""ET TROJAN Win32.UFRStealer.A issuing MKD command FTP""

SID: 2014111

Revision: 4

Class Type: trojan-activity

Metadata: created_at 2011_04_20, updated_at 2012_01_10

Reference:

  • md5

  • a251ef38f048d695eae52626e57d617d

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: 21

Flow: to_server,established

Contents:

  • Value: "MKD UFR_Stealer|0d 0a|" Depth: 17

Within:

PCRE:

Special Options:

  • nocase

source