SPYWARE: Codename Alvin
This signature detects the runtime behavior of spyware Codename Alvin, a keylogger. After infecting a host, this spyware enables attackers to capture screen images, monitor user Web activity, and log keystrokes made by the host user. It also downloads and installs code from its controlling server.
References
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3