alert http $HOME_NET any -> $EXTERNAL_NET any (
msg:"ET MOBILE_MALWARE Android/GoldDream Infected Device Registration";
flow:established,to_server;
http.uri;
content:"/RegistUid.asp"; fast_pattern; nocase;
content:"?pid="; nocase;
content:"&cid="; nocase;
content:"&imei="; nocase;
content:"&sim="; nocase;
content:"&imsi="; nocase;
reference:url,www.fortiguard.com/encyclopedia/virus/android_golddream.a!tr.spy.html;
classtype:trojan-activity;
sid:2013238; rev:6;
metadata:affected_product Android, attack_target Client_Endpoint, created_at 2011_07_09, deployment Perimeter, signature_severity Critical, tag Android, updated_at 2020_09_18;
)