<?xml version="1.0"?>
<!--
#*************************************************************
#
#  Copyright (c) 2003-2007, Bleeding Edge Threats
#  All rights reserved.
#
#  Redistribution and use in source and binary forms, with or without modification, are permitted provided that the
#  following conditions are met:
#
#  * Redistributions of source code must retain the above copyright notice, this list of conditions and the following
#    disclaimer.
#  * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the
#    following disclaimer in the documentation and/or other materials provided with the distribution.
#  * Neither the name of the nor the names of its contributors may be used to endorse or promote products derived
#    from this software without specific prior written permission.
#
#  THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS AS IS AND ANY EXPRESS OR IMPLIED WARRANTIES,
#  INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
#  DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
#  SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
#  SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
#  WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE
#  USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
#
#
# For more information see http://www.bleedingthreats.net
# All convertable rules from Bleeding Sbort are available in this format.
#
#
-->
<NetworkSensorConfiguration daemonize="yes" debug="no" threaded="yes">
   <Device pcap="no" time-out-msec="500" name="DRAGON-DEFAULT">
      <Interface name="eth0"/>
   </Device>
   <SearchEngines search-groups="1" threads-per-group="1" mq-size="1024" buffer-mq="yes" pre-capture-buffer-size="0" pre-capture-all-events="no" adaptive="yes" disable="no"/>
   <PerformanceReport seconds="0" packets="0" sniffer-only="no" no-search="no" 
                packet-length="no" ports-stats="no"/>
   <Heartbeat rate="60" rollover="0"/>
   <SensorConfig name="DRAGON-DEFAULT" default="no">
      <Configuration>
         <ProtectedNetwork internal-same-as-from="no">
            <Network ip="0.0.0.0" mask="24"/>
         </ProtectedNetwork>
         <Logging ring-buffer="yes" alarmlog-file="no" alarmlog-display="no" 
                  local-db="no" swatch="no">
         </Logging>
		 <SNMPTrap disable="yes" object-id="1.3.6.1.4.1.4471"/>
         <ProbeDetection disable="no" verbose="yes" debug="no"
                         protocol-scan="3" protocol-ping="10" 
                         ports-per-host="5" hosts-per-port="5"
                         distributed-ports-per-host="5" distributed-hosts-per-port="5"
                         max-threshold="50000">
            <PortRange low="0" high="1023" direction="toward"/>
            <PortRange low="1032" high="1032" direction="toward"/>
            <PortRange low="1257" high="1257" direction="toward"/>
            <PortRange low="1520" high="1530" direction="toward"/>
            <PortRange low="2049" high="2049" direction="toward"/>
            <PortRange low="2301" high="2301" direction="toward"/>
            <PortRange low="2745" high="2745" direction="toward"/>
            <PortRange low="3127" high="3127" direction="toward"/>
            <PortRange low="3306" high="3306" direction="toward"/>
            <PortRange low="6000" high="6010" direction="toward"/>
            <PortRange low="6112" high="6112" direction="toward"/>
            <PortRange low="6129" high="6129" direction="toward"/>
            <PortRange low="8999" high="8999" direction="toward"/>
            <PortRange low="20168" high="20168" direction="toward"/>
            <PortRange low="32700" high="33430" direction="toward"/>
            <PortRange low="65506" high="65506" direction="toward"/>
         </ProbeDetection>
         <ActiveResponse disable="yes" interface="eth0" tcp-ecm="no"/>
         <Dynamic cushion="0" logging="yes"/>
         <NetworkLayer log-localhost-traffic="yes" same-address="yes" null-address="yes"
                       favor-old="yes" resv-bit="yes" tcp-frag-first-packet="yes"
                       tcp-frag-flags-overlay="yes" frag-small="32"
                       frag-large="yes" options-check="yes" drop-ttl="2" log-ttl="0"
                       max-mtu="1500" max-mtu-verbose="yes" frag-rebuild-hash="3301"
                       disable="no" verbose="no" debug="no" frag-rebuild="yes" frag-rebuild-size="low">
         </NetworkLayer>
         <TCPState max-sessions="50000" action="none" disable="no"/>
         <TransportLayer port-zero="no"
                         syn-data-max="10" syn-nonzero="yes" tcp-options-check="no"
                         syn-bomb-threshold="500" trust="no" disable="no" debug="no"
                         verbose="yes">
            <StreamRebuilding force-rebuild="yes" min-length="3" rebuild-to="yes" 
                              rebuild-from="yes" rebuild-all="yes" session-window="100"
                              disable="no" debug="no" verbose="no" session-window-size="high"
                              session-rebuild-size="high"/>
        <Flags flags="SF"/>
        <Flags flags="SR"/>
        <Flags flags="FSRPAU"/>
        <Flags flags="FSRPU"/>
        <Flags flags="N"/>
        <Flags flags="FUP"/>
        <Flags flags="FSR"/>
         </TransportLayer>
         <RPCAnalysis verbose="no" any-port="no" inbound-only="yes" disable="no" debug="no">
           <PortMacroName name="R"/>
         </RPCAnalysis>
         <TelnetAnalysis debug="no" verbose="no" disable="no" binary="yes" bad-cmd="yes">
           <Port port="23"/>
         </TelnetAnalysis>
         <FTPAnalysis verbose="no" debug="no" disable="no" port-request-check="yes">
            <Port port="21"/>
         </FTPAnalysis>
         <DNSAnalysis verbose="no" debug="no" disable="no">
            <Port port="53"/>
         </DNSAnalysis>
         <FingerAnalysis verbose="no" debug="no" disable="no">
            <Port port="79"/>
         </FingerAnalysis>
         <SNMPAnalysis verbose="no" debug="no" disable="no">
            <Port port="161"/>
         </SNMPAnalysis>
         <HTTPAnalysis verbose="no" unicode="yes" iis-unicode="yes" 
                      multi-method="yes" null-method="no" doc-root="no" fast-analyze="yes" debug="no" disable="no">
            <Port port="80" direction="toward"/>
            <Port port="8080" direction="toward"/>
            <Port port="3128" direction="toward"/>
         </HTTPAnalysis>
         <RIPAnalysis verbose="no" debug="no" disable="no"/>
         <H225Analysis verbose="no" debug="no" disable="no">
         <Port port="1720" />
         </H225Analysis>
         <SIPAnalysis verbose="no" debug="no" disable="no">
         <Port port="5060" />
         </SIPAnalysis>
         <SMBAnalysis log-netbios-session-failures="yes" log-remote-session-attempts="yes" 
                      log-admin-login-attempts="yes" log-null-login-attempts="yes"
                      debug="no" disable="no" verbose="no">
            <Port port="135"/>
            <Port port="445"/>
            <PortRange direction="any" low="137" high="139"/>
         </SMBAnalysis>
         <ICMPAnalysis large="1400" debug="no" disable="no" verbose="no">
         </ICMPAnalysis>
         <DoSCheck verbose="no" debug="no" disable="no"/>
         <CovertChannelAnalysis loki-check="yes" 
                                debug="no" disable="no" verbose="no"/>
        <PortMacro name="W">
                <Port direction="any" port="80" />
                <Port direction="any" port="8080" />
                <Port direction="any" port="3128" />
        </PortMacro>
        <PortMacro name="U">
                <Port direction="any" port="22" />
                <Port direction="any" port="53" />
                <Port direction="any" port="143" />
                <Port direction="any" port="443" />
                <Port direction="any" port="2049" />
        </PortMacro>
        <PortMacro name="N">
                <Port direction="any" port="23" />
                <Port direction="any" port="53" />
                <Port direction="any" port="80" />
                <Port direction="any" port="135" />
                <Port direction="any" port="139" />
        </PortMacro>
        <PortMacro name="X">
                <PortRange direction="any" low="6000" high="6070" />
        </PortMacro>
        <PortMacro name="H">
                <PortRange direction="any" low="1024" high="65535" />
        </PortMacro>
        <PortMacro name="L">
                <PortRange direction="any" low="0" high="1023" />
        </PortMacro>
        <PortMacro name="A">
                <PortRange direction="any" low="0" high="65535" />
        </PortMacro>
        <PortMacro name="M">
                <Port direction="any" port="161" />
                <Port direction="any" port="162" />
                <PortRange direction="any" low="32770" high="32800" />
        </PortMacro>
        <PortMacro name="S">
                <NotPort direction="any" port="22" />
        </PortMacro>
        <PortMacro name="B">
                <NotPort direction="any" port="80" />
        </PortMacro>
        <PortMacro name="P">
                <Port direction="any" port="21" />
                <Port direction="any" port="80" />
                <Port direction="any" port="119" />
        </PortMacro>
        <PortMacro name="Q">
                <PortRange direction="any" low="27900" high="27999" />
        </PortMacro>
        <PortMacro name="T">
                <Port direction="any" port="21" />
                <Port direction="any" port="23" />
        </PortMacro>
        <PortMacro name="R">
                <Port direction="any" port="111" />
                <PortRange direction="any" low="32768" high="32900" />
        </PortMacro>
      </Configuration>
      <NetworkSignatures>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002695">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20PE/2d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS Generic Downloader Outbound HTTP connection - Downloading Code]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2001764">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="uv/2bLRCQID7dIDFEECggDSLm9df8C/2fzSNKDBBAAoGA0AEUQ/2bFEN23f7doqAT/2fdCQk/2fxWcEQmDxCTD"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS - Bugbear@MM virus in SMTP]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.symantec.com/avcenter/venc/data/w32.bugbear@mm.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="139" match-neg-port="no" follow-on-sig="no" name="DC:2001765">
        <ExtendedLanguage src-port="any" dst-port="139">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/24/48/fb/bb/ff/e6/63/02/3a/20/41/70/61/63/68/65"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS - BugBear@MM virus in Network share]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.symantec.com/avcenter/venc/data/w32.bugbear@mm.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="139" match-neg-port="no" follow-on-sig="no" name="DC:2001766">
        <ExtendedLanguage src-port="any" dst-port="139">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/77/00/69/00/6b/00/2e/00/65/00/78/00/65/00/00/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS - BugBear@MM Worm Copied to Startup Folder]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.symantec.com/avcenter/venc/data/w32.bugbear@mm.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002892">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="UEsDBAoA"/>
        </Match>
        <Match match-order="1" within="16" distance="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="ojRrPyGt"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS Mytob.X [clam] SMTP Inbound]]></Description>
        <Reference name="URLREF"><![CDATA[http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=42326]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002893">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="UEsDBAoA"/>
        </Match>
        <Match match-order="1" within="16" distance="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="ojRrPyGt"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS Mytob.X [clam] SMTP Outbound]]></Description>
        <Reference name="URLREF"><![CDATA[http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=42326]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002894">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="RE9TIG1v"/>
        </Match>
        <Match match-order="1" within="9" distance="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="GUuDQ0KJ"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS W32.Nugache SMTP Inbound]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.symantec.com/avcenter/venc/data/w32.nugache.a@mm.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002895">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="RE9TIG1v"/>
        </Match>
        <Match match-order="1" within="9" distance="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="GUuDQ0KJ"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS W32.Nugache SMTP Outbound]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.symantec.com/avcenter/venc/data/w32.nugache.a@mm.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2003614">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/4d/5a/4b/45/52/4e/45/4c/33/32/2e/44/4c/4c/00/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS WinUpack Modified PE Header Inbound]]></Description>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/WinPEHeaders]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2003615">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/4d/5a/4b/45/52/4e/45/4c/33/32/2e/44/4c/4c/00/00"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS WinUpack Modified PE Header Outbound]]></Description>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/WinPEHeaders]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003088">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20kuku/20"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[User-Agent\:[^\n]+KUKU\sv]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ VIRUS Sality Trojan User-Agent (KUKU v3.09 exp)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.sophos.com/security/analyses/w32salityu.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003424">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fnew/5farray2/2ephp/3fspeed/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ VIRUS Sality Trojan Web Update]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.sophos.com/security/analyses/w32salityu.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003636">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20kuku"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS Sality Virus User Agent Detected (KUKU v3.09)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003651">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20spm/5fid/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS Sality Virus User Agent Detected (SPM_ID=)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2001879">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="4">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Ehlo"/>
        </Match>
        <PayloadSize min="0" max="50" match-zero="no"/>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[SoberEhlo]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS Sober-style Ehlo - noalert]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/w32.sober@mm.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2001880">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="10">
        <ExtendedPattern uri-decode="no" type="binary" pattern="AUTH/20LOGIN"/>
        </Match>
        <FlowTag action="test-defined" suppress-alert="yes"><![CDATA[SoberEhlo]]></FlowTag>
        <FlowTag action="define" suppress-alert="yes"><![CDATA[SoberAuth]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS Sober-style Ehlo followed by SMTP AUTH - noalert]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/w32.sober@mm.html]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="udp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="8998" match-neg-port="no" follow-on-sig="no" name="DC:2001547">
        <ExtendedLanguage src-port="any" dst-port="8998">
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/5c/bf/01/29/ca/62/eb/f1"/>
        </Match>
        <PayloadSize min="8" max="8" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ VIRUS Sobig.E-F Trojan Site Download Request]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/w32.sobig.e@mm.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001726">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/5bAspackDie/21/5d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/0f/6d/07/9e/6c/62/6c/68/00/d2/2f/63/6d/64/9d/11/af/af/45/c7/72/ac/5f/31/38/d0"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ VIRUS Trojan-Spy.Win32.Bancos Download]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.bancos.b.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003638">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20p4r4z1t3v3"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS AV-Killer.Win32 User Agent Detected (p4r4z1t3v3.one14.J)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2003041">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="subject/3a/20/3a/20zombie"/>
        </Match>
        <Match match-order="1" distance="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="x/2dlibrary/3a/20indy/209/2e00/2e10"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>VIRUS</EventGroup>
        <Description><![CDATA[ VIRUS Win32.SMTP-Mailer SMTP Outbound]]></Description>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Win32.SMTP-Mailer&threatid=48095]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.hauri.net/virus/virusinfo_read.php?code=TRW3000774&start=1]]></Reference>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="8000" match-neg-port="no" follow-on-sig="no" name="DC:2002974">
        <ExtendedLanguage src-port="any" dst-port="8000">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/00/00/00/00"/>
        </Match>
        <PayloadSize min="4" max="4" match-zero="no"/>
        <FlowTag action="define" suppress-alert="no"><![CDATA[BSHupigonControlStart]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Backdoor.Hupigon Possible Control Connection Being Established]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.avira.com/en/threats/section/fulldetails/id_vir/1051/bds_hupigon.bo.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="8000" match-neg-port="no" follow-on-sig="no" name="DC:2002975">
        <ExtendedLanguage src-port="any" dst-port="8000">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Windows/20"/>
        </Match>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BSHupigonControlStart]]></FlowTag>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BSHupigonControlStart]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Backdoor.Hupigon INFECTION - Reporting Host Type]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.avira.com/en/threats/section/fulldetails/id_vir/1051/bds_hupigon.bo.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003549">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/26first/26/20/23/20"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[# \d+d \d+dh \d+m # ]]></PCRE>
        </Match>
        <FlowTag action="test-not-defined" suppress-alert="no"><![CDATA[BE.Bandook1.2]]></FlowTag>
        <FlowTag action="define" suppress-alert="no"><![CDATA[BE.Bandook1.2]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.2 Initial Connection and Report]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003550">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/99/9b/86/8a/85/80/9a/9d"/>
        </Match>
        <PayloadSize min="8" max="8" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.2]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.2 Get Processes]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003551">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="6">
        <ExtendedPattern uri-decode="no" type="binary" pattern="kill3d"/>
        </Match>
        <PayloadSize min="8" max="1514" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.2]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.2 Kill Process Command]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003552">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" offset="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="sockson"/>
        </Match>
        <PayloadSize min="7" max="7" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.2]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.2 Reporting Socks Proxy Active]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003553">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" offset="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="socksoff"/>
        </Match>
        <PayloadSize min="8" max="8" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.2]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.2 Reporting Socks Proxy Off]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003554">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" offset="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/26SEXREPLY/26"/>
        </Match>
        <PayloadSize min="10" max="10" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.2]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.2 Client Ping Reply]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003555">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="2">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/cf/8f"/>
        </Match>
        <Match match-order="1" distance="50">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/20/26/26/26"/>
        </Match>
        <FlowTag action="test-not-defined" suppress-alert="no"><![CDATA[BE.Bandook1.35]]></FlowTag>
        <FlowTag action="define" suppress-alert="no"><![CDATA[BE.Bandook1.35]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.35 Initial Connection and Report]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003556">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" offset="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/cf/ab/a8/a7/ae/cf"/>
        </Match>
        <PayloadSize min="6" max="6" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.35]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.35 Keepalive Send]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003557">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/cf/ab/a8/a4/ae/cf/26/26/26"/>
        </Match>
        <PayloadSize min="9" max="9" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.35]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.35 Keepalive Reply]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003558">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" offset="0" depth="7">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/cf/9b/8c/8e/8a/9b/cf"/>
        </Match>
        <Match match-order="1" distance="5">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/95"/>
        </Match>
        <PayloadSize min="10" max="1514" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.35]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.35 Create Registry Key Command Send]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003559">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" offset="0" depth="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/cf/84/82/8d/80/9b/cf/95"/>
        </Match>
        <PayloadSize min="7" max="1514" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.35]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.35 Create Directory Command Send]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003560">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" offset="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/cf/8e/80/84/84/8c/9e/80/87/cf"/>
        </Match>
        <PayloadSize min="10" max="10" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.35]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.35 Window List Command Send]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003561">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="9">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/cf/9e/80/87/85/80/9a/9d/cf"/>
        </Match>
        <Match match-order="1" distance="10">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/26/26/26"/>
        </Match>
        <PayloadSize min="10" max="1514" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.35]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.35 Window List Reply]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003562">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" offset="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/99/9b/86/8a/85/80/9a/9d"/>
        </Match>
        <PayloadSize min="8" max="8" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.35]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.35 Get Processes Command Send]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003565">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0" depth="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/cf/9d/82/99/9b/86/8a/cf"/>
        </Match>
        <Match match-order="1" distance="10">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/26/26/26"/>
        </Match>
        <PayloadSize min="10" max="1514" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.35]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.35 Get Processes Command Reply]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003563">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" offset="0" depth="5">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/a7/a0/a7/ae/95"/>
        </Match>
        <PayloadSize min="6" max="1514" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.35]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.35 Start Socks5 Proxy Command Send]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="H" match-neg-port="no" follow-on-sig="no" name="DC:2003564">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" offset="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/9a/86/8a/82/9a/86/87/26/26/26"/>
        </Match>
        <PayloadSize min="10" max="10" match-zero="no"/>
        <FlowTag action="test-defined" suppress-alert="no"><![CDATA[BE.Bandook1.35]]></FlowTag>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook v1.35 Socks5 Proxy Start Command Reply]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.nuclearwintercrew.com]]></Reference>
        <Reference name="URLREF"><![CDATA[http://research.sunbelt-software.com/threatdisplay.aspx?name=Bandook&threatid=40408]]></Reference>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/bin/view/Main/TrojanBandook]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2003936">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/cf/8f/80/9b/9a/9d/cf/95"/>
        </Match>
        <PayloadSize min="0" max="80" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandok phoning home (xor by 0xe9 to decode)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.dshield.org/diary.html?date=2007-03-28]]></Reference>
        <Reference name="URLREF"><![CDATA[http://www.secureworks.com/research/threats/bbbphish/?threat=bbbphish]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003937">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="6">
        <ExtendedPattern uri-decode="no" type="binary" pattern="POST/20/2f"/>
        </Match>
        <Match match-order="1" within="150">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/20HTTP/2f1/2e1/0d/0aContent/2dType/3a/20application/2fx/2dwww/2dform/2durlencoded/0d/0aHost/3a/20"/>
        </Match>
        <Match match-order="2" within="100">
        <ExtendedPattern uri-decode="no" type="binary" pattern="Content/2dLength/3a/20"/>
        </Match>
        <Match match-order="3" within="12">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/0d/0a/0d/0a"/>
        </Match>
        <Match match-order="4" within="100">
        <ExtendedPattern uri-decode="no" type="binary" pattern="VISITED/5fURL"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Bandook iwebho/BBB-phish trojan leaking user data]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.secureworks.com/research/threats/bbbphish]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002976">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="x/2dlibrary/3a/20indy/209"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="maquina/2e/2e"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="vers/e3o/20do/20windows"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="microsoft/20windows"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="mac/20address/2e/2e"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Banker.Delf Infection - Sending Initial Email to Owner]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.avira.com/en/threats/section/details/id_vir/1836/tr_banker.delf.df735649.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002978">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="x/2dlibrary/3a/20indy/209"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="nome/20computador/3a/20"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="data/3a/20"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="windows/3a/20microsoft/20windows/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Banker.Delf Infection variant 2 - Sending Initial Email to Owner]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.avira.com/en/threats/section/details/id_vir/1836/tr_banker.delf.df735649.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002980">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="x/2dlibrary/3a/20indy/209"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="subject/3a/20infect/20/2d/20"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="data/3a/20"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="windows/3a/20microsoft/20windows/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Banker.Delf Infection variant 3 - Sending Initial Email to Owner]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.avira.com/en/threats/section/details/id_vir/1836/tr_banker.delf.df735649.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002981">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="x/2dlibrary/3a/20indy/209"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="maquina"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="ip"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="hora"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="data"/>
        </Match>
        <Match match-order="5">
        <ExtendedPattern uri-decode="no" type="string" pattern="microsoft/20windows/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Banker.Delf Infection variant 4 - Sending Initial Email to Owner]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.avira.com/en/threats/section/details/id_vir/1836/tr_banker.delf.df735649.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003931">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20varlok/5f"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Banker.Delf User-Agent (Varlok_11000)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.avira.com/en/threats/section/details/id_vir/1836/tr_banker.delf.df735649.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003933">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20Ms/0d/0a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Banker.Delf User-Agent (Ms)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.avira.com/en/threats/section/details/id_vir/1836/tr_banker.delf.df735649.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004442">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20hhh"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Banker.Delf User-Agent (hhh)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.avira.com/en/threats/section/details/id_vir/1836/tr_banker.delf.df735649.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007594">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20MzApp"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Banker.Delf User-Agent (MzApp)]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.avira.com/en/threats/section/details/id_vir/1836/tr_banker.delf.df735649.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007699">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20WINDOWS/5fLOADS"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Banker.Delf User-Agent (WINDOWS_LOADS)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002977">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="x/2dlibrary/3a/20indy/209"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="dispositivo/20instalado/2e"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="maquina/20pronta/20para/20uso/2e"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="no" type="string" pattern="data/3a/20"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="no" type="string" pattern="hora/3a/20"/>
        </Match>
        <Match match-order="5">
        <ExtendedPattern uri-decode="no" type="string" pattern="development/20by/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Banload Downloader Infection - Sending initial email to owner]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.viruslist.com/en/viruses/encyclopedia?virusid=95586]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2004440">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20ExampleDL"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Banload User-Agent Detected (ExampleDL)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007692">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/0d/0a/0d/0aa/3d"/>
        </Match>
        <Match match-order="1" within="40" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/26b/3dreported"/>
        </Match>
        <Match match-order="2" within="40" distance="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/26d/3dreport"/>
        </Match>
        <PayloadSize min="1000" max="1514" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Basine Trojan Checkin]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007668">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="5">
        <ExtendedPattern uri-decode="no" type="binary" pattern="POST/20"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/0d/0aCache/2dControl/3a/20no/2dcache/0d/0a/0d/0aid/3d"/>
        </Match>
        <Match match-order="2" distance="5">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/26build/5fid/3d"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="no" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[id=x.+_[0-9A-F]{8}&build_id=.+]]></PCRE>
        </Match>
        <PayloadSize min="0" max="400" match-zero="no"/>
        </ExtendedLanguage>
        <EventGroup>COMPROMISE</EventGroup>
        <Description><![CDATA[ TROJAN Blackenergy Bot Checkin to C&C]]></Description>
        <Reference name="URLREF"><![CDATA[http://asert.arbornetworks.com/2007/10/blackenergy-ddos-bot-analysis-available]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006999">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20brontok"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Brontok User-Agent Detected (Brontok.A3 Browser)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003083">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fgetnumtemp/2easp/3fnip/3d0"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Dialer]]></Description>
        <Reference name="URLREF"><![CDATA[http://isc.sans.org/diary.php?storyid=1388]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003650">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fperl/2finvoc/5foneway/2epl"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3fid/5fservice/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26nom/5fexe/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26skin/3d"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26id/5fproduit/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Dialer-715 Install Checkin]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006364">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20del/0d/0a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Dialer-967 User-Agent]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003598">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dagent/3a/20cv/5fv"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Diazom Trojan User-Agent in Use (cv_v2.0.1)]]></Description>
        <Reference name="URLREF"><![CDATA[http://ww.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-032316-0426-99&tabid=2]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003408">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fadload/2ephp/3fa1/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="a3/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26a4/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26a5/3d"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="no" type="negative" pattern="user/2dagent/3a"/>
        </Match>
        <Match match-order="5">
        <ExtendedPattern uri-decode="no" type="binary" pattern="host/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Downloader-1355 Checking In]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003238">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsp/2fpost/2ephp"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20mozilla/2f3/2e0b5a/20/28win95/5c"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="string" pattern="data/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN W32.Downloader-388 (Trojan-Downloader.Win32.Tibs.jy) Reporting to C&C]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003239">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fcp/2frule/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="name/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="b/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="w/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN W32.Downloader-388 (Trojan-Downloader.Win32.Tibs.jy) Reporting to C&C (2)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003590">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="320">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20msid/20/5b"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Downloader-5265/Torpig/Anserin/Sinowal Unique UA (MSID [...)]]></Description>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/2003590]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007595">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3fid/3d/7b"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26srv/3dms"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26ver/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26docid/3d"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26time/3d"/>
        </Match>
        <Match match-order="5">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26cstate/3d"/>
        </Match>
        <Match match-order="6">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26state/3d"/>
        </Match>
        <Match match-order="7">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26flash/3d"/>
        </Match>
        <Match match-order="8">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26pin/3d"/>
        </Match>
        <Match match-order="9">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26osinfo2/3d"/>
        </Match>
        <Match match-order="10">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26cinfo/3d"/>
        </Match>
        <Match match-order="11">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26smd/3d"/>
        </Match>
        <Match match-order="12">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26rts/3d"/>
        </Match>
        <Match match-order="13">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26retryattempt/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Downloader.Dluca HTTP Checkin]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003380">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[User-Agent\:[^\n]+\)ver\d]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ TROJAN Suspicious User-Agent - Possible Trojan Downloader (ver18/ver19, etc)]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003641">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20netscafe/20"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Downloader.Small User Agent Detected (NetScafe)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003642">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20lol"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Downloader.Affill User Agent Detected (lol)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003647">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20irc/2du/20v"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Backdoor.Irc.MFV User Agent Detected (IRC-U)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003648">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20linkrunner"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Clicker.BC User Agent Detected (linkrunner)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006366">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fremote/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="os/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26user/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26status/3d"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26version/3d"/>
        </Match>
        <Match match-order="5">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26build/3d"/>
        </Match>
        <Match match-order="6">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26uptime/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>COMPROMISE</EventGroup>
        <Description><![CDATA[ TROJAN Bot Backdoor Checkin/registration Request]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006377">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3fm/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26a/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26hdd/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26os/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Downloader.Win32.Agent.bwr]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006382">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20x"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="no" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[x\w\wx\w\w\!x\w\wx\w\wx\w\w]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Matcash or related downloader User-Agent Detected]]></Description>
        <Reference name="URLREF"><![CDATA[http://doc.bleedingthreats.net/2006382]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006387">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20Windows/20Updates/20Manager/7c"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Downloader User-Agent Detected (Windows Updates Manager|3.12|...)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006394">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20ld/0d/0a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Downloader User-Agent Detected (ld)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006400">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="install/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="wall/5fid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26maddr/3d0"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26action/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Downloader.26001 Url Pattern Detected]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2006401">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="aff/5fid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="lunch/5fid/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26maddr/3d0"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Downloader.26001 Url Pattern Detected (lunch_id)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007284">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fping/2f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[\/ping\/[0-9a-fA-F]{64}\/[0-9a-fA-F]+\/[0-9a-fA-F]+]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Downloader.Win32.Agent.cav Url Pattern Detected (ping)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007577">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26version/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26configversion/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="guid/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26cmd/3d"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26p/3d"/>
        </Match>
        <Match match-order="5">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26i/3d"/>
        </Match>
        <Match match-order="6">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26x/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN General Downloader Checkin URL (GUID+)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007587">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="uid/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26version/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26actionname/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26action/3d"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26success/3d"/>
        </Match>
        <Match match-order="5">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26debug/3d"/>
        </Match>
        <Match match-order="6">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26nocache/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN General Downloader or Virut C&C Ack]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007633">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="user/2dagent/3a/20ismazo"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>SUSPICIOUS</EventGroup>
        <Description><![CDATA[ TROJAN Suspicious User-Agent - Matcash related Trojan Downloader (Ismazo Advanced Loader)]]></Description>
        <Score>Medium</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007644">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3fv/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26mid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26r1/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26tm/3d200"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26av/3d"/>
        </Match>
        <Match match-order="5">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26os/3dwindows"/>
        </Match>
        <Match match-order="6">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26uid/3d"/>
        </Match>
        <Match match-order="7">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="cht/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Win32.Agent.cah Checkin Request]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002763">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ephp/3fp/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3fmachineid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26connection/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26iplan/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Dumador Reporting User Activity]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.norman.com/Virus/Virus_descriptions/24279/]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003537">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="rfe/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="cmp/3ddun/5ftekfirst"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="guid/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[TROJAN Trojan.Duntek establishing remote connection]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.symantec.com/security_response/writeup.jsp?docid=2006-102514-0554-99]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="toward" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002938">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="MAIL/20FROM/3a/3clogs/40logs/2ecom/3e"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN - elitekeylogger v1.0 reporting - Inbound]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002941">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="MAIL/20FROM/3a/3clogs/40logs/2ecom/3e"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN - elitekeylogger v1.0 reporting - Outbound]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007700">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="php/3fi/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/26v/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/26win/3dWindows"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/26un/3d"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/26uv/3d"/>
        </Match>
        <Match match-order="5">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/26s/3d"/>
        </Match>
        <Match match-order="6">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/26onl/3d"/>
        </Match>
        <Match match-order="7">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/26ip/3d"/>
        </Match>
        <Match match-order="8">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/26f/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN ExplorerHijack Trojan HTTP Checkin]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007646">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="/2frpt"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/0d/0aUser/2dAgent/3a/20"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="negative" pattern="/0d/0aUser/2dAgent/3a/20Mozilla"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[\x0a\x0aUser-Agent\: [a-z0-9]{92}]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Farfli User Agent Detected]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007658">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/0d/0aUser/2dAgent/3a/20VYG/0d/0a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Farfli User Agent Detected (VYG)]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007286">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/3fucid/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26wmid/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[BLEEDING_EDGE TROJAN Feral Checkin via HTTP]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002982">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="subject/3a/20microsoft/20windows"/>
        </Match>
        <Match match-order="1" within="20">
        <ExtendedPattern uri-decode="no" type="string" pattern="infectado"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN GENERAL Possible Trojan Sending Initial Email to Owner - INFECTADO]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="25" match-neg-port="no" follow-on-sig="no" name="DC:2002983">
        <ExtendedLanguage src-port="any" dst-port="25">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="string" pattern="pc/20infectado/20com/20successo"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN GENERAL Possible Trojan Sending Initial Email to Owner - SUCCESSO]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003431">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fww20/2fscript/2ephp/3fid/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="no" type="string" pattern="/26config/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="no" type="negative" pattern="user/2dagent/3a"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ TROJAN Unnamed Generic.Malware http get]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003645">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="User/2dAgent/3a/20Rescue/2f9/2e11"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>MALWARE</EventGroup>
        <Description><![CDATA[ TROJAN Generic.Malware.SFL User-Agent (Rescue/9.11)]]></Description>
        <Score>High</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002775">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fdata/2ephp/3fparam/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26socks/3d"/>
        </Match>
        <Match match-order="2">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[User-Agent\:[^\n]Windows Updater]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Goldun Reporting User Activity]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.avira.com/en/threats/TR_Spy_Goldun_de_1_details.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002780">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fc/2ephp/3fphid/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26ver/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26nn/3d"/>
        </Match>
        <Match match-order="3">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[User-Agent\:[^\n]+z]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Goldun Reporting User Activity 2]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.avira.com/en/threats/TR_Spy_Goldun_de_1_details.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003107">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fsd/2ephp"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Possible Goldun Dropsite 1]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003108">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ffix/2ephp"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Possible Goldun Dropsite 2]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003509">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="24">
        <ExtendedPattern uri-decode="no" type="binary" pattern="POST/20/2fcgi/2dbin/2fcerts/2ecgi/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[POST\x20\x2Fcgi\x2Dbin\x2Fcerts\x2Ecgi\x20HTTP\x2F1\x2E1[\x0D\x0A]+Content\x2DType\x3A\x20multipart\x2Fform\x2Ddata\x3B\x20boundary\x3D.*[\x0D\x0A]+User\x2DAgent\x3A\x20Mozilla\x2F4\x2D0\x20\x28compatible\x3B\x20MSIE\x206\x2D0\x3B\x20Windows\x20NT\x205\x2D1\x29[\x0D\x0A]+Host\x3A\x20]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Gozi Certificate Information Leakage]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.secureworks.com/research/threats/gozi]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003510">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="25">
        <ExtendedPattern uri-decode="no" type="binary" pattern="GET/20/2fcgi/2dbin/2foptions/2ecgi/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[GET\x20\x2Fcgi\x2Dbin\x2Foptions\x2Ecgi\x3Fuser_id\x3D([0-9])+\x26socks\x3D([0-9])+\x26version_id\x3D([0-9])+\x26passphrase\x3D\x20HTTP\x2F1\x2E1[\x0D\x0A]+User\x2DAgent\x3A\x20Mozilla\x2F4\x2D0\x20\x28compatible\x3B\x20MSIE\x206\x2D0\x3B\x20Windows\x20NT\x205\x2D1\x29[\x0D\x0A]+Host\x3A\x20]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Gozi Registration]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.secureworks.com/research/threats/gozi]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2003511">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="24">
        <ExtendedPattern uri-decode="no" type="binary" pattern="POST/20/2fcgi/2dbin/2fforms/2ecgi/3f"/>
        </Match>
        <Match match-order="1">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[POST\x20\x2Fcgi\x2Dbin\x2Fforms\x2Ecgi\x20HTTP\x2F1\x2E1[\x0D\x0A]+Content\x2DType\x3A\x20multipart\x2Fform\x2Ddata\x3B\x20boundary\x3D.*[\x0D\x0A]+User\x2DAgent\x3A\x20Mozilla\x2F4\x2D0\x20\x28compatible\x3B\x20MSIE\x206\x2D0\x3B\x20Windows\x20NT\x205\x2D1\x29[\x0D\x0A]+Host\x3A\x20]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Gozi Form Data Information Leakage]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.secureworks.com/research/threats/gozi]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2007632">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="cgi"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="user/5fid/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="version/5fid/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="crc/3d"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="binary" pattern="passphrase"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Possible Gozi Trojan Checkin]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.secureworks.com/research/threats/gozi]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001899">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2freg/3fu/3d"/>
        </Match>
        <Match match-order="1" within="15">
        <ExtendedPattern uri-decode="no" type="string" pattern="/26v/3d"/>
        </Match>
        <Match match-order="2" within="15">
        <ExtendedPattern uri-decode="no" type="string" pattern="/26s/3d"/>
        </Match>
        <Match match-order="3" within="15">
        <ExtendedPattern uri-decode="no" type="string" pattern="/26su/3d"/>
        </Match>
        <Match match-order="4" within="15">
        <ExtendedPattern uri-decode="no" type="string" pattern="/26p/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>COMPROMISE</EventGroup>
        <Description><![CDATA[ BOTNET HTTP Botnet reg]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.honeynet.org/papers/bots]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001900">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fupdate/2ephp/3fport/3d"/>
        </Match>
        <Match match-order="1" within="20">
        <ExtendedPattern uri-decode="no" type="string" pattern="/26checktime/3d"/>
        </Match>
        <Match match-order="2" within="20">
        <ExtendedPattern uri-decode="no" type="string" pattern="/26uptime/3d"/>
        </Match>
        <Match match-order="3" within="20">
        <ExtendedPattern uri-decode="no" type="string" pattern="/26result/3d"/>
        </Match>
        <Match match-order="4" within="15">
        <ExtendedPattern uri-decode="no" type="string" pattern="/26localip/3d"/>
        </Match>
        <Match match-order="5" within="20">
        <ExtendedPattern uri-decode="no" type="string" pattern="/26id/3d"/>
        </Match>
        <Match match-order="6" within="20">
        <ExtendedPattern uri-decode="no" type="string" pattern="/24hash/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>COMPROMISE</EventGroup>
        <Description><![CDATA[ BOTNET BwB Botnet Checkin]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.honeynet.org/papers/bots]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="any" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2001901">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="11">
        <ExtendedPattern uri-decode="no" type="binary" pattern="GET/20/2freg/3fu/3d"/>
        </Match>
        <Match match-order="1" within="3" distance="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/26v/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Possible Bobax trojan infection]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.lurhq.com/bobax.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2001743">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/01/9a/8c/66/af/c0/4a/11/9e/3f/40/88/12/2c/3a/4a/84/65/38/b0/b4/08/0b/af/db/ce/02/94/34/5f/22"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN HackerDefender Root Kit Remote Connection Attempt Detected]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/backdoor.hackdefender.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="from" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2003244">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="target-server" state="established"/>
        <Match match-order="0" depth="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/d0/84/ec/77/cf/ec/60/e9"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN HackerDefender.HE Root Kit Control Connection]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/backdoor.hackdefender.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="both" traffic-direction="toward" dynamic-collection="0" port="A" match-neg-port="no" follow-on-sig="no" name="DC:2003245">
        <ExtendedLanguage src-port="any" dst-port="any">
        <Flow direction="source-server" state="established"/>
        <Match match-order="0" depth="8">
        <ExtendedPattern uri-decode="no" type="binary" pattern="/d0/84/ec/77/cf/ec/60/e9"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN HackerDefender.HE Root Kit Control Connection Reply]]></Description>
        <Reference name="URLREF"><![CDATA[http://securityresponse.symantec.com/avcenter/venc/data/backdoor.hackdefender.html]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002790">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2fbsrv/2ephp/3f"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="lang/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26socksport/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26httpport/3d"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26uptimem/3d"/>
        </Match>
        <Match match-order="5">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26uptimeh/3d"/>
        </Match>
        <Match match-order="6">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26uid/3d"/>
        </Match>
        <Match match-order="7">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26ver/3d"/>
        </Match>
        <Match match-order="8">
        <PCRE relative-to-previous="no" caseless="yes" multi-line="no" single-line="no" extended="no" anchored="no" dollar-endonly="no" ungreedy="no"><![CDATA[User-Agent\:[^\n]MSIE 6.0]]></PCRE>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Haxdoor Reporting User Activity]]></Description>
        <Reference name="URLREF"><![CDATA[http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BKDR_HAXDOOR.DI]]></Reference>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="destination" traffic-direction="from" dynamic-collection="0" port="W" match-neg-port="no" follow-on-sig="no" name="DC:2002929">
        <ExtendedLanguage>
        <Flow direction="target-server" state="established"/>
        <Match match-order="0">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/2ephp/3fparam/3d"/>
        </Match>
        <Match match-order="1">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26socksport/3d"/>
        </Match>
        <Match match-order="2">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26httpport/3d"/>
        </Match>
        <Match match-order="3">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26uptime"/>
        </Match>
        <Match match-order="4">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26uid/3d"/>
        </Match>
        <Match match-order="5">
        <ExtendedPattern uri-decode="yes" type="string" pattern="/26ver/3d"/>
        </Match>
        </ExtendedLanguage>
        <EventGroup>TROJAN</EventGroup>
        <Description><![CDATA[ TROJAN Haxdoor Reporting User Activity 2]]></Description>
        <Score>Critical</Score>
        <DateAdded date="2005-01-24"/>
        <DateModified date="2007-12-18"/>
        <Enabled value="yes"/>
    </Signature>
    <Signature protocol="tcp" service-direction="source" traffic-direction="toward" dynamic-collection="0" port="W" match-neg-port="yes" follow-on-sig="no" name="DC:2001959">
        <ExtendedLanguage>
        <Flow direction="source-server" state="established"/>
        <Match match-order="0">
        <Ex