alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Hupigon.AZG Checkin"; flow:established,to_server; content:"GET "; depth:4; nocase; content:"|0d 0a|User-Agent|3a 20|Mozilla|2f|3|2e|0|20 28|compatible|3b| Indy Library|29 0d 0a|"; within:300; nocase; uricontent:"eve="; nocase; uricontent:"username="; nocase; uricontent:"anma="; nocase; uricontent:"ver="; nocase; reference:url,www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=143511&sind=0; reference:url,vil.nai.com/vil/content/v_145056.htm; classtype:trojan-activity; sid:2008515; rev:1;)
Added 2008-08-20 00:30:23 UTC