[Emerging-Sigs] Win32.Trojan-Dropper.Wlock Checkin Signature

Micah Kays micah.d.kays at gmail.com
Wed Oct 5 19:55:32 EDT 2011


alert tcp $HOME_NET any -> any $HTTP_PORTS
(msg:"Win32.Trojan-Dropper.Wlock Checkin"; uricontent:".php?adv=";
uricontent:"&id="; uricontent:"&c="; nocase;
classtype:trojan-activity;
reference:url,http://www.threatexpert.com/report.aspx?md5=881e21645e5ffe1ffb959835f8fdf71d;
sid:2; rev:1;)


More information about the Emerging-sigs mailing list