<?xml version="1.0" encoding="iso-8859-15"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>TWiki's Main web</title>
<subtitle>The web for users, groups and offices. TWiki is an Enterprise Collaboration Platform.</subtitle>
<link rel="self" type="application/atom+xml" href="http://doc.emergingthreats.net/bin/view/Main/WebAtom"/>
<id>http://doc.emergingthreats.net/bin/view/Main</id>
<rights>Copyright 2012 Emerging Threats and Contributing Authors</rights>
<updated>2012-02-09T01:36:41Z</updated>
<entry>
 <title>2014198</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2014198?t=2012-02-09T01:36:41Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2014198</id>
 <updated>2012-02-09T01:36:41Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET 1024: (msg:"ET TROJAN ZeuS ICE IX cid in cookie"; content:"POST"; http method; content:" 0D 0A Cookie 3a cid "; pcre: ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2013836</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2013836?t=2012-02-09T01:36:41Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2013836</id>
 <updated>2012-02-09T01:36:41Z</updated>
 <summary>#alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET DELETED HTTP Request to a .cz.tf domain"; flow:to server,established; content:".cz.tf 0D 0A "; fast ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2011923</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2011923?t=2012-02-09T01:36:41Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2011923</id>
 <updated>2012-02-09T01:36:41Z</updated>
 <summary>##alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET DELETED FAKEAV CryptMEN inst.exe Payload Download"; flow:established,from server; content:"Content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>WebStatistics</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/WebStatistics?t=2012-02-08T21:51:30Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/WebStatistics</id>
 <updated>2012-02-08T21:51:30Z</updated>
 <summary>Statistics for Main Web Month: Topic views: Topic saves: File uploads: Most popular topic views: Top contributors for topic save and uploads ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2014217</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2014217?t=2012-02-07T03:00:20Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2014217</id>
 <updated>2012-02-07T03:00:20Z</updated>
 <summary>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET TROJAN Delf/Troxen/Zema controller delivering clickfraud instructions"; flow:established,to client; file ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2014212</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2014212?t=2012-02-07T03:00:19Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2014212</id>
 <updated>2012-02-07T03:00:19Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN MSUpdater POST checkin to CnC"; flow:established,to server; content:"/microsoft/errorpost/default ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2014214</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2014214?t=2012-02-07T03:00:19Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2014214</id>
 <updated>2012-02-07T03:00:19Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN MSUpdater post auth checkin"; flow:established,to server; content:"/search6"; http uri; fast pattern ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2014216</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2014216?t=2012-02-07T03:00:19Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2014216</id>
 <updated>2012-02-07T03:00:19Z</updated>
 <summary>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET TROJAN Delf/Troxen/Zema controller responding to client"; flow:established,to client; file data; content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2014209</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2014209?t=2012-02-07T03:00:19Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2014209</id>
 <updated>2012-02-07T03:00:19Z</updated>
 <summary>alert tcp $EXTERNAL NET 443 $HOME NET any (msg:"ET TROJAN Sykipot SSL Certificate serial number detected"; flow:established,to client; content:" 16 "; content: ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2014213</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2014213?t=2012-02-07T03:00:19Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2014213</id>
 <updated>2012-02-07T03:00:19Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN MSUpdater Connectivity Check to Google"; flow:established,to server; content:"/search?qu "; http ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2014215</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2014215?t=2012-02-07T03:00:19Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2014215</id>
 <updated>2012-02-07T03:00:19Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MOBILE MALWARE Android/Plankton.P Commands Request to CnC Server"; flow:established,to server; content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2014211</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2014211?t=2012-02-07T03:00:19Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2014211</id>
 <updated>2012-02-07T03:00:19Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN MSUpdater alt checkin to CnC"; flow:established,to server; content:"/microsoft/errorpost/default ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2014204</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2014204?t=2012-02-07T03:00:18Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2014204</id>
 <updated>2012-02-07T03:00:18Z</updated>
 <summary>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET CURRENT EVENTS CutePack Exploit Kit JavaScript Variable Detected"; flow:established,to client; content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2014207</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2014207?t=2012-02-07T03:00:18Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2014207</id>
 <updated>2012-02-07T03:00:18Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET CURRENT EVENTS Likely MS12 004 midiOutPlayNextPolyEvent Heap Overflow Midi Filename Requested baby.mid ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2014203</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2014203?t=2012-02-07T03:00:18Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2014203</id>
 <updated>2012-02-07T03:00:18Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET CURRENT EVENTS CUTE IE.html CutePack Exploit Kit Landing Page Request"; flow:established,to server; content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2014206</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2014206?t=2012-02-07T03:00:18Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2014206</id>
 <updated>2012-02-07T03:00:18Z</updated>
 <summary>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"ET CURRENT EVENTS CutePack Exploit Kit Landing Page Detected"; flow:established,to client; content:"button ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
 <!-- <ul>
<li> Set SKIN = rssatom
</li></ul> 
--></feed>
