alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS
(msg: "BLEEDING-
EDGE WORM Merry Storm Worm Christmas Charlie Brown";
flow:established,to_server;
uricontent:"uhavepostcard.com"; nocase;
classtype:trojan-activity;
reference:url,isc.sans.org/diary.html?
storyid=3784; sid:2007998; rev:1;)
Joshua Gimer
_______________________________________________
Bleeding-sigs mailing list
Bleeding-sigs bleedingthreats.net
http://lists.bleedingthreats.net/cgi-bin/
mailman/listinfo/bleeding-sigs
|