alert http $HOME_NET any -> $EXTERNAL_NET any (
msg:"ET MALWARE Bredolab Downloader Communicating With Controller (1)";
flow:established,to_server;
http.uri;
content:"action="; nocase;
content:"&entity_list="; nocase;
content:"&uid="; nocase;
content:"&first=";
content:"&guid="; nocase;
content:"&rnd="; nocase;
reference:url,www.microsoft.com/security/portal/Entry.aspx?Name=TrojanDownloader%3aWin32/Bredolab.B;
classtype:trojan-activity;
sid:2009353; rev:10;
metadata:created_at 2010_07_30, signature_severity Major, updated_at 2020_04_21;
)