alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST"; nocase; http_method; content:"/instlog/?"; nocase; http_uri; fast_pattern; content:"Mozilla/3.0 (compatible|3b 20|TALWinInetHTTPClient"; http_user_agent; depth:45; reference:url,doc.emergingthreats.net/2008322; classtype:trojan-activity; sid:2008322; rev:11; metadata:created_at 2010_07_30, former_category MALWARE, updated_at 2020_10_14;)
Added 2020-10-14 20:54:41 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST"; nocase; http_method; content:"/instlog/?"; nocase; http_uri; fast_pattern; content:"Mozilla/3.0 (compatible|3b 20|TALWinInetHTTPClient"; http_user_agent; depth:45; reference:url,doc.emergingthreats.net/2008322; classtype:trojan-activity; sid:2008322; rev:11; metadata:created_at 2010_07_30, former_category MALWARE, updated_at 2019_10_11;)
Added 2020-08-05 19:05:21 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST"; nocase; http_method; content:"/instlog/?"; nocase; http_uri; fast_pattern; content:"Mozilla/3.0 (compatible|3b 20|TALWinInetHTTPClient"; http_user_agent; depth:45; metadata: former_category MALWARE; reference:url,doc.emergingthreats.net/2008322; classtype:trojan-activity; sid:2008322; rev:11; metadata:created_at 2010_07_30, updated_at 2019_10_11;)
Added 2019-10-11 19:56:26 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST"; nocase; http_method; content:"/instlog/?"; nocase; http_uri; fast_pattern; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b|
TALWinInetHTTPClient?"; http_header; metadata: former_category MALWARE; reference:url,doc.emergingthreats.net/2008322; classtype:trojan-activity; sid:2008322; rev:10; metadata:created_at 2010_07_30, updated_at 2010_07_30;)
Added 2019-09-19 19:25:45 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST"; nocase; http_method; content:"/instlog/?"; nocase; http_uri; fast_pattern; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b|
TALWinInetHTTPClient?"; http_header; reference:url,doc.emergingthreats.net/2008322; classtype:trojan-activity; sid:2008322; rev:10; metadata:created_at 2010_07_30, updated_at 2010_07_30;)
Added 2018-09-13 19:39:49 UTC
Added 2018-09-13 17:53:50 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST"; nocase; http_method; content:"/instlog/?"; nocase; http_uri; fast_pattern; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b|
TALWinInetHTTPClient?"; http_header; reference:url,doc.emergingthreats.net/2008322; classtype:trojan-activity; sid:2008322; rev:10; metadata:created_at 2010_07_30, updated_at 2010_07_30;)
Added 2017-08-07 21:01:29 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST"; nocase; http_method; content:"/instlog/?"; nocase; http_uri; fast_pattern; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b|
TALWinInetHTTPClient?"; http_header; reference:url,doc.emergingthreats.net/2008322; classtype:trojan-activity; sid:2008322; rev:9;)
Added 2012-03-16 17:31:51 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST"; http_method; content:"/instlog/?"; nocase; http_uri; fast_pattern; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b|
TALWinInetHTTPClient?"; http_header; reference:url,doc.emergingthreats.net/2008322; classtype:trojan-activity; sid:2008322; rev:8;)
Added 2011-12-19 18:45:32 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST"; http_method; content:"/instlog/?"; nocase; http_uri; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b|
TALWinInetHTTPClient?"; http_header; reference:url,doc.emergingthreats.net/2008322; classtype:trojan-activity; sid:2008322; rev:7;)
Added 2011-10-12 19:24:53 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST"; http_method; content:"/instlog/?"; nocase; http_uri; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b|
TALWinInetHTTPClient?"; http_header; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2008322; sid:2008322; rev:7;)
Added 2011-09-14 22:38:21 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST"; http_method; content:"/instlog/?"; nocase; http_uri; content:"User-Agent|3a| Mozilla/3.0 (compatible|3b|
TALWinInetHTTPClient?"; http_header; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2008322; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/VIRUS/TROJAN_Fraudload; sid:2008322; rev:7;)
Added 2011-02-04 17:27:26 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST "; depth:5; uricontent:"/instlog/?"; nocase; content:"|0d 0a|User-Agent|3a| Mozilla/3.0 (compatible\;
TALWinInetHTTPClient?"; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2008322; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/VIRUS/TROJAN_Fraudload; sid:2008322; rev:4;)
Added 2009-08-25 21:00:35 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST "; depth:5; uricontent:"/instlog/?"; nocase; content:"|0d 0a|User-Agent|3a| Mozilla/3.0 (compatible\;
TALWinInetHTTPClient?"; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2008322; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/VIRUS/TROJAN_Fraudload; sid:2008322; rev:4;)
Added 2009-08-25 21:00:35 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST "; depth:5; uricontent:"/instlog/?"; nocase; content:"|0d 0a|User-Agent\: Mozilla/3.0 (compatible\;
TALWinInetHTTPClient?"; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2008322; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/VIRUS/TROJAN_Fraudload; sid:2008322; rev:3;)
Added 2009-03-13 20:47:16 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST "; depth:5; uricontent:"/instlog/?"; nocase; content:"|0d 0a|User-Agent\: Mozilla/3.0 (compatible\;
TALWinInetHTTPClient?"; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2008322; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/VIRUS/TROJAN_Fraudload; sid:2008322; rev:3;)
Added 2009-03-13 20:47:16 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST"; depth:4; uricontent:"/instlog/?"; nocase; content:"|0d 0a|User-Agent\: Mozilla/3.0 (compatible\;
TALWinInetHTTPClient?"; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2008322; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/VIRUS/TROJAN_Fraudload; sid:2008322; rev:2;)
Added 2009-02-12 18:21:16 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST"; depth:4; uricontent:"/instlog/?"; nocase; content:"|0d 0a|User-Agent\: Mozilla/3.0 (compatible\;
TALWinInetHTTPClient?"; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2008322; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/VIRUS/TROJAN_Fraudload; sid:2008322; rev:2;)
Added 2009-02-12 18:21:16 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN
FraudLoad?.aww HTTP
CnC? Post"; flow:established,to_server; content:"POST"; depth:4; uricontent:"/instlog/?"; nocase; content:"|0d 0a|User-Agent\: Mozilla/3.0 (compatible\;
TALWinInetHTTPClient?"; classtype:trojan-activity; sid:2008322; rev:1;)
Added 2008-06-24 13:06:31 UTC