Versions (4)
Version DetailsCurrent
Rev: 2 • Mar 28, 2013, 12:00 PMET MALWARE Win32/Delfinject Check-in
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE Win32/Delfinject Check-in"; flow:established,to_server; content: "|44 4d 7f 49 51 48 50 62 7d 74 61 77 4e 55 32 2f|"; depth:16; dsize:<65; reference:md5,90f8b934c541966aede75094cfef27ed; reference:url,www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=VirTool%3AWin32%2FDelfInject; classtype:trojan-activity; sid:2016685; rev:2; metadata:created_at 2013_03_28, malware_family Win32_Delfinject, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
Mar 28, 2013, 12:00 PM
Jul 26, 2019, 12:00 PM
Mar 28, 2013, 12:00 PM
Oct 1, 2025, 9:34 PM
rules/emerging-malware.rules