Snort mailing list archives

RE: welchia rule


From: "Schmehl, Paul L" <pauls () utdallas edu>
Date: Tue, 4 Nov 2003 09:44:50 -0600

-----Original Message-----
From: David Omar Ortega Aranda [mailto:dortega () uacj mx] 
Sent: Monday, November 03, 2003 5:51 PM
To: snort-users () lists sourceforge net
Subject: [Snort-users] welchia rule

Do any of you have a good working Welchia virus signature?

# This rule is for tracking Nachi infections
alert icmp $HOME_NET any -> any any (msg: "ALERT!!! NACHI Infection!!";
content: "|aaaa aaaa aaaa\
 aaaa aaaa aaaa aaaa aaaa aaaa aaaa aaaa aaaa aaaa aaaa aaaa aaaa aaaa
aaaa aaaa aaaa aaaa aaaa\
 aaaa aaaa aaaa aaaa aaaa aaaa aaaa aaaa aaaa|"; dsize:64; itype: 8;
icode: 0; \
 classtype:trojan-activity; sid: 10000008; rev: 1;)

Paul Schmehl (pauls () utdallas edu)
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/~pauls/ 


-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
Does SourceForge.net help you be more productive?  Does it
help you create better code?   SHARE THE LOVE, and help us help
YOU!  Click Here: http://sourceforge.net/donate/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: