[Emerging-Sigs] Win32.PEx.Delphi.307674628 Checkin Signature

Micah Kays micah.d.kays at gmail.com
Sun Oct 23 23:31:25 EDT 2011


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN
Win32.PEx.Delphi.307674628 Checkin"; flow:established,to_server;
content:"GET"; http_method; content:"/LogProc.php?mac="; nocase;
http_uri; content:"&mode="; nocase; http_uri; content:"&pCode=";
nocase; http_uri;
reference:url,http://www.threatexpert.com/report.aspx?md5=2700d3fcdd4b8a7c22788db1658d9163;
reference:url,http://threatcenter.crdf.fr/?More&ID=46606&D=CRDF.Malware.Win32.PEx.Delphi.307674628;
classtype:trojan-activity; sid:041; rev:1;)


More information about the Emerging-sigs mailing list