Home page logo
/

snort logo Snort mailing list archives

BitBot sig
From: James Lay <jlay () slave-tothe-box net>
Date: Tue, 04 Jun 2013 16:34:55 -0600

Didn't have a ton to work with:

alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"MALWARE-CNC 
BitBot Idle C2 response"; flow:from_server,established; file_data; 
content:"<|5c||5c||5c|>IDLE<|5c||5c||5c|>"; depth:18; metadata:policy 
balanced-ips drop, policy security-ips drop, service http, ruleset 
community; 
reference:url,http://blogs.mcafee.com/mcafee-labs/delving-deeply-into-a-bitcoin-botnet; 
classtype:trojan-activity; sid:10000074; rev:1;)

Also, anyone know if there's a....server response to client much like 
http_client_body?  Just curious..thanks all.

James

------------------------------------------------------------------------------
How ServiceNow helps IT people transform IT departments:
1. A cloud service to automate IT design, transition and operations
2. Dashboards that offer high-level views of enterprise services
3. A single system of record for all IT processes
http://p.sf.net/sfu/servicenow-d2d-j
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
http://www.snort.org


Please visit http://blog.snort.org for the latest news about Snort!


  By Date           By Thread  

Current thread:
  • BitBot sig James Lay (Jun 04)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]