alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE MALWARE User Agent Containing http\:// Suspicious Likely Spyware/Trojan"; flow:to server ...
Snort.Conf Samples The goal of this project is to make a set of sample snort.conf files. These will represent different size and goal installs of snort. We do not ...
JohnMcCash 10 Jan 2008 I have a question for the BleedingThreats audience at large. I was just reading up a bit on Fast Flux DNS configurations, which are being ...
Web Search. Searched: edittable ... Edit Contrib Package Provides subroutines useful in writing plugins that edit and save parts of topics. ... Last modified time ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE TROJAN Win32 ALT C C Initial Infection Checkin"; flow:established,to server; dsize:18; content ...
BlackHoleDNS by David Glosser This project has moved to Malware List. The project files can be found at: BIND format http://www.malwaredomains.com/files/spywaredomains ...
alert udp $HOME NET any $DNS SERVERS 53 (msg:"BLEEDING EDGE DNS Possible MITM lookup for WPAD.com"; content:" 04 wpad 03 com 02 "; nocase; reference:url,support ...
alert udp $HOME NET any $DNS SERVERS 53 (msg:"BLEEDING EDGE DNS Possible MITM lookup for WPAD.net"; content:" 04 wpad 03 net 02 "; nocase; reference:url,support ...
alert udp $HOME NET any $DNS SERVERS 53 (msg:"BLEEDING EDGE DNS Possible MITM lookup for WPAD.co"; content:" 04 wpad 02 co 02 "; nocase; reference:url,support.microsoft ...
Bleeding Edge Threats Projects This page indexes the projects hosted at or closely connected and supported by the Bleeding Edge Threats Community. We highly encourage ...
alert tcp any any any $HTTP PORTS (msg:"BLEEDING EDGE WORM Allaple Unique HTTP Request Possibly part of DDOS"; flow:established,to server; content:"GET / HTTP ...
alert tcp $EXTERNAL NET any $HOME NET any (msg: "BLEEDING EDGE WEB CLIENT Apple Quicktime RTSP Content Type overflow attempt"; flow:established,from server; content ...
alert udp $EXTERNAL NET any $HOME NET any (msg: "BLEEDING EDGE WEB CLIENT Apple Quicktime RTSP Content Type overflow attempt"; content:"RTSP/"; nocase; depth:5 ...
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"BLEEDING EDGE EXPLOIT Possible UTF 16 encoded Shellcode Detected";flow:from server,established;pcre:"/( ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE VIRUS Sality Virus User Agent Detected (SPM ID )"; flow:established,to server; content:"User ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE POLICY Windows 98 User Agent Detected Possible Malware or Non Updated System"; flow:established ...
alert tcp $HOME NET any $EXTERNAL NET 25 (msg:"BLEEDING EDGE POLICY Possible Infection Report Mail Indy Mail lib and No Message Body Priority 3"; flow:established ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE MALWARE Antivirgear.com Fake Anti Spyware User Agent (AntiVirGear)"; flow:established,to server ...
Windows 98 User Agent Sig 2007695 is intended primarily to catch spyware and downloaders that are using Windows 98 user agent strings as fakes. The side benefit is ...
alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"BLEEDING EDGE TROJAN Proxy.Win32.Wopla.ag Server Reply"; dsize:12; flow:established,from server; content ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE MALWARE Popads123.com Related Spyware User Agent (LmaokaazLdr)"; flow:established,to server ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE MALWARE Zredirector.com Related Spyware User Agent (BndDriveLoader)"; flow:established,to ...
alert tcp $HOME NET any $EXTERNAL NET 1863 (msg:"BLEEDING EDGE WORM Singworm MSN message Outbound"; flow:established; content:"Here are the new smiles for MSN, ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE CURRENT EVENTS E Jihad 3.0 DDoS HTTP Activity OUTBOUND"; flow:established,to server; content ...