#alert ftp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN ftpchk3.php possible upload success"; flow:to_client,established; content:"|0d 0a|150 "; content:"ftpchk3.php|0d 0a|226 "; distance:0; nocase; reference:url,digitalpbk.blogspot.com/2009/10/ftpchk3-virus-php-pl-hacked-website.html; reference:url,labs.mwrinfosecurity.com/system/assets/131/original/Journey-to-the-Centre-of-the-Breach.pdf; classtype:attempted-admin; sid:2018417; rev:3; metadata:created_at 2014_04_23, updated_at 2014_04_23;)

Added 2020-11-20 19:36:44 UTC


alert ftp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN ftpchk3.php possible upload success"; flow:to_client,established; content:"|0d 0a|150 "; content:"ftpchk3.php|0d 0a|226 "; distance:0; nocase; reference:url,digitalpbk.blogspot.com/2009/10/ftpchk3-virus-php-pl-hacked-website.html; reference:url,labs.mwrinfosecurity.com/system/assets/131/original/Journey-to-the-Centre-of-the-Breach.pdf; classtype:attempted-admin; sid:2018417; rev:3; metadata:created_at 2014_04_23, updated_at 2014_04_23;)

Added 2018-09-13 19:48:43 UTC


Added 2018-09-13 17:58:38 UTC


alert ftp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN ftpchk3.php possible upload success"; flow:to_client,established; content:"|0d 0a|150 "; content:"ftpchk3.php|0d 0a|226 "; distance:0; nocase; reference:url,digitalpbk.blogspot.com/2009/10/ftpchk3-virus-php-pl-hacked-website.html; reference:url,labs.mwrinfosecurity.com/system/assets/131/original/Journey-to-the-Centre-of-the-Breach.pdf; classtype:attempted-admin; sid:2018417; rev:3; metadata:created_at 2014_04_23, updated_at 2014_04_23;)

Added 2017-08-07 21:12:29 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET TROJAN ftpchk3.php possible upload success"; flow:to_client,established; content:"226 Transfer complete"; nocase; flowbits:isset,ET.ftpchk3; reference:url,digitalpbk.blogspot.com/2009/10/ftpchk3-virus-php-pl-hacked-website.html; reference:url,labs.mwrinfosecurity.com/system/assets/131/original/Journey-to-the-Centre-of-the-Breach.pdf; classtype:attempted-admin; sid:2018417; rev:2;)

Added 2014-04-23 18:13:25 UTC


Topic revision: r1 - 2020-11-21 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats