[Snort-sigs] W32.Beagle.J Worm Signature?

Mark.Schutzmann at ...2233... Mark.Schutzmann at ...2233...
Wed Mar 3 12:58:16 EST 2004

Has anyone developed or seen a signature for the W32.Beagle.J? I know that
it is not best-practices to monitor for viruses through the SMTP gateway
with Snort, but I am having a problem detecting this one. The issue is that
the well-known AV Vendor that I am using will not scan a password-protected
zip file, which is usually the attachment for this worm's e-mail. Any help
would be appreciated.


More information about the Snort-sigs mailing list