rule Worm_Win32_Womble_D{ meta: description = "Worm:Win32/Womble.D,SIGNATURE_TYPE_PEHSTR,0f 00 0e 00 13 00 00 01 00 " strings : $a_01_0 = {66 61 73 74 6d 61 69 6c 2e } //01 00 fastmail. $a_01_1 = {67 72 61 66 66 69 74 69 2e } //01 00 graffiti. $a_01_2 = {2e 63 6f 6d 2f 63 75 72 72 65 6e 74 2f } //01 00 .com/current/ $a_01_3 = {3f 61 3d 25 64 26 64 3d 30 3a 30 3a 25 64 } //01 00 ?a=%d&d=0:0:%d $a_01_4 = {3c 66 72 61 6d 65 20 73 72 63 3d } //01 00 condition: any of ($a_*) }