[Snort-sigs] Blackrev C2 sigs

James Lay jlay at ...3266...
Tue May 21 16:25:22 EDT 2013


Enjoy:

alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"MALWARE-CNC 
Win.Trojan.BlackRev Rev 1 C2 Traffic"; content:"GET"; http_method; 
content:"gate.php|3f|reg="; http_uri; 
pcre:"/gate\x2ephp\x3freg=[a-z]{10}/m"; content:"User-Agent|3a| 
Mozilla/4.0 (compatible|3b| Synapse)|0d 0a|"; http_header; 
metadata:policy balanced-ips drop, policy security-ips drop, ruleset 
community service http; 
reference:url,http://ddos.arbornetworks.com/2013/05/the-revolution-will-be-written-in-delphi; 
classtype:trojan-activity; sid:10000066; rev:1;)

alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"MALWARE-CNC 
Win.Trojan.BlackRev Rev 2 C2 Traffic"; content:"GET"; http_method; 
content:"gate.php|3f|reg="; http_uri; 
pcre:"/gate\x2ephp\x3freg=[a-z]{15}/mi"; content:"User-Agent|3a| 
Mozilla/4.0 (compatible|3b| SEObot)|0d 0a|"; http_header; 
metadata:policy balanced-ips drop, policy security-ips drop, ruleset 
community service http; 
reference:url,http://ddos.arbornetworks.com/2013/05/the-revolution-will-be-written-in-delphi; 
classtype:trojan-activity; sid:10000067; rev:1;)

alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"MALWARE-CNC 
Win.Trojan.BlackRev Rev 3 C2 Traffic"; content:"GET"; http_method; 
content:"gate.php|3f|id="; http_uri; 
pcre:"/gate\x2ephp\x3fid=[a-z]{15}/mi"; content:"User-Agent|3a| 
Mozilla/4.0 (compatible|3b| SEObot)|0d 0a|"; http_header; 
metadata:policy balanced-ips drop, policy security-ips drop, ruleset 
community service http; 
reference:url,http://ddos.arbornetworks.com/2013/05/the-revolution-will-be-written-in-delphi; 
classtype:trojan-activity; sid:10000068; rev:1;)

Lot's of good info on that reference link.

James




More information about the Snort-sigs mailing list