Snort mailing list archives
BitBot sig
From: James Lay <jlay () slave-tothe-box net>
Date: Tue, 04 Jun 2013 16:34:55 -0600
Didn't have a ton to work with: alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"MALWARE-CNC BitBot Idle C2 response"; flow:from_server,established; file_data; content:"<|5c||5c||5c|>IDLE<|5c||5c||5c|>"; depth:18; metadata:policy balanced-ips drop, policy security-ips drop, service http, ruleset community; reference:url,http://blogs.mcafee.com/mcafee-labs/delving-deeply-into-a-bitcoin-botnet; classtype:trojan-activity; sid:10000074; rev:1;) Also, anyone know if there's a....server response to client much like http_client_body? Just curious..thanks all. James ------------------------------------------------------------------------------ How ServiceNow helps IT people transform IT departments: 1. A cloud service to automate IT design, transition and operations 2. Dashboards that offer high-level views of enterprise services 3. A single system of record for all IT processes http://p.sf.net/sfu/servicenow-d2d-j _______________________________________________ Snort-sigs mailing list Snort-sigs () lists sourceforge net https://lists.sourceforge.net/lists/listinfo/snort-sigs http://www.snort.org Please visit http://blog.snort.org for the latest news about Snort!
Current thread:
- BitBot sig James Lay (Jun 04)