alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET TROJAN Delf/Troxen/Zema controller delivering clickfraud instructions"; flow:established,to_client; file_data; content:""; within:5; content:""; distance:16; within:11; classtype:trojan-activity; sid:2014217; rev:1;)

Added 2012-02-06 22:00:20 UTC


Topic revision: r1 - 2012-02-07 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats