<p># alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS(msg:"MALWARE-CNC<br/>Linux.Trojan.XORDDoS outbound connection attempt";flow:to_server,established; urilen:>100;<br/>content:"/compiler.action?iid="; http_uri;content:"&username="; within:10; distance:32; http_uri;<br/>content:"&password="; within:30; distance:1; http_uri;content:"&kernel="; distance:0; http_uri;<br/>metadata:impact_flag red, policy balanced-ips drop, policysecurity-ips drop, ruleset community,<br/>service http;reference:url,www.virustotal.com/en/file/e8cb63cc050c952c1168965f597105a128b56114835eb<br/>7d40bdec964a0e243dc/analysis/;