Back to Rule

Rule History

SID: 2012894 • Source: et/open

Versions (6)

Version DetailsCurrent

Rev: 5May 31, 2011, 12:00 PM

ET RETIRED Dropper.Win32.Agent.bpxo Checkin

alert tcp $HOME_NET any -> $EXTERNAL_NET 1024: (msg:"ET RETIRED Dropper.Win32.Agent.bpxo Checkin"; flow:established,to_server; content:"|71 4E 6C 39 34 65 66 59 41 7A 32 32 37 4F 71 45 44 4D 50 0A|"; depth:20; reference:md5,02e447b347a90680e03c8b7d843a8e46; reference:url,www.antivirus365.org/PCAntivirus/37128.html; classtype:command-and-control; sid:2012894; rev:5; metadata:created_at 2011_05_31, former_category MALWARE, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_12_03;)

May 31, 2011, 12:00 PM

Dec 3, 2024, 12:00 PM

Sep 21, 2024, 3:00 AM

Dec 1, 2025, 11:34 PM

rules/emerging-retired.rules