<?xml version="1.0"?>
<!--
#*************************************************************
#
#  Copyright (c) 2003-2007, Bleeding Edge Threats
#  All rights reserved.
#
#  Redistribution and use in source and binary forms, with or without modification, are permitted provided that the
#  following conditions are met:
#
#  * Redistributions of source code must retain the above copyright notice, this list of conditions and the following
#    disclaimer.
#  * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the
#    following disclaimer in the documentation and/or other materials provided with the distribution.
#  * Neither the name of the nor the names of its contributors may be used to endorse or promote products derived
#    from this software without specific prior written permission.
#
#  THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS AND ANY EXPRESS OR IMPLIED WARRANTIES,
#  INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
#  DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
#  SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
#  SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
#  WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE
#  USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
#
#
# For more information see http://www.bleedingthreats.net
# All convertable rules from Bleeding Sbort are available in this format.
#
#
-->
<NetworkSensorConfiguration daemonize="yes" debug="no" threaded="yes">
   <Device pcap="no" time-out-msec="500" name="DRAGON-DEFAULT">
      <Interface name="eth0"/>
   </Device>
   <SearchEngines search-groups="1" threads-per-group="1" mq-size="1024" buffer-mq="yes" pre-capture-buffer-size="0" pre-capture-all-events="no" adaptive="yes" disable="no"/>
   <PerformanceReport seconds="0" packets="0" sniffer-only="no" no-search="no" 
                packet-length="no" ports-stats="no"/>
   <Heartbeat rate="60" rollover="0"/>
   <SensorConfig name="DRAGON-DEFAULT" default="no">
      <Configuration>
         <ProtectedNetwork internal-same-as-from="no">
            <Network ip="0.0.0.0" mask="24"/>
         </ProtectedNetwork>
         <Logging ring-buffer="yes" alarmlog-file="no" alarmlog-display="no" 
                  local-db="no" swatch="no">
         </Logging>
		 <SNMPTrap disable="yes" object-id="1.3.6.1.4.1.4471"/>
         <ProbeDetection disable="no" verbose="yes" debug="no"
                         protocol-scan="3" protocol-ping="10" 
                         ports-per-host="5" hosts-per-port="5"
                         distributed-ports-per-host="5" distributed-hosts-per-port="5"
                         max-threshold="50000">
            <PortRange low="0" high="1023" direction="toward"/>
            <PortRange low="1032" high="1032" direction="toward"/>
            <PortRange low="1257" high="1257" direction="toward"/>
            <PortRange low="1520" high="1530" direction="toward"/>
            <PortRange low="2049" high="2049" direction="toward"/>
            <PortRange low="2301" high="2301" direction="toward"/>
            <PortRange low="2745" high="2745" direction="toward"/>
            <PortRange low="3127" high="3127" direction="toward"/>
            <PortRange low="3306" high="3306" direction="toward"/>
            <PortRange low="6000" high="6010" direction="toward"/>
            <PortRange low="6112" high="6112" direction="toward"/>
            <PortRange low="6129" high="6129" direction="toward"/>
            <PortRange low="8999" high="8999" direction="toward"/>
            <PortRange low="20168" high="20168" direction="toward"/>
            <PortRange low="32700" high="33430" direction="toward"/>
            <PortRange low="65506" high="65506" direction="toward"/>
         </ProbeDetection>
         <ActiveResponse disable="yes" interface="eth0" tcp-ecm="no"/>
         <Dynamic cushion="0" logging="yes"/>
         <NetworkLayer log-localhost-traffic="yes" same-address="yes" null-address="yes"
                       favor-old="yes" resv-bit="yes" tcp-frag-first-packet="yes"
                       tcp-frag-flags-overlay="yes" frag-small="32"
                       frag-large="yes" options-check="yes" drop-ttl="2" log-ttl="0"
                       max-mtu="1500" max-mtu-verbose="yes" frag-rebuild-hash="3301"
                       disable="no" verbose="no" debug="no" frag-rebuild="yes" frag-rebuild-size="low">
         </NetworkLayer>
         <TCPState max-sessions="50000" action="none" disable="no"/>
         <TransportLayer port-zero="no"
                         syn-data-max="10" syn-nonzero="yes" tcp-options-check="no"
                         syn-bomb-threshold="500" trust="no" disable="no" debug="no"
                         verbose="yes">
            <StreamRebuilding force-rebuild="yes" min-length="3" rebuild-to="yes" 
                              rebuild-from="yes" rebuild-all="yes" session-window="100"
                              disable="no" debug="no" verbose="no" session-window-size="high"
                              session-rebuild-size="high"/>
        <Flags flags="SF"/>
        <Flags flags="SR"/>
        <Flags flags="FSRPAU"/>
        <Flags flags="FSRPU"/>
        <Flags flags="N"/>
        <Flags flags="FUP"/>
        <Flags flags="FSR"/>
         </TransportLayer>
         <RPCAnalysis verbose="no" any-port="no" inbound-only="yes" disable="no" debug="no">
           <PortMacroName name="R"/>
         </RPCAnalysis>
         <TelnetAnalysis debug="no" verbose="no" disable="no" binary="yes" bad-cmd="yes">
           <Port port="23"/>
         </TelnetAnalysis>
         <FTPAnalysis verbose="no" debug="no" disable="no" port-request-check="yes">
            <Port port="21"/>
         </FTPAnalysis>
         <DNSAnalysis verbose="no" debug="no" disable="no">
            <Port port="53"/>
         </DNSAnalysis>
         <FingerAnalysis verbose="no" debug="no" disable="no">
            <Port port="79"/>
         </FingerAnalysis>
         <SNMPAnalysis verbose="no" debug="no" disable="no">
            <Port port="161"/>
         </SNMPAnalysis>
         <HTTPAnalysis verbose="no" unicode="yes" iis-unicode="yes" 
                      multi-method="yes" null-method="no" doc-root="no" fast-analyze="yes" debug="no" disable="no">
            <Port port="80" direction="toward"/>
            <Port port="8080" direction="toward"/>
            <Port port="3128" direction="toward"/>
         </HTTPAnalysis>
         <RIPAnalysis verbose="no" debug="no" disable="no"/>
         <H225Analysis verbose="no" debug="no" disable="no">
         <Port port="1720" />
         </H225Analysis>
         <SIPAnalysis verbose="no" debug="no" disable="no">
         <Port port="5060" />
         </SIPAnalysis>
         <SMBAnalysis log-netbios-session-failures="yes" log-remote-session-attempts="yes" 
                      log-admin-login-attempts="yes" log-null-login-attempts="yes"
                      debug="no" disable="no" verbose="no">
            <Port port="135"/>
            <Port port="445"/>
            <PortRange direction="any" low="137" high="139"/>
         </SMBAnalysis>
         <ICMPAnalysis large="1400" debug="no" disable="no" verbose="no">
         </ICMPAnalysis>
         <DoSCheck verbose="no" debug="no" disable="no"/>
         <CovertChannelAnalysis loki-check="yes" 
                                debug="no" disable="no" verbose="no"/>
        <PortMacro name="W">
                <Port direction="any" port="80" />
                <Port direction="any" port="8080" />
                <Port direction="any" port="3128" />
        </PortMacro>
        <PortMacro name="U">
                <Port direction="any" port="22" />
                <Port direction="any" port="53" />
                <Port direction="any" port="143" />
                <Port direction="any" port="443" />
                <Port direction="any" port="2049" />
        </PortMacro>
        <PortMacro name="N">
                <Port direction="any" port="23" />
                <Port direction="any" port="53" />
                <Port direction="any" port="80" />
                <Port direction="any" port="135" />
                <Port direction="any" port="139" />
        </PortMacro>
        <PortMacro name="X">
                <PortRange direction="any" low="6000" high="6070" />
        </PortMacro>
        <PortMacro name="H">
                <PortRange direction="any" low="1024" high="65535" />
        </PortMacro>
        <PortMacro name="L">
                <PortRange direction="any" low="0" high="1023" />
        </PortMacro>
        <PortMacro name="A">
                <PortRange direction="any" low="0" high="65535" />
        </PortMacro>
        <PortMacro name="M">
                <Port direction="any" port="161" />
                <Port direction="any" port="162" />
                <PortRange direction="any" low="32770" high="32800" />
        </PortMacro>
        <PortMacro name="S">
                <NotPort direction="any" port="22" />
        </PortMacro>
        <PortMacro name="B">
                <NotPort direction="any" port="80" />
        </PortMacro>
        <PortMacro name="P">
                <Port direction="any" port="21" />
                <Port direction="any" port="80" />
                <Port direction="any" port="119" />
        </PortMacro>
        <PortMacro name="Q">
                <PortRange direction="any" low="27900" high="27999" />
        </PortMacro>
        <PortMacro name="T">
                <Port direction="any" port="21" />
                <Port direction="any" port="23" />
        </PortMacro>
        <PortMacro name="R">
                <Port direction="any" port="111" />
                <PortRange direction="any" low="32768" high="32900" />
        </PortMacro>
      </Configuration>
      <NetworkSignatures>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000930">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="3">
        <ExtendedPattern uri-decode="no" type="binary" pattern="GET"/>
        </Match>
        <Match match-order="1" within="300">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Host/3a"/>
        </Match>
        <Match match-order="2" within="40">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/2e180solutions/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions Update Engine]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.safer-networking.org/index.php?page=threats&detail=212]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001397">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ftrackedevent/2easpx/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="eid/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions Spyware (tracked event reported)]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001399">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2factionurls/2factionurl"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions Spyware (action url reported)]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001400">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fshowme/2easpx/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="partner/5fid/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions Spyware Reporting]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002001">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="keywords/2fkyf"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="partner/5fid/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions Spyware Keywords Download]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002003">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdownloads/2finstallers/2f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="simpleinternet/2f180sainstaller/2eexe"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions Spyware Install]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002048">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fgeodefs/2fgdf"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions Spyware Defs Download]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002099">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fconfig/2easpx/3fdid/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions Spyware config Download]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002354">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fversionconfig/2easpx/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26ver/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions Spyware versionconfig POST]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003057">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2factionurls/2factionurlb"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="partnerid/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions Spyware Actionlibs Download]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003058">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fzango/2fzangoinstaller/2eexe"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions (Zango) Spyware Installer Download]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003059">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fzangotbinstaller/2eexe"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions (Zango) Spyware TB Installer Download]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003060">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fphp/2frpc/5fuci/2ephp"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions (Zango) Spyware Local Stats Post]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003061">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fphp/2fuci/2ephp"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions (Zango) Spyware Event Activity Post]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003170">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fbanman/2fbanman/2easp/3fzoneid/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26task/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26x/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Zango Spyware Activity]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003217">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="config/2easpx"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3fver/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="http"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="negative" pattern="user/2dagent/3a/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions (Zango) Spyware Installer Config 2]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003306">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ftrackedevent/2easpx/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ver/3d"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[ver=\d+\.\d+]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 180solutions Spyware (tracked event 2 reporting)]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003610">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ftbrequest"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26q/3d"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[\/tbrequest\d+\.php]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Zango Spyware (tbrequest data post)]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pf/adware.180search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007607">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fte/2easpx/3fver/3d10"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Zango Spyware version 10.0 Post]]></Description>
        <Reference name="URLREF"><![CDATA[http://usa.kaspersky.com/about-us/news-press-releases.php?smnr_id=900000045]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000327">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/48/6f/73/74/3a/20/77/77/77/2e/32/30/32/30/73/65/61/72/63/68/2e/63/6f/6d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/49/70/41/64/64/72"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Spyware 2020]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/spyware.2020search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000934">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="post"/>
        </Match>
        <Match match-order="1" within="50">
        <ExtendedPattern uri-decode="no" type="binary" pattern="srng/2freg/2ephp/20http"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/0d/0ahost/3a"/>
        </Match>
        <Match match-order="3" within="40">
        <ExtendedPattern uri-decode="no" type="binary" pattern="2020search/2ecom"/>
        </Match>
        <Match match-order="4" within="100">
        <ExtendedPattern uri-decode="no" type="string" pattern="ipaddr/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 2020search Update Engine]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.safer-networking.org/index.php?page=updatehistory&detail=2004-03-04]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001447">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/67/6f/69/64/72/2e/63/61/62"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="/48/6f/73/74/3a/20/77/77/77/2e/77/65/62/6e/65/74/69/6e/66/6f/2e/6e/65/74"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 2nd-thought (W32.Daqa.C) Download]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/adware.secondthought.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003620">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsa/2easpx/3fid/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26refe/3dhttp"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE 51yes.com Spyware Reporting User Activity]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001730">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcgi/2dbin/2fpopupv"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3fid/3d/7b"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE A-d-w-a-r-e.com Activity (popup)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.a-d-w-a-r-e.com]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001735">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fapp/2fvt00/2fucmd/2ephp/3fv/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE A-d-w-a-r-e.com Activity (cmd)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.a-d-w-a-r-e.com]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001761">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fabx/5fsearch/5fwebinstall/2fabx/5fsearch/2ecab"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE ABX Toolbar ActiveX Install]]></Description>
        <Reference name="URLREF"><![CDATA[http://isc.sans.org/diary.php?date=2005-03-04]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003438">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcgi/2dbin/2fsearch/2fmxml/2efcgi/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="terms/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26affiliate/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26subid/3d"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26hits/5fper/5fpage/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Abcsearch.com Spyware Reporting]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001441">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26time/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fnew/5finstall/3fid/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Abox Install Report]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/adware.adultbox.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007601">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3fuid/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26dist/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26npr/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20microsoft/20url/20control"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Advertisementserver.com Spyware Initial Checkin]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007602">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="monitor/2ephp"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3fuid/3d"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[UID=\d+]]></PCRE>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20microsoft/20url/20control"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Advertisementserver.com Spyware Checkin]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001228">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fgames/2fvillains/2easpx"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Advertising.com Data Post (villains)]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/adware.fastseek.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001230">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fgames/2fcakedeal/2easpx"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Advertising.com Data Post (cakedeal)]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/adware.fastseek.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003446">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fclient/2ephp/3fstr/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20"/>
        </Match>
        <Match match-order="2" within="30">
        <ExtendedPattern uri-decode="no" type="string" pattern="indy/20library/29"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Adware Command Client Checkin]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuker.com/container/details/adware_command.php]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001318">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsearch/5f404/2easpx/3faff/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Adwave Agent Access]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.intermute.com/spyware/HuntBar.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001450">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fwtools"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ecab"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Wintools Download/Configure]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.intermute.com/spyware/HuntBar.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001529">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="host/3a"/>
        </Match>
        <Match match-order="1" within="30">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2eak/2dnetworks/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Casalemedia Access, Likely Spyware]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001530">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsyncaksoft/2eda/5f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE ak-networks.com Spyware Code Download]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001737">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fakcore/2edl/5f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE ak-networks.com Spyware Code Install]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002349">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fimage/5fserver/2ecgi/3fsize/3dsmall/26url/3dhttp/3a/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Alexa Spyware Reporting URL]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003219">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdata/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="cli/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26dat/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26ver/3d"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26uid/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Alexa Spyware Reporting]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003606">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdata/2f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26cli/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26dat/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26ver/3d"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26url/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Alexa Spyware Reporting URL Visited]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003619">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fredirect/3fhttp"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="host/3a/20redirect/2ealexa/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Alexa Spyware Redirecting User]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000906">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fpm/2fstart/2easp"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Altnet PeerPoints Manager Start]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/adware.topsearch.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000598">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fbackoffice/2enet/2fstats/2fadd/2easpx"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Altnet PeerPoints Manager Data Submission]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/adware.topsearch.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000907">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fpointsmanager/2fsettings/2ecab/3f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Altnet PeerPoints Manager Settings Download]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/adware.topsearch.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000903">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fie/2fupdatenew/2f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="config"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Avres Agent Receiving Instructions]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.avres.net]]></Reference>
        <Reference name="URLREF"><![CDATA[http://ar.avres.net/ie/updatenew/]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001999">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fa/2fdrk/2esyn/3fadcontext/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE BTGrab.com Spyware Downloading Ads]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.btgrab.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453090726]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003340">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fupdate/2fbarcab/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Baidu.com Spyware Bar Reporting]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.pctools.com/mrc/infections/id/BaiDu/]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003341">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fupdate/2fcab/2floadmovie/2eswf"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="bar/2ebaidu/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Baidu.com Spyware Bar Pulling Content]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.pctools.com/mrc/infections/id/BaiDu/]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003578">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcpro/2fui/2fui"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="baidu/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Baidu.com Spyware Bar Pulling Data]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.pctools.com/mrc/infections/id/BaiDu/]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003605">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fn/3fcmd/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26class/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26pn/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26tn"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Baidu.com Spyware Bar Activity]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.pctools.com/mrc/infections/id/BaiDu/]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003630">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsobar/2fsobar"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Baidu.com Spyware Sobar Bar Activity]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.pctools.com/mrc/infections/id/BaiDu/]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000574">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdownload/2fbargin/5fbuddy"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bargain Buddy]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.doxdesk.com/parasite/BargainBuddy.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001885">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2fcgi/2dbin/2ffav/5fdel/2efcgi/3fid"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Begin2Search.com Spyware]]></Description>
        <Reference name="URLREF"><![CDATA[http://sarc.com/avcenter/venc/data/adware.begin2search.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003209">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcheckin/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="unq/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="version/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20opera/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Best-targeted-traffic.com Spyware Checkin]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003210">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2finstall/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26pais/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="unq/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20opera/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Best-targeted-traffic.com Spyware Install]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003211">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fping/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="ul/3dhttp"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="unq/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20opera/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Best-targeted-traffic.com Spyware Ping]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002955">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fadv/2f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fadload/2ephp/3fa1/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26a2/3dtype/20of/20processor/3a"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26a3/3dwindows/20version/20is/20"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26a4/3dbuild/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bestcount.net Spyware Checkin]]></Description>
        <Reference name="URLREF"><![CDATA[http://reports.internic.net/cgi/whois?whois_nic=bestcount.net&type=domain]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002956">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fvxgame1/2fvxv/2ephp"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bestcount.net Spyware Downloading vxgame]]></Description>
        <Reference name="URLREF"><![CDATA[http://reports.internic.net/cgi/whois?whois_nic=bestcount.net&type=domain]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002957">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fwin32/2eexe"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[\/adv\/\d+\/win32\.exe]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bestcount.net Spyware Initial Infection Download]]></Description>
        <Reference name="URLREF"><![CDATA[http://reports.internic.net/cgi/whois?whois_nic=bestcount.net&type=domain]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003153">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsploit/2eanr"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bestcount.net Spyware Exploit Download]]></Description>
        <Reference name="URLREF"><![CDATA[http://reports.internic.net/cgi/whois?whois_nic=bestcount.net&type=domain]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003154">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fobjects/2focget/2edll"/>
        </Match>
        <Match match-order="1" depth="150">
        <ExtendedPattern uri-decode="no" type="string" pattern="mybest"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bestcount.net Spyware Data Upload]]></Description>
        <Reference name="URLREF"><![CDATA[http://reports.internic.net/cgi/whois?whois_nic=bestcount.net&type=domain]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000366">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdownload/2fcabs/2f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="download/5fcomplete/2ehtm"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Binet (download complete)]]></Description>
        <Reference name="URLREF"><![CDATA[http://sarc.com/avcenter/venc/data/pf/adware.betterinternet.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000367">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdownload/2fcabs/2fset/5fpix/2ephp"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="abetterinternet/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Binet (set_pix)]]></Description>
        <Reference name="URLREF"><![CDATA[http://sarc.com/avcenter/venc/data/pf/adware.betterinternet.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000371">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdownload/2fcabs/2frandreco/2frandreco/2eexe"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="abetterinternet/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Binet (randreco.exe)]]></Description>
        <Reference name="URLREF"><![CDATA[http://sarc.com/avcenter/venc/data/pf/adware.betterinternet.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000593">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fbba/2fflashimages/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Binet Ad Retrieval]]></Description>
        <Reference name="URLREF"><![CDATA[http://sarc.com/avcenter/venc/data/pf/adware.betterinternet.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001198">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdownloads/2fcabs/2ftwtdll/2ftwaintec/2ecab"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Twaintec Download Attempt]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.pestpatrol.com/PestInfo/t/twain-tech.asp]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001199">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ftwain/2fservlet/2ftwain/3fadcontext/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Twaintec Ad Retrieval]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.pestpatrol.com/PestInfo/t/twain-tech.asp]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001216">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdownloads/2frecord/5fdownload/2easp"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Twaintec Reporting Data]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.pestpatrol.com/PestInfo/t/twain-tech.asp]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001339">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fbi/2fservlet/2fthinstallpre"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE BInet Information Upload]]></Description>
        <Reference name="URLREF"><![CDATA[http://sarc.com/avcenter/venc/data/pf/adware.betterinternet.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001576">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fbi/2fservlet/2fthinstallpost"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE BInet Information Install Report]]></Description>
        <Reference name="URLREF"><![CDATA[http://sarc.com/avcenter/venc/data/pf/adware.betterinternet.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2005319">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="5">
        <ExtendedPattern uri-decode="no" type="string" pattern="post/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fzuzu/2ephp/3f/26r/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bizconcept.info Spyware Checkin]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002959">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcntr/2ephp/3fb/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26c/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26d/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Blueskyltd.biz Spyware Checkin]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002960">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdl/2ephp/3fcode1/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26code2/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="dl/2ephp"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="negative" pattern="user/2dagent/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Blueskyltd.biz Spyware Download]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002961">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcntr/2ephp/3fe/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26x/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Blueskyltd.biz Spyware Checkin 2]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002962">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsred2/2eexe"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="sred2"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="negative" pattern="user/2dagent/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE nov.ru Spyware Code Download]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002963">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsynctl/2f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="synctl"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="negative" pattern="user/2dagent/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Generic Spambot-Spyware Access]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002964">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsynctl/2ftask/2efcgi/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="id/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26v/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Generic Spyware Update Download]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002965">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsynctl/2fgetmail/2efcgi/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="synctl"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="negative" pattern="user/2dagent/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Generic Spambot Spam Download]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001345">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fbonziportal/2fbin/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bonziportal Traffic]]></Description>
        <Reference name="URLREF"><![CDATA[http://www3.ca.com/securityadvisor/pest/pest.aspx?id=59256]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002954">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fbravesentry/2eexe"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bravesentry.com Fake Antispyware Download]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.bravesentry.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=BraveSentry&threatid=44152]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003541">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fupdate/2ephp/3fv/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26d/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26vs/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="negative" pattern="user/2dagent/3a/20"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="host/3a/20"/>
        </Match>
        <Match match-order="5" distance="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2ebravesentry/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bravesentry.com Fake Antispyware Updating]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.bravesentry.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=BraveSentry&threatid=44152]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003542">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdownload/2ephp/3f/26advid/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26u/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26p/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="negative" pattern="user/2dagent/3a/20"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="host/3a/20"/>
        </Match>
        <Match match-order="5" distance="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2ebravesentry/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bravesentry.com/Protectwin.com Fake Antispyware Reporting]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.bravesentry.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=BraveSentry&threatid=44152]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001266">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fperl/2fads/2epl"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Browseraid.com Agent Reporting Data]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.browseraid.com]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001304">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fperl/2fuptodate/2epl"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="uptodate/2ebrowseraid/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Browseraid.com Agent Updating]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.browseraid.com]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001501">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="host/3a/20www/2ebullseye/2dnetwork/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Clickspring.net Spyware Reporting]]></Description>
        <Reference name="URLREF"><![CDATA[http://sarc.com/avcenter/venc/data/adware.bargainbuddy.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001451">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fapp/2finternetfuel/2fappwrap/2eexe"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bundleware Spyware Download]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001452">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="referer/3a/20ms/2dits/3amhtml/3afile/3a/2f/2fc/3acounter/2emht/21http/3a/2f/2f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2fcounter/2fhelp3/2echm/3a/3a/2fhelp/2ehtm"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bundleware Spyware CHM Download]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001458">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcounter/2fcounter/5fv3/2ecab"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Bundleware Spyware cab Download]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001531">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="host/3a"/>
        </Match>
        <Match match-order="1" within="26">
        <ExtendedPattern uri-decode="no" type="string" pattern="/2ec4tdownload/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE C4tdownload.com Access, Likely Spyware]]></Description>
        <Reference name="URLREF"><![CDATA[http://sarc.com/avcenter/venc/data/adware.clickdloader.b.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002088">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fjs/2ephp/3fevent/5ftype/3donload/26recurrence/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE C4tdownload.com Spyware Activity]]></Description>
        <Reference name="URLREF"><![CDATA[http://sarc.com/avcenter/venc/data/adware.clickdloader.b.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006403">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="5">
        <ExtendedPattern uri-decode="no" type="binary" pattern="post/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fctrl/2fchkmac/2ephp/3fmac/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE CASClient Spyware/Adware Install  Checkin]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006404">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="5">
        <ExtendedPattern uri-decode="no" type="binary" pattern="post/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fctrl/2fctrv/2ephp"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE CASClient Spyware/Adware Checkin]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003417">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdownload/2fcnsmin"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3ft/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE CNSMIN (3721.com) Spyware Activity]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.spyany.com/program/article_spy_rm_CnsMin.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003418">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdownload/2fcnsup"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3ft/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE CNSMIN (3721.com) Spyware Activity 2]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.spyany.com/program/article_spy_rm_CnsMin.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003419">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdownload/2fautolvsw/2eini/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3ft/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE CNSMIN (3721.com) Spyware Activity 3]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.spyany.com/program/article_spy_rm_CnsMin.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002089">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fx/2fin/2ephp/3fwm/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE CWS qck.cc Spyware Installer (in.php)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076035]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002095">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fx/2ftbd/5fweb/2ephp/3fwm/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE CWS qck.cc Spyware Installer (web.php)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076035]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002931">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fprogs/5ftraff/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE CWS Trafcool.biz Related Installer]]></Description>
        <Reference name="URLREF"><![CDATA[http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076035]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002932">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2flivesupport/2fimage/5ftracker/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="l/3dsupport/26"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="x/3d1/26"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="deptid/3d1/26"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26page/3dhttp"/>
        </Match>
        <Match match-order="5">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26unique/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE CWS Related Installer]]></Description>
        <Reference name="URLREF"><![CDATA[http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076035]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002933">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2f/3fadvid/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="spy/2dsheriff/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE CWS Spy-Sheriff.com Infeced Buy Page Request]]></Description>
        <Reference name="URLREF"><![CDATA[http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076035]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001521">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fdownload/2fcabs/2fTHNALL1L/2fthnall1l/2eexe"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Spywaremover Activity]]></Description>
        <Reference name="URLREF"><![CDATA[http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453087903]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002195">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/26u/3dhttp"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[\/s\?s=[d+]&u=http]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Casalemedia Spyware Reporting URL Visited1]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002196">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/26f/3d"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[\/sd\?s=[d+]&f=\d]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Casalemedia Spyware Reporting URL Visited2]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003366">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fr404/2ephp/3fid/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26url/3dhttp/3a/2f/2f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE qsrch.com/Casalemedia Spyware Reporting URL Visited3]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001041">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fnewdownload/2fnewsetup/2f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="casinone"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Casino on Net Install]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.888casino.net]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001031">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2flogs/2easp/3fmsgid/3d100"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Casino on Net Reporting Data]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.888casino.net]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001032">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fping/2fping/2etxt"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Casino on Net Ping Hit]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.888casino.net]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001033">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsdl/2fcasinov"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Casino on Net Data Download]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.888casino.net]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003358">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fnw3/2fr1/2etxt/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="catchonlife"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Catchonlife.com Spyware]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001494">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fnotify/2ephp/3fpid/3dremupd/26module/3dinstall/26v/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="/26result/3d1/26message/3dsuccess"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ Malware Clickspring.net Spyware Reporting Successful Install]]></Description>
        <Reference name="URLREF"><![CDATA[http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453082745]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001500">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fnotify/2ephp/3fpid/3dctxad/26module/3dndrvexe/26v/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ Malware Clickspring.net Spyware Reporting]]></Description>
        <Reference name="URLREF"><![CDATA[http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453082745]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003607">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fstat/2ephp/3fid/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26web/5fid/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Cnzz.com/Baidu Related Spyware Stat Reporting]]></Description>
        <Reference name="URLREF"><![CDATA[http://vil.nai.com/vil/content/v_140364.htm]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2000931">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fcc/2f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Host/3a/20update/2ecc/2ecometsystems/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ Malware Comet Systems Spyware Traffic]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001050">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcomet/2frequest"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ Malware CometSystems Spyware]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001655">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcontext/2f1/2fup/5fcontext/5f1/2exml"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ Malware Comet Systems Spyware Traffic (context.xml)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453083029]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001658">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="host/3a/20log/2ecc/2ecometsystems/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ Malware Comet Systems Spyware Reporting]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002351">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcc/2f5/2fmasterconfig/2f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fupdate/2exml/3fv/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ Malware Comet Systems Spyware Update Download]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002352">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcontext/2f1/2fup/5fcontext/5f1/2exml/3fv/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ Malware Comet Systems Spyware Context Report]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003307">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fczcontent/2fcursor"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ Malware Comet Systems Spyware Cursor DL]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003216">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fiis2ebs/2easp"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20ei"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ Malware Conduit Connect Toolbar (Many report to be benign)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.conduit.com]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003218">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2fmessage/2f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20ei"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[\/Message\/\S+\/\S+\.xml]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ Malware Conduit Connect Toolbar Message Download(Many report to be benign)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.conduit.com]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003074">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fgetexe/2f/3fwmid/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Content-loader.com Spyware Install]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003075">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fgetdata/2fgetdata/2ephp/3fwmid/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Content-loader.com Spyware Install 2]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003076">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ffdial2/2ephp/3fo/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ MALWARE Content-loader.com (ownusa.info) Spyware Install]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001704">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2faproposclientinstaller/2eexe"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ Malware Context Plus Spyware Install]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001456">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcplog/2f/3flogtype/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="contextpanel/2ecom"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ Malware ContextPanel Reporting]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003462">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2falert/2fget/5fxml"/>
        </Match>
        <Ma