[Snort-sigs] BLACKLIST DNS request for known malware domain 143biz.cc.md-14.webhostbox.net

Travis McWaters travis.mcwaters+snort-sigs at ...2420...
Thu Nov 17 17:28:13 EST 2016


Looking over the DNS related signatures today, I noticed two signatures for
the same domain:

alert udp $HOME_NET any -> any 53 (msg:"BLACKLIST DNS request for known
malware domain 143biz.cc.md-14.webhostbox.net - Win.Trojan.Backoff";
flow:to_server; byte_test:1,!&,0xF8,2;
content:"|06|143biz|02|cc|05|md-14|0A|webhostbox|03|net|00|";
fast_pattern:only; metadata:impact_flag red, policy balanced-ips drop,
policy security-ips drop, service dns; reference:url,
www.virustotal.com/en/url/b7aac87f8be38de5a35efac918c577380f229d461c5d7567bd5842b71d252523/analysis/;
classtype:trojan-activity; sid:32446; rev:1; )

alert udp $HOME_NET any -> any 53 (msg:"BLACKLIST DNS request for known
malware domain 143biz.cc.md-14.webhostbox.net - Win.Trojan.Soraya";
 flow:to_server; byte_test:1,!&,0xF8,2;
content:"|06|143biz|02|cc|05|md-14|0A|webhostbox|03|net|00|";
fast_pattern:only; metadata:impact_flag red, policy balanced-ips drop,
policy security-ips drop, service dns; reference:url,
www.virustotal.com/en/domain/143biz.cc.md-14.webhostbox.net/information/;
classtype:trojan-activity; sid:31226; rev:1; )

The only difference seems to be the reference metadata and the message
(Win.Trojan.Backoff vs Win.Trojan.Soraya)

Thought I'd point it out and suggest possibly combining them.

Thanks,
Travis
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20161117/799659eb/attachment.html>


More information about the Snort-sigs mailing list