r1 - 19 Dec 2011 - 23:45:34 - TWikiGuestYou are here: TWiki >  Main Web > 2009486

alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Pingbed/Downbot User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"User-Agent|3a| "; http_header; content:"Windows+NT+5"; http_header; within:128; fast_pattern; reference:url,doc.emergingthreats.net/2009486; classtype:trojan-activity; sid:2009486; rev:14;)

Added 2011-12-19 18:45:34 UTC

 


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Pingbed/Downbot User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"User-Agent|3a| "; http_header; content:"Windows+NT+5"; http_header; within:128; reference:url,doc.emergingthreats.net/2009486; classtype:trojan-activity; sid:2009486; rev:13;)

Added 2011-10-20 15:10:33 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Pingbed/Downbot User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"Windows+NT+5"; http_header; fast_pattern:only; reference:url,doc.emergingthreats.net/2009486; classtype:trojan-activity; sid:2009486; rev:11;)

Added 2011-10-19 18:51:44 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Pingbed User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"User-Agent|3a|"; http_header; content:"Windows+NT+5.1|0D 0A|"; http_header; fast_pattern:only; reference:url,doc.emergingthreats.net/2009486; classtype:trojan-activity; sid:2009486; rev:9;)

Added 2011-10-12 19:27:29 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Pingbed User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"User-Agent|3a|"; http_header; content:"Windows+NT+5.1|0D 0A|"; http_header; fast_pattern:only; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2009486; sid:2009486; rev:9;)

Added 2011-09-14 22:40:50 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN Pingbed User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"User-Agent|3a|"; http_header; content:"Windows+NT+5.1|0D 0A|"; http_header; fast_pattern:only; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2009486; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/USER_AGENTS/USER_AGENTS_Suspicious; sid:2009486; rev:9;)

Added 2011-06-17 13:31:09 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET USER_AGENTS Suspicious Downloader User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"User-Agent|3a|"; http_header; content:"Windows+NT+5.1|0D 0A|"; http_header; fast_pattern:only; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2009486; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/USER_AGENTS/USER_AGENTS_Suspicious; sid:2009486; rev:7;)

Added 2011-02-04 17:28:49 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET USER_AGENTS Suspicious Downloader User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"|0D 0A|User-Agent\:"; content:"Windows+NT+5.1|0D 0A|"; within:128; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2009486; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/USER_AGENTS/USER_AGENTS_Suspicious; sid:2009486; rev:4;)

Added 2009-10-19 09:15:44 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET USER_AGENTS Suspicious Downloader User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"|0D 0A|User-Agent\:"; content:"Windows+NT+5.1|0D 0A|"; within:128; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2009486; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/USER_AGENTS/USER_AGENTS_Suspicious; sid:2009486; rev:4;)

Added 2009-10-19 09:15:44 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET MALWARE Suspicious Downloader User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"|0D 0A|User-Agent\:"; content:"Windows+NT+5.1|0D 0A|"; within:128; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2009486; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/MALWARE/MALWARE_USER_Agents; sid:2009486; rev:2;)

Added 2009-07-08 19:45:40 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET MALWARE Suspicious Downloader User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"|0D 0A|User-Agent\:"; content:"Windows+NT+5.1|0D 0A|"; within:128; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2009486; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/MALWARE/MALWARE_USER_Agents; sid:2009486; rev:2;)

Added 2009-07-08 19:45:40 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET MALWARE Suspicious Downloader User-Agent (Windows+NT+5.1)"; flow:established,to_server; content:"|0D 0A|User-Agent\:"; content:"Windows+NT+5.1|0D 0A|"; within:128; classtype:trojan-activity; sid:2009486; rev:1;)

Added 2009-07-02 22:15:34 UTC


Edit | Attach | Printable | Raw View | Backlinks: Web, All Webs | History: r1 | More topic actions
 
Emerging Threats
This site is powered by the TWiki collaboration platformCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback