",fast_pattern,nocase; content:"if(document|2E|getElementById(|22|HideMeBetter|22|)|20 21 3D 20|null)"; metadata:impact_flag red,policy balanced-ips drop,policy max-detect-ips drop,policy security-ips drop,ruleset community; service:http; reference:url,blog.sucuri.net/2013/07/hidemebetter-spam-injection-variant.html; classtype:trojan-activity; sid:27565; rev:2; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Trojan.Rovnix malicious download request"; flow:to_server,established; http_uri; content:"/ld.aspx",nocase; http_header; content:"User-Agent|3A 20|FWVersionTestAgent|0D 0A|",fast_pattern,nocase; metadata:impact_flag red,ruleset community; service:http; reference:url,blog.didierstevens.com/2013/08/04/quickpost-rovnix-pcap; reference:url,blogs.technet.com/b/mmpc/archive/2013/07/25/the-evolution-of-ronvix-private-tcp-ip-stacks.aspx; classtype:trojan-activity; sid:27567; rev:2; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Trojan.Redyms variant outbound connection"; flow:to_server,established; http_uri; content:"&intip=",fast_pattern,nocase; content:"?id="; content:"&port=",distance 0; content:"&bid=",distance 0; metadata:impact_flag red,ruleset community; service:http; reference:url,www.virustotal.com/en/file/1c61afd792257cbc72dc3221deb3d0093f0fc1abf2c3f2816e041e37769137a4/analysis/1375189147/; classtype:trojan-activity; sid:27596; rev:5; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Fort Disco Registration variant outbound connection"; flow:to_server,established; http_uri; content:"/cmd.php"; http_header; content:"User-Agent|3A 20|Mozilla/4.0 (compatible|3B| Synapse)",fast_pattern,nocase; metadata:ruleset community; service:http; reference:url,www.net-security.org/secworld.php?id=15370; classtype:trojan-activity; sid:27599; rev:3; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Backdoor.Aumlib variant outbound connection"; flow:to_server,established; http_uri; content:"/tomcat-docs/index.jsp?/"; http_header; content:"User-Agent|3A| Mozilla/4.0 |28|compatible|3B| MSIE 5.01|3B| Windows NT 5.0|29|",fast_pattern,nocase; metadata:impact_flag red,ruleset community; service:http; classtype:trojan-activity; sid:27629; rev:5; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET any ( msg:"MALWARE-CNC Win.Backdoor.Aumlib variant outbound connection"; flow:to_server,established; content:"/bbs/search.asp"; content:"User-Agent|3A| Mozilla/4.0 |28|compatible|3B| MSIE 5.0|3B| Windows NT 5.0|29|",fast_pattern,nocase; metadata:impact_flag red,ruleset community; service:http; classtype:trojan-activity; sid:27630; rev:5; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET any ( msg:"MALWARE-CNC Win.Backdoor.Aumlib variant outbound connection"; flow:to_server,established; content:"/buy-sell/search.asp?newsid="; content:"User-Agent|3A| Mozilla/4.0 |28|compatible|3B| MSIE 5.0|3B| Windows NT 5.0|29|",fast_pattern,nocase; metadata:impact_flag red,ruleset community; service:http; classtype:trojan-activity; sid:27631; rev:5; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Worm.Silly variant outbound connection"; flow:to_server,established; http_raw_uri; bufferlen:7; http_uri; content:"/ul.htm",fast_pattern,nocase; http_header; content:"|3B| MSIE 6.0|3B 20|"; content:!"Accept-Language: "; metadata:impact_flag red,ruleset community; service:http; reference:url,www.virustotal.com/en/file/0ddd3488b618b17437413a9d579aa111f0a2ba302262d0a9b0d2832718a93524/analysis/; classtype:trojan-activity; sid:27633; rev:4; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Trojan.SpyBanker.ZSL variant outbound connection"; flow:to_server,established; http_method; content:"POST"; http_client_body; content:"valor=",depth 6; content:"]branco[",fast_pattern,nocase; metadata:impact_flag red,ruleset community; service:http; reference:url,www.virustotal.com/en/file/709fa674b301e9123fc2c01e817da21cb29cdfb5a42634a793e27c9533d335b1/analysis/1375811416/; classtype:trojan-activity; sid:27648; rev:4; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Brazilian Banking Trojan data theft"; flow:to_server,established; http_method; content:"POST"; http_client_body; content:"remetente=",depth 10; content:"&destinatario=",distance 0; content:"&assunto=",distance 0; content:"&mensagem=",distance 0; metadata:impact_flag red,ruleset community; service:http; classtype:trojan-activity; sid:27649; rev:2; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Trojan.ZeroAccess variant outbound connection"; flow:to_server,established; http_raw_uri; bufferlen:>95; pkt_data; content:".php HTTP/1.1|0D 0A|User-Agent: Opera/",fast_pattern,nocase; http_uri; pcre:"/(?=^[a-z\x2d\x5f\x2f]{95,}\.php$).*?[a-z]{2,48}\x2d[a-z]{2,48}\x2d[a-z]{2,48}\x2d[a-z]{2,48}\x2d?\.php$/"; metadata:impact_flag red,ruleset community; service:http; classtype:trojan-activity; sid:27680; rev:2; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Ransomware.Urausy outbound connection"; flow:to_server,established; http_uri; bufferlen:>145; content:".html"; pkt_data; content:"|0D 0A|User-Agent|3A| Mozilla/5.0 |28|compatible|3B| MSIE 9.0|3B| Windows NT 6.1|3B| Trident/5.0",fast_pattern,nocase; http_header; content:!"Cookie:"; content:!"X-BlueCoat-Via:"; content:!"Referer"; http_uri; pcre:"/\x2f[a-z-_]{80,}\x2ehtml$/"; metadata:impact_flag red,ruleset community; service:http; reference:url,www.virustotal.com/en/file/f53a483befed8d1494827a3f2444cfe638d3f7e595d72b722eab92d1aca9ede3/analysis/1376847283/; classtype:trojan-activity; sid:27708; rev:8; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Orbit Downloader denial of service update"; flow:to_server,established; http_uri; content:"/update/ido.ipl",fast_pattern,nocase; metadata:impact_flag red,ruleset community; service:http; reference:url,www.welivesecurity.com/2013/08/21/orbital-decay-the-dark-side-of-a-popular-file-downloading-tool; classtype:trojan-activity; sid:27726; rev:3; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Orbit Downloader denial of service update"; flow:to_server,established; http_uri; content:"/update/myinfo.php",fast_pattern,nocase; metadata:impact_flag red,ruleset community; service:http; reference:url,www.welivesecurity.com/2013/08/21/orbital-decay-the-dark-side-of-a-popular-file-downloading-tool; classtype:trojan-activity; sid:27727; rev:3; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Orbit Downloader denial of service update"; flow:to_server,established; http_uri; content:"/update/param.php?",fast_pattern,nocase; metadata:impact_flag red,ruleset community; service:http; reference:url,www.welivesecurity.com/2013/08/21/orbital-decay-the-dark-side-of-a-popular-file-downloading-tool; classtype:trojan-activity; sid:27728; rev:3; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC RDN Banker Data Exfiltration"; flow:to_server,established; http_method; content:"POST"; http_client_body; content:"|3B| name=|22|arquivo|22 3B| filename=|22|C:|5C|",fast_pattern,nocase; content:"_.log|22 0D 0A|"; metadata:impact_flag red,ruleset community; service:http; reference:url,attack.mitre.org/techniques/T1020; classtype:trojan-activity; sid:27774; rev:3; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Trojan.Fareit variant outbound connection"; flow:to_server,established; http_method; content:"GET"; http_uri; content:".htm"; http_header; content:!"Accept"; content:"|0A|Content-Length: 164|0D 0A|User-Agent: ",fast_pattern,nocase; content:"host|3A|",nocase; content:"|2E|",within 5; content:"|2E|",within 4; content:"|2E|",within 4; http_client_body; content:"|6C 55 55 45|",depth 4,offset 4; metadata:impact_flag red,ruleset community; service:http; classtype:trojan-activity; sid:27775; rev:5; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Trojan.PRISM variant outbound connection"; flow:to_server,established; http_uri; content:"/page/index_htm_files2/",nocase; content:".png",within 4,distance 3; metadata:impact_flag red,ruleset community; service:http; reference:url,www.virustotal.com/en/file/417cb84f48d20120b92530c489e9c3ee9a9deab53fddc0dc153f1034d3c52c58/analysis/1377785686/; classtype:trojan-activity; sid:27802; rev:4; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Trojan.PRISM variant outbound connection"; flow:to_server,established; http_uri; content:"/form.php",depth 9; http_client_body; content:"RcpTfdsvoD9KB9O",fast_pattern,nocase; metadata:impact_flag red,ruleset community; service:http; reference:url,www.virustotal.com/en/file/417cb84f48d20120b92530c489e9c3ee9a9deab53fddc0dc153f1034d3c52c58/analysis/1377785686/; classtype:trojan-activity; sid:27803; rev:4; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Trojan.PRISM variant outbound connection"; flow:to_server,established; http_uri; content:"/page/index.php",nocase; http_cookie; content:"foo="; http_client_body; content:"data=RcpTfdssoD9KB9O",depth 20,fast_pattern; metadata:impact_flag red,ruleset community; service:http; reference:url,www.virustotal.com/en/file/417cb84f48d20120b92530c489e9c3ee9a9deab53fddc0dc153f1034d3c52c58/analysis/1377785686/; classtype:trojan-activity; sid:27804; rev:4; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET 443 ( msg:"MALWARE-CNC Win.Trojan.Bisonha variant outbound connection"; flow:to_server,established; content:"GET /3001",fast_pattern; isdataat:260,relative; content:"0000000000000000000000000"; pcre:"/\/3001[0-9A-F]{262,304}/"; metadata:impact_flag red,ruleset community; service:ssl; reference:url,bl0g.cedricpernet.net/post/2013/08/29/APT-More-on-G20Summit-Espionage-Operation; reference:url,www.virustotal.com/en/file/f0d8834fb0e2d3c6e7c1fde7c6bcf9171e5deca119338e4fac21568e0bb70ab7/analysis/; classtype:trojan-activity; sid:27805; rev:2; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"EXPLOIT-KIT Blackholev2/Darkleech exploit kit landing page request"; flow:to_server,established; http_raw_uri; bufferlen:>32; http_uri; content:".php",fast_pattern,nocase; http_method; content:"GET"; http_uri; pcre:"/^\/[a-f0-9]{32}\/[a-z]{1,15}-[a-z]{1,15}\.php/"; http_header; content:!"PacketShaper"; content:!"siteadvisor.com"; metadata:impact_flag red,policy balanced-ips drop,policy max-detect-ips drop,policy security-ips drop,ruleset community; service:http; reference:cve,2012-1889; reference:cve,2012-4681; classtype:trojan-activity; sid:27865; rev:7; )
+alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any ( msg:"EXPLOIT-KIT Blackholev2/Darkleech exploit kit landing page"; flow:to_client,established; file_data; content:"
",fast_pattern,nocase; flowbits:set,file.exploit_kit.jar; metadata:policy balanced-ips drop,policy max-detect-ips drop,policy security-ips drop,ruleset community; service:http; classtype:trojan-activity; sid:27866; rev:2; )
+alert udp $EXTERNAL_NET any -> $SIP_SERVERS $SIP_PORTS ( msg:"PROTOCOL-VOIP Possible SIP OPTIONS service information gathering attempt"; flow:to_server; sip_method:options; content:"SIP/2.0",fast_pattern,nocase; detection_filter:track by_src,count 100,seconds 25; metadata:policy max-detect-ips drop,ruleset community; service:sip; reference:url,blog.sipvicious.org/2008/02/detecting-sip-attacks-with-snort.html; classtype:attempted-recon; sid:27899; rev:4; )
+alert udp $SIP_SERVERS $SIP_PORTS -> $EXTERNAL_NET any ( msg:"PROTOCOL-VOIP Excessive number of SIP 4xx responses potential user or password guessing attempt"; flow:to_client; sip_stat_code:4; content:"SIP/2.0",fast_pattern,nocase; detection_filter:track by_src,count 100,seconds 25; metadata:policy max-detect-ips drop,ruleset community; service:sip; reference:url,blog.sipvicious.org/2008/02/detecting-sip-attacks-with-snort.html; classtype:attempted-recon; sid:27900; rev:4; )
+alert udp $SIP_SERVERS $SIP_PORTS -> $EXTERNAL_NET any ( msg:"PROTOCOL-VOIP Ghost call attack attempt"; flow:to_client; sip_stat_code:180; content:"SIP/2.0",fast_pattern,nocase; detection_filter:track by_src,count 100,seconds 25; metadata:policy max-detect-ips drop,ruleset community; service:sip; reference:url,blog.sipvicious.org/2008/02/detecting-sip-attacks-with-snort.html; classtype:attempted-recon; sid:27901; rev:4; )
+alert tcp $EXTERNAL_NET any -> $SIP_SERVERS $SIP_PORTS ( msg:"PROTOCOL-VOIP Possible SIP OPTIONS service information gathering attempt"; flow:to_server,established,only_stream; sip_method:options; content:"SIP/2.0",fast_pattern,nocase; detection_filter:track by_src,count 100,seconds 25; metadata:policy max-detect-ips drop,ruleset community; service:sip; reference:url,blog.sipvicious.org/2008/02/detecting-sip-attacks-with-snort.html; classtype:attempted-recon; sid:27902; rev:3; )
+alert tcp $SIP_SERVERS $SIP_PORTS -> $EXTERNAL_NET any ( msg:"PROTOCOL-VOIP Ghost call attack attempt"; flow:to_client,established,only_stream; sip_stat_code:180; content:"SIP/2.0",fast_pattern,nocase; detection_filter:track by_src,count 100,seconds 25; metadata:policy max-detect-ips drop,ruleset community; service:sip; reference:url,blog.sipvicious.org/2008/02/detecting-sip-attacks-with-snort.html; classtype:attempted-recon; sid:27903; rev:3; )
+alert tcp $SIP_SERVERS $SIP_PORTS -> $EXTERNAL_NET any ( msg:"PROTOCOL-VOIP Excessive number of SIP 4xx responses potential user or password guessing attempt"; flow:to_client,established,only_stream; sip_stat_code:4; content:"SIP/2.0",fast_pattern,nocase; detection_filter:track by_src,count 100,seconds 25; metadata:policy max-detect-ips drop,ruleset community; service:sip; reference:url,blog.sipvicious.org/2008/02/detecting-sip-attacks-with-snort.html; classtype:attempted-recon; sid:27904; rev:3; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"EXPLOIT-KIT Blackholev2/Cool exploit kit payload download attempt"; flow:to_server,established; http_raw_uri; bufferlen:50<=>150; http_method; content:"GET"; http_header; content:" Java/1.",fast_pattern,nocase; http_uri; content:".php?"; pcre:"/\/(?:[^\/]+?\/[a-z]{2,24}[_-][a-z]{2,16}([_-][a-z]{2,16})*?|closest\/[a-z0-9]{15,25})\.php\?[\(\)\!\*\w-]+=[\(\)\!\*\w-]+&[\(\)\*\!\w-]+=[\(\)\!\*\w-]+$/"; metadata:policy max-detect-ips drop,ruleset community; service:http; classtype:trojan-activity; sid:27907; rev:8; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"PUA-ADWARE Vittalia adware - get ads"; flow:to_server,established; http_uri; content:"/afr.php?zoneid="; http_header; content:"/ads/ox.html"; metadata:policy max-detect-ips drop,ruleset community; service:http; reference:url,www.virustotal.com/en/file/9cdb2b3095cfb94cf8f6204d0f073674dd808b0f742a16216c2f06cf3b5afd50/analysis/1378700802/; classtype:trojan-activity; sid:27913; rev:3; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"PUA-ADWARE Vittalia adware - post install"; flow:to_server,established; http_uri; content:"/report.php?key="; http_header; content:"User-Agent|3A| NSIS_ToolkitOffers (Mozilla)",fast_pattern,nocase; metadata:policy max-detect-ips drop,ruleset community; service:http; reference:url,www.virustotal.com/en/file/9cdb2b3095cfb94cf8f6204d0f073674dd808b0f742a16216c2f06cf3b5afd50/analysis/1378700802/; classtype:trojan-activity; sid:27914; rev:3; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"PUA-ADWARE Vittalia adware outbound connection - pre install"; flow:to_server,established; http_uri; content:"/instapi.php?idMk="; content:"&state=",distance 0; content:"&idTime=",distance 0; content:"&idA2=",distance 0; content:"&xVal=",distance 0; http_header; content:"User-Agent|3A| NSIS_ToolkitOffers (Mozilla)",fast_pattern,nocase; metadata:policy max-detect-ips drop,ruleset community; service:http; reference:url,www.virustotal.com/en/file/9cdb2b3095cfb94cf8f6204d0f073674dd808b0f742a16216c2f06cf3b5afd50/analysis/1378700802/; classtype:trojan-activity; sid:27915; rev:3; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"PUA-TOOLBARS Vittalia adware outbound connection - Eazel toolbar install"; flow:to_server,established; http_uri; content:"/utilsbar/EazelBar.exe"; http_header; content:"User-Agent|3A| NSIS_ToolkitOffers (Mozilla)",fast_pattern,nocase; metadata:policy max-detect-ips drop,ruleset community; service:http; reference:url,www.virustotal.com/en/file/9cdb2b3095cfb94cf8f6204d0f073674dd808b0f742a16216c2f06cf3b5afd50/analysis/1378700802/; classtype:trojan-activity; sid:27916; rev:3; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"PUA-TOOLBARS Vittalia adware outbound connection - offers"; flow:to_server,established; http_uri; content:"/listener.php"; http_header; content:"User-Agent|3A| NSIS_ToolkitOffers (Mozilla)",fast_pattern,nocase; metadata:policy max-detect-ips drop,ruleset community; service:http; reference:url,www.virustotal.com/en/file/9cdb2b3095cfb94cf8f6204d0f073674dd808b0f742a16216c2f06cf3b5afd50/analysis/1378700802/; classtype:trojan-activity; sid:27917; rev:3; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Trojan.Zeus variant outbound connection"; flow:to_server,established; content:".exe HTTP/1.0|0D 0A|Host:",fast_pattern,nocase; http_header; content:"Accept-Encoding: identity, *|3B|q=0|0D 0A|"; content:"|3B| MSIE "; metadata:impact_flag red,ruleset community; service:http; reference:url,www.virustotal.com/en/file/8825abfca1a6d843ce5670858886cb63bb1317ddbb92f91ffd46cfdcaba9ac00/analysis/; classtype:trojan-activity; sid:27918; rev:3; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Trojan.Zeus encrypted POST Data exfiltration"; flow:to_server,established; http_header; content:"Accept-Encoding|3A| identity, *|3B|q=0|0D 0A|",fast_pattern,nocase; content:"|3B| MSIE "; http_client_body; pcre:"/[^ -~\r\n]{4}/"; metadata:impact_flag red,ruleset community; service:http; reference:url,attack.mitre.org/techniques/T1020; reference:url,www.virustotal.com/en/file/8825abfca1a6d843ce5670858886cb63bb1317ddbb92f91ffd46cfdcaba9ac00/analysis/; classtype:trojan-activity; sid:27919; rev:5; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET any ( msg:"MALWARE-CNC Win.Trojan.Gh0st variant outbound connection"; flow:to_server,established; content:"Gh0st",depth 5; content:"|00 00 00|",within 3,distance 1; content:"|00 00 78 9C|",within 4,distance 2; metadata:impact_flag red,ruleset community; reference:url,virustotal.com/en/file/a4fd37b8b9eabd0bfda7293acbb1b6c9f97f8cc3042f3f78ad2b11816e1f9a59/analysis/1425053730/; classtype:trojan-activity; sid:27964; rev:6; )
+alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any ( msg:"MALWARE-CNC Win.Trojan.Eupuds variant connection"; flow:to_client,established; file_data; content:"insert into avs (id, pc,data,ref,country , id_user, mostrar)values(",fast_pattern,nocase; metadata:impact_flag red,ruleset community; service:http; reference:url,www.virustotal.com/en/file/09f4611c05dcff55d4471b90d41b0fd3e6d3289f71321301751008dab75ded4d/analysis/; classtype:trojan-activity; sid:27965; rev:3; )
+alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Backdoor.Chopper web shell connection"; flow:to_server,established; http_header; content:"X-Forwarded-For",nocase; http_client_body; content:"=Response",nocase; content:"FromBase64String",nocase; metadata:impact_flag red,policy balanced-ips drop,policy max-detect-ips drop,policy security-ips drop,ruleset community; service:http; reference:url,attack.mitre.org/techniques/T1100; reference:url,informationonsecurity.blogspot.com/2012/11/china-chopper-webshell.html; reference:url,www.virustotal.com/en/file/BE24561427D754C0C150272CAB5017D5A2DA64D41BEC74416B8AE363FB07FD77/analysis/; classtype:trojan-activity; sid:27966; rev:7; )
+alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Backdoor.Chopper web shell connection"; flow:to_server,established; http_header; content:"X-Forwarded-For",nocase; http_client_body; content:"caidao=",fast_pattern,nocase; pcre:"/caidao\s?=\s?(Response|Write|Execute)/im"; metadata:impact_flag red,policy balanced-ips drop,policy max-detect-ips drop,policy security-ips drop,ruleset community; service:http; reference:url,attack.mitre.org/techniques/T1100; reference:url,informationonsecurity.blogspot.com/2012/11/china-chopper-webshell.html; reference:url,www.virustotal.com/en/file/BE24561427D754C0C150272CAB5017D5A2DA64D41BEC74416B8AE363FB07FD77/analysis/; classtype:trojan-activity; sid:27967; rev:6; )
+alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Backdoor.Chopper web shell connection"; flow:to_server,established; http_header; content:"X-Forwarded-For",nocase; http_client_body; content:"=Execute",nocase; content:"On+Error+Resume+Next:",fast_pattern,nocase; metadata:impact_flag red,policy balanced-ips drop,policy max-detect-ips drop,policy security-ips drop,ruleset community; service:http; reference:url,attack.mitre.org/techniques/T1100; reference:url,informationonsecurity.blogspot.com/2012/11/china-chopper-webshell.html; reference:url,www.virustotal.com/en/file/BE24561427D754C0C150272CAB5017D5A2DA64D41BEC74416B8AE363FB07FD77/analysis/; classtype:trojan-activity; sid:27968; rev:7; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Trojan.Kuluoz outbound command"; flow:to_server,established,only_stream; http_uri; content:"/index.php?"; content:"-dsafe_mode",distance 0; content:"-ddisable_functions",distance 0; content:"-dallow_url_fopen",distance 0; content:"-dallow_url_include",distance 0; content:"-dauto_prepend_file",distance 0; pkt_data; content:"echo.txt"; detection_filter:track by_src,count 20,seconds 60; metadata:impact_flag red,ruleset community; service:http; reference:url,www.virustotal.com/en/file/2d134b69c41fadc5d3a28c90e452323f1c54dd1aa20ac5f5e897feac8d86755a/analysis/; classtype:trojan-activity; sid:28005; rev:4; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-OTHER Win.Trojan.Kuluoz outbound download request"; flow:to_server,established; http_uri; content:"?message=",fast_pattern,nocase; pcre:"/(info|app)\x2ephp\x3fmessage\x3d/"; metadata:impact_flag red,policy max-detect-ips drop,policy security-ips drop,ruleset community; service:http; reference:url,malwaremustdie.blogspot.com/2013/09/302-redirector-new-cushion-attempt-to.html; classtype:trojan-activity; sid:28006; rev:2; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC BLYPT installer startupkey outbound traffic"; flow:to_server,established; http_uri; content:"/index.aspx?info=startupkey_",fast_pattern,nocase; metadata:ruleset community; service:http; reference:url,blog.trendmicro.com/trendlabs-security-intelligence/blypt-a-new-backdoor-family-installed-via-java-exploit; classtype:trojan-activity; sid:28007; rev:2; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC BLYPT installer reuse outbound traffic"; flow:to_server,established; http_uri; content:"/index.aspx?info=reuse",fast_pattern,nocase; metadata:ruleset community; service:http; reference:url,blog.trendmicro.com/trendlabs-security-intelligence/blypt-a-new-backdoor-family-installed-via-java-exploit; classtype:trojan-activity; sid:28008; rev:2; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC BLYPT installer configkey outbound traffic"; flow:to_server,established; http_uri; content:"/index.aspx?info=configkey",fast_pattern,nocase; metadata:ruleset community; service:http; reference:url,blog.trendmicro.com/trendlabs-security-intelligence/blypt-a-new-backdoor-family-installed-via-java-exploit; classtype:trojan-activity; sid:28009; rev:2; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC BLYPT installer tserror outbound traffic"; flow:to_server,established; http_uri; content:"/index.aspx?info=tserror_",fast_pattern,nocase; metadata:ruleset community; service:http; reference:url,blog.trendmicro.com/trendlabs-security-intelligence/blypt-a-new-backdoor-family-installed-via-java-exploit; classtype:trojan-activity; sid:28010; rev:2; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC BLYPT installer createproc outbound traffic"; flow:to_server,established; http_uri; content:"/index.aspx?info=createproc_",fast_pattern,nocase; metadata:ruleset community; service:http; reference:url,blog.trendmicro.com/trendlabs-security-intelligence/blypt-a-new-backdoor-family-installed-via-java-exploit; classtype:trojan-activity; sid:28011; rev:2; )
+alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS ( msg:"MALWARE-CNC Win.Trojan.Bancos variant outbound connection"; flow:to_server,established; http_client_body; content:"from=%20Nome..:",depth 15; metadata:impact_flag red,ruleset community; service:http; reference:url,www.virustotal.com/en/file/d8870137f7f761055a2ac83b03eb3f8fe26015fa0ba99f41551ca59374c6a3ec/analysis/1365436849/; classtype:trojan-activity; sid:28012; rev:2; )
+alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any ( msg:"EXPLOIT-KIT Blackholev2 exploit kit landing page"; flow:to_client,established; file_data; content:"