[Snort-sigs] Trojan.APT.Seinup sig with pcre help request
jlay at ...3266...
Fri Jun 21 11:39:06 EDT 2013
On 2013-06-21 09:27, Joel Esler wrote:
> Is there a minimum length to the query here? for the use of urilen?
> ".php" is a content match that will enter all the time. Trying to
> scrounge up ways of making this faster.
Yea I've been trying to optimize this myself...not sure if this is a
GET or POST...that could help if we knew. I've not seen any other info
on this besides the referenced site...maybe you can use your connections
to see what else we could get on this Joel ;)
>> And yet another fix...thanks to those that have helped out:
>> alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS
>> Trojan.Win32.APT.Seinup outbound connection";
>> flow:to_server,established; content:".php|3f|"; http_uri;
>> metadata:policy balanced-ips drop, policy security-ips drop, service
>> classtype:trojan-activity; sid:10000081; rev:3;)
More information about the Snort-sigs