Snort mailing list archives

Re: Possible scr worm


From: Erek Adams <erek () theadamsfamily net>
Date: Mon, 20 Aug 2001 07:57:56 -0700 (PDT)

On Mon, 20 Aug 2001 john.ruff () us abb com wrote:



Any idea what might be causing this aler tot be generated?  I realize it's
POP3 traffic (probably someone's internet mail acct.), but is there
something new out there generating these alerts?  I've actually got about
3600 of these alerts which just started Saturday(8/18/01).  Need more info
let me know.

[**] [1:729:1] Virus - Possible scr Worm [**]
08/20-10:04:45.515817 216.136.173.10:110 -> xxx.xxx.xx.xx:4062
TCP TTL:49 TOS:0x0 ID:2259 IpLen:20 DgmLen:1500 DF
***A**** Seq: 0x878CAF66  Ack: 0x2AE6A993  Win: 0x4470  TcpLen: 20

Well, if you look at the rule:

alert tcp any 110 -> any any (msg:"Virus - Possible scr Worm"; content:
".scr"; nocase; sid:729; rev:1;)

It tells you if you see traffic on port 110 with a content of ".scr" then
trigger this.  This rule is very prone to false positives, which is one reason
it's not in 1.8.1-RELEASE.

Someone had a file or the phrase .scr in some email they popped.  In fact if
you popped this email, you just got some! :)

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: