List Info

Thread: A speficic rule for a trojan




A speficic rule for a trojan
country flaguser name
France
2007-03-21 09:23:50
Hello,

One  existing alert (useragent=mozila/4.0)  have detected 
this trojan, 
defined at the url given as reference. This rule can be a
more speficic rule 
for this trojan.


alert tcp any any -> any any (msg: "LOCAL
TROJ_MESPAM.A"; 
flow:to_server,established; 
pcre:"/^Hostx3A[^rn]*px2Esecondsite1x2Ecom/smi&quo
t;;  
classtype:policy-violation; 
reference:url,de.trendmicro-europe.com/enterprise/vinfo/ency
clopedia.php?LYstr=VMAINDATA&vNav=3&VName=TROJ_MESPA
M.A; 
sid:200703190959;rev:1;)


Thierry.
_______________________________________________
Bleeding-sigs mailing list
Bleeding-sigsbleedingthreats.net
http://lists.bleedingthreats.net/cgi-bin/
mailman/listinfo/bleeding-sigs

[1]

about | contact  Other archives ( Real Estate discussion Medical topics )