""ET TROJAN PWS Win32/Lmir.BMQ checkin""
SID: 2017724
Revision: 2
Class Type: trojan-activity
Metadata: created_at 2013_11_15, updated_at 2013_11_15
Reference:
Protocol: icmp
Source Network: any
Source Port: any
Destination Network: any
Destination Port: any
Flow:
Contents:
- Value: "This|27|s|20|Ping|20|Packet|21|"
Within:
PCRE:
Special Options: