Emergingthreats - doc.emergingthreats.net - EmergingThreats's Main web
General Information:
Latest News:
2017372 27 Aug 2013 | 08:15 am
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET CURRENT EVENTS Sweet Orange Landing with Applet Aug 26 2013`; flow:established,from server; file data ... (last changed by TWikiGuest)
2017374 27 Aug 2013 | 08:15 am
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET CURRENT EVENTS CookieBomb Generic PHP Format`; flow:from server,established; file data; content:`echo ... (last changed by TWikiGuest)
2017115 27 Aug 2013 | 08:15 am
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET CURRENT EVENTS Sweet Orange applet July 08 2013`; flow:established,from server; file data; content:` ... (last changed by TWikiGuest)
2017375 27 Aug 2013 | 08:15 am
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET CURRENT EVENTS CookieBomb Generic HTML Format`; flow:from server,established; file data; content:`/R ... (last changed by TWikiGuest)
2017371 27 Aug 2013 | 08:15 am
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:`ET TROJAN Win32/Neurevt.A checkin`; flow:established,to server; content:`POST`; http method; nocase; content ... (last changed by TWikiGuest)
2016851 27 Aug 2013 | 08:15 am
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET CURRENT EVENTS Winwebsec/Zbot/Luder Checkin Response`; flow:established,from server; file data; content ... (last changed by TWikiGuest)
2017373 27 Aug 2013 | 08:15 am
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET CURRENT EVENTS Possible CookieBomb Generic JavaScript Format`; flow:from server,established; file data ... (last changed by TWikiGuest)
2001304 27 Aug 2013 | 08:15 am
#alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:`ET DELETED Browseraid.com Agent Updating`; flow: to server,established; content:`/perl/uptodate.pl`; nocase ... (last changed by TWikiGuest)
2015680 27 Aug 2013 | 08:15 am
#alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET CURRENT EVENTS Blackhole Java applet with obfuscated URL Nov 09 2012`; flow:established,from server ... (last changed by TWikiGuest)
2014143 27 Aug 2013 | 08:15 am
#alert tcp $HOME NET any $EXTERNAL NET any (msg:`ET DELETED PoisonIvy.Esf Keepalive to CnC`; flow:established,to server; content:` ad 4a 6c bb a7 9c 30 3e 44 bc ... (last changed by TWikiGuest)