<?xml version="1.0" encoding="iso-8859-15"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>TWiki's Main web</title>
<subtitle>The web for users, groups and offices. TWiki is an Enterprise Collaboration Platform.</subtitle>
<link rel="self" type="application/atom+xml" href="http://doc.emergingthreats.net/bin/view/Main/WebAtom"/>
<id>http://doc.emergingthreats.net/bin/view/Main</id>
<rights>Copyright 2008 Emerging Threats and Contributing Authors</rights>
<updated>2008-07-06T20:19:21Z</updated>
<entry>
 <title>2008370</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2008370?t=2008-07-06T20:19:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2008370</id>
 <updated>2008-07-06T20:19:21Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MALWARE Shopcenter.co.kr Spyware Install Report"; flow:established,to server; uricontent:"/RewardInstall ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2001891</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2001891?t=2008-07-06T20:19:21Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2001891</id>
 <updated>2008-07-06T20:19:21Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MALWARE Suspicious User Agent (agent)"; flow: to server,established; content:" 0d 0a User Agent\: agent ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2008077</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2008077?t=2008-07-04T13:35:04Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2008077</id>
 <updated>2008-07-04T13:35:04Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET CURRENT EVENTS Possible Storm Worm EXE Request (fireworks.exe)"; flow:established,to server; content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>SandnetAnalystsGroup</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/SandnetAnalystsGroup?t=2008-07-03T19:55:17Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/SandnetAnalystsGroup</id>
 <updated>2008-07-03T19:55:17Z</updated>
 <summary>SandnetAnalystsGroup Member list (comma separated list): Set GROUP MattJonkman, DeapeshMisra, BlakeHartstein, JamesMcQuaid, AndreDiMino, DavidBianco, TeresaGarner ... (last changed by MattJonkman)</summary>
 <author>
  <name>MattJonkman</name></author>
</entry>
<entry>
 <title>WillForte</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/WillForte?t=2008-07-03T19:37:09Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/WillForte</id>
 <updated>2008-07-03T19:37:09Z</updated>
 <summary>My Links .ATasteOfTWiki view a short introductory presentation on TWiki for beginners .WelcomeGuest starting points on TWiki .TWikiUsersGuide ... (last changed by TWikiRegistrationAgent)</summary>
 <author>
  <name>TWikiRegistrationAgent</name></author>
</entry>
<entry>
 <title>2008367</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2008367?t=2008-07-03T19:30:00Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2008367</id>
 <updated>2008-07-03T19:30:00Z</updated>
 <summary>alert tcp any 20 $HOME NET 25 (msg:"ET MALWARE Possible Windows executable sent when remote host claims to send Javascript"; flow: established; content:" 0d 0a ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2008368</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2008368?t=2008-07-03T19:30:00Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2008368</id>
 <updated>2008-07-03T19:30:00Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN Unknown Keylogger checkin"; flow:established; content:"GET"; depth:4; uricontent:"?mail "; uricontent ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2001685</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2001685?t=2008-07-03T19:24:48Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2001685</id>
 <updated>2008-07-03T19:24:48Z</updated>
 <summary>alert tcp any 20 $HOME NET 25 (msg:"ET MALWARE Possible Windows executable sent when remote host claims to send an image"; flow: established; content:"Content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2001684</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2001684?t=2008-07-03T19:24:48Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2001684</id>
 <updated>2008-07-03T19:24:48Z</updated>
 <summary>alert tcp any $HTTP PORTS $HOME NET any (msg:"ET MALWARE Windows executable sent when remote host claims to send image, Win32"; flow: established; content:"Content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2008369</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2008369?t=2008-07-03T19:24:48Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2008369</id>
 <updated>2008-07-03T19:24:48Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN Keylogger Crack by bahman"; flow:established; content:"POST"; depth:5; content:" message 2b keylogger ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2008366</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2008366?t=2008-07-03T15:12:53Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2008366</id>
 <updated>2008-07-03T15:12:53Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET 82 (msg:"ET TROJAN LD Pinch Checkin (HTTP POST on port 82)"; flow:established,to server; content:"POST "; depth:5; content ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2008185</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2008185?t=2008-07-03T14:34:46Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2008185</id>
 <updated>2008-07-03T14:34:46Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN Win32 Cloaker Related Post Infection Checkin"; flow:established,to server; uricontent:"/log/proc ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2008365</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2008365?t=2008-07-03T04:30:14Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2008365</id>
 <updated>2008-07-03T04:30:14Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MALWARE Suspicious User Agent (Playtech Downloader)"; flow:to server,established; content:" 0d 0a User ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2008363</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2008363?t=2008-07-03T04:30:14Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2008363</id>
 <updated>2008-07-03T04:30:14Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET MALWARE Suspicious User Agent (ISMYIE)"; flow:to server,established; content:" 0d 0a User Agent\: ISMYIE ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>2008364</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/2008364?t=2008-07-03T04:30:14Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/2008364</id>
 <updated>2008-07-03T04:30:14Z</updated>
 <summary>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"ET TROJAN Donkeyp2p Update Detected"; flow:established,to server; content:"GET "; depth:4; uricontent:"donkeyp2p ... (last changed by TWikiGuest)</summary>
 <author>
  <name>TWikiGuest</name></author>
</entry>
<entry>
 <title>SifuKurt</title>
 <link rel="alternate" type="text/html" href="http://doc.emergingthreats.net/bin/view/Main/SifuKurt?t=2008-07-01T23:16:18Z"/>
 <id>http://doc.emergingthreats.net/bin/view/Main/SifuKurt</id>
 <updated>2008-07-01T23:16:18Z</updated>
 <summary>My Links .ATasteOfTWiki view a short introductory presentation on TWiki for beginners .WelcomeGuest starting points on TWiki .TWikiUsersGuide ... (last changed by TWikiRegistrationAgent)</summary>
 <author>
  <name>TWikiRegistrationAgent</name></author>
</entry>
 <!-- <ul>
<li> Set SKIN = rssatom
</li></ul> 
--></feed>