""ET TROJAN Win32/Delfinject Check-in""
SID: 2016685
Revision: 2
Class Type: trojan-activity
Metadata: created_at 2013_03_28, updated_at 2013_03_28
Reference:
Protocol: tcp
Source Network: $HOME_NET
Source Port: any
Destination Network: $EXTERNAL_NET
Destination Port: any
Flow: established,to_server
Contents:
- Value: "|44 4d 7f 49 51 48 50 62 7d 74 61 77 4e 55 32 2f|" Depth: 16
Within:
PCRE:
Special Options: