alert tcp $HOME_NET any -> $EXTERNAL_NET 1024: (msg:"ET TROJAN Beizhu/Womble/Vipdataend Checking with Controller"; flow:established,to_server; dsize:<70; content:"\:Windows"; depth:11; offset:2; content:"|7c|212("; distance:2; within:11; content:"Mhz)\:|7c|"; distance:0; classtype:trojan-activity; sid:2008334; rev:1;)
Added 2008-06-25 12:36:14 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET 1024: (msg:"ET TROJAN Beizhu/Womble/Vipdataend Checking with Controller"; flow:established,to_server; dsize:<70; content:"\:Windows"; depth:11; offset:2; content:"|7c|212("; distance:2; within:11; content:"Mhz)\:|7c|"; distance:0; classtype:trojan-activity; sid:2008334; rev:1;)
Added 2008-06-25 12:33:35 UTC