[Emerging-Sigs] High false positive rate ET TROJAN Kazy/Kryptor/Cycbot Checkin 3

matt sendtomatt at gmail.com
Wed Dec 12 17:31:28 HAST 2012

In FreeBSD land, a bug report is called a "PR" (problem report). The cgi
interface for viewing these @ freebsd.org uses ?pr= in the get URL.

Here is an example URL that will trigger the false positive:

This rule may be overly vague, or cause undue concern that a host is
This could be resolved by either making a more specific rule to the
trojan (not sure there)
or changing the language of the rule to include something like "Possible

Please CC me in responses, I'm not subscribed to the list.


Matt M
