Read the below on Google Reader, figured it was easy enough to write some SNORT® rules for:
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:”VIRUS W32/Xpaj Botnet infection”; flow:to_server,established; uricontent:”up.php”; content:”a=g2″; rev:1; sid:1000000;)
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:”VIRUS W32/Xpaj Botnet Infection”; flow:to_server,established; uricontent:”stamm/”; content:”stamm.dat”; depth:0; within:9; rev:1; sid:1000001;)
alert tcp $HOME_NET any -> $EXTERNAL_NET [...]
Pages…
Who's Online
16 visitors online now
16 guests, 0 membersPowered by Visitor Maps
-
Recent Comments
- cybfor (Cyber Informant) on Funny ‘Hacker’ Story
- winsec (Windows Security) on 10 reasons to avoid talking on the phone
- sans_isc (SANS ISC) on VRT: APT: Should your panties be in a bunch, and how do you un-bunch them?
- enhancedx (enhanced) on VRT: APT: Should your panties be in a bunch, and how do you un-bunch them?
- JoelEsler (Joel Esler) on VRT: APT: Should your panties be in a bunch, and how do you un-bunch them?