alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN APT1 WEBC2-UGX Related Pingbed/Downbot User-Agent (Windows+NT+5.x)"; flow:established,to_server; content:"User-Agent|3a| "; http_header; content:"Windows+NT+5"; http_header; within:128; fast_pattern; flowbits:set,ET.webc2ugx; reference:url,www.mandiant.com/apt1; reference:md5,14cfaefa5b8bc6400467fba8af146b71; classtype:trojan-activity; sid:2009486; rev:14; metadata:created_at 2010_07_30, updated_at 2010_07_30;)

Added 2017-08-07 21:02:37 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN APT1 WEBC2-UGX Related Pingbed/Downbot User-Agent (Windows+NT+5.x)"; flow:established,to_server; content:"User-Agent|3a| "; http_header; content:"Windows+NT+5"; http_header; within:128; fast_pattern; flowbits:set,ET.webc2ugx; reference:url,www.mandiant.com/apt1; reference:md5,14cfaefa5b8bc6400467fba8af146b71; classtype:trojan-activity; sid:2009486; rev:16;)

Added 2013-02-22 01:37:14 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Pingbed/Downbot User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"User-Agent|3a| "; http_header; content:"Windows+NT+5"; http_header; within:128; fast_pattern; reference:url,doc.emergingthreats.net/2009486; classtype:trojan-activity; sid:2009486; rev:14;)

Added 2011-12-19 18:45:34 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Pingbed/Downbot User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"User-Agent|3a| "; http_header; content:"Windows+NT+5"; http_header; within:128; reference:url,doc.emergingthreats.net/2009486; classtype:trojan-activity; sid:2009486; rev:13;)

Added 2011-10-20 15:10:33 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Pingbed/Downbot User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"Windows+NT+5"; http_header; fast_pattern:only; reference:url,doc.emergingthreats.net/2009486; classtype:trojan-activity; sid:2009486; rev:11;)

Added 2011-10-19 18:51:44 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Pingbed User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"User-Agent|3a|"; http_header; content:"Windows+NT+5.1|0D 0A|"; http_header; fast_pattern:only; reference:url,doc.emergingthreats.net/2009486; classtype:trojan-activity; sid:2009486; rev:9;)

Added 2011-10-12 19:27:29 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Pingbed User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"User-Agent|3a|"; http_header; content:"Windows+NT+5.1|0D 0A|"; http_header; fast_pattern:only; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2009486; sid:2009486; rev:9;)

Added 2011-09-14 22:40:50 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Pingbed User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"User-Agent|3a|"; http_header; content:"Windows+NT+5.1|0D 0A|"; http_header; fast_pattern:only; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2009486; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/USER_AGENTS/USER_AGENTS_Suspicious; sid:2009486; rev:9;)

Added 2011-06-17 13:31:09 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET USER_AGENTS Suspicious Downloader User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"User-Agent|3a|"; http_header; content:"Windows+NT+5.1|0D 0A|"; http_header; fast_pattern:only; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2009486; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/USER_AGENTS/USER_AGENTS_Suspicious; sid:2009486; rev:7;)

Added 2011-02-04 17:28:49 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET USER_AGENTS Suspicious Downloader User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"|0D 0A|User-Agent\:"; content:"Windows+NT+5.1|0D 0A|"; within:128; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2009486; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/USER_AGENTS/USER_AGENTS_Suspicious; sid:2009486; rev:4;)

Added 2009-10-19 09:15:44 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET USER_AGENTS Suspicious Downloader User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"|0D 0A|User-Agent\:"; content:"Windows+NT+5.1|0D 0A|"; within:128; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2009486; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/USER_AGENTS/USER_AGENTS_Suspicious; sid:2009486; rev:4;)

Added 2009-10-19 09:15:44 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET MALWARE Suspicious Downloader User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"|0D 0A|User-Agent\:"; content:"Windows+NT+5.1|0D 0A|"; within:128; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2009486; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/MALWARE/MALWARE_USER_Agents; sid:2009486; rev:2;)

Added 2009-07-08 19:45:40 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET MALWARE Suspicious Downloader User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"|0D 0A|User-Agent\:"; content:"Windows+NT+5.1|0D 0A|"; within:128; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2009486; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/MALWARE/MALWARE_USER_Agents; sid:2009486; rev:2;)

Added 2009-07-08 19:45:40 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET MALWARE Suspicious Downloader User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"|0D 0A|User-Agent\:"; content:"Windows+NT+5.1|0D 0A|"; within:128; classtype:trojan-activity; sid:2009486; rev:1;)

Added 2009-07-02 22:15:34 UTC


Topic revision: r1 - 2017-08-08 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats