[Emerging-Sigs] "F P" for ET TROJAN Suspicious User-Agent - Possible Trojan Downloader (https) 2008019

Darien Huss dhuss at emergingthreats.net
Wed Sep 24 08:24:13 EDT 2014


Thanks Russell, we'll get that fixed today!

Regards,
Darien

On Tue, Sep 23, 2014 at 6:44 PM, Russell Fulton <r.fulton at auckland.ac.nz>
wrote:

>
> we are seeing several different things using things like this:
>
> User-Agent: HttpSendRequest
>
> I am using the surciata rules which does not check the CR/LF which the
> original rule did.
>
> Russell.
> _______________________________________________
> Emerging-sigs mailing list
> Emerging-sigs at lists.emergingthreats.net
> https://lists.emergingthreats.net/mailman/listinfo/emerging-sigs
>
> Support Emerging Threats! Subscribe to Emerging Threats Pro
> http://www.emergingthreats.net
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.emergingthreats.net/pipermail/emerging-sigs/attachments/20140924/9e26befa/attachment.html>


More information about the Emerging-sigs mailing list