 20|Mozilla|2f|3|2e|0|20 28|compatible|3b| Indy Library|29 0d 0a|"; within:300; nocase; uricontent:"eve="; nocase; uricontent:"username="; nocase; uricontent:"anma="; nocase; uricontent:"ver="; nocase; reference:url,www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=143511&sind=0; reference:url,vil.nai.com/vil/content/v_145056.htm; classtype:trojan-activity; sid:2008515; rev:1;)

Added 2008-08-20 00:30:23 UTC

 


Edit | Attach | Printable | Raw View | Backlinks: Web, All Webs | History: r1 | More topic actions
 
Emerging Threats
This site is powered by the TWiki collaboration platformCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback