[prev in list] [next in list] [prev in thread] [next in thread] 

List:       snort-sigs
Subject:    Re: [Snort-sigs] Rawbytes needed?
From:       Y M <snort () outlook ! com>
Date:       2014-02-05 19:38:44
Message-ID: COL129-W794D8A9E2E52F004C772D9A8950 () phx ! gbl
[Download RAW message or body]

[Attachment #2 (multipart/alternative)]


Hi James,
 
How about using file_data? Also there is a missing pipe "|" at the end of the content pattern :).
 
YM
 
> To: snort-sigs@lists.sourceforge.net
> Date: Wed, 5 Feb 2014 11:34:42 -0700
> From: jlay@slave-tothe-box.net
> Subject: [Snort-sigs] Rawbytes needed?
> 
> What say you all?
> 
> alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"MALWARE-CNC 
> Win32/Asprox Variant Outbound Traffic"; flow:from_server, established; 
> content:"|3c|html|3e 3c|body|3e|hi|21 3c 2f|body|3e 3c 2f|html|3e"; 
> fast_pattern:only; 
> reference:url,research.zscaler.com/2014/02/new-zbot-variant-goes-above-and-beyond.html; 
> classtype:trojan-activity; sid:10000124; rev:1;)
> 
> Guessing html and body tags will get normalized yes?
> 
> James
> 
> ------------------------------------------------------------------------------
> Managing the Performance of Cloud-Based Applications
> Take advantage of what the Cloud has to offer - Avoid Common Pitfalls.
> Read the Whitepaper.
> http://pubads.g.doubleclick.net/gampad/clk?id=121051231&iu=/4140/ostg.clktrk
> _______________________________________________
> Snort-sigs mailing list
> Snort-sigs@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/snort-sigs
> http://www.snort.org
> 
> 
> Please visit http://blog.snort.org for the latest news about Snort!
 		 	   		  
[Attachment #5 (text/html)]

<html>
<head>
<style><!--
.hmmessage P
{
margin:0px;
padding:0px
}
body.hmmessage
{
font-size: 12pt;
font-family:Calibri
}
--></style></head>
<body class='hmmessage'><div dir='ltr'>Hi James,<BR>&nbsp;<BR>How about using \
file_data? Also there is a missing pipe "|" at the end of the content \
pattern&nbsp;:).<BR>&nbsp;<BR>YM<br>&nbsp;<BR><div>&gt; To: \
snort-sigs@lists.sourceforge.net<br>&gt; Date: Wed, 5 Feb 2014 11:34:42 -0700<br>&gt; \
From: jlay@slave-tothe-box.net<br>&gt; Subject: [Snort-sigs] Rawbytes needed?<br>&gt; \
<br>&gt; What say you all?<br>&gt; <br>&gt; alert tcp $EXTERNAL_NET $HTTP_PORTS -&gt; \
$HOME_NET any (msg:"MALWARE-CNC <br>&gt; Win32/Asprox Variant Outbound Traffic"; \
flow:from_server, established; <br>&gt; content:"|3c|html|3e 3c|body|3e|hi|21 3c \
2f|body|3e 3c 2f|html|3e"; <br>&gt; fast_pattern:only; <br>&gt; \
reference:url,research.zscaler.com/2014/02/new-zbot-variant-goes-above-and-beyond.html; \
<br>&gt; classtype:trojan-activity; sid:10000124; rev:1;)<br>&gt; <br>&gt; Guessing \
html and body tags will get normalized yes?<br>&gt; <br>&gt; James<br>&gt; <br>&gt; \
------------------------------------------------------------------------------<br>&gt; \
Managing the Performance of Cloud-Based Applications<br>&gt; Take advantage of what \
the Cloud has to offer - Avoid Common Pitfalls.<br>&gt; Read the Whitepaper.<br>&gt; \
http://pubads.g.doubleclick.net/gampad/clk?id=121051231&amp;iu=/4140/ostg.clktrk<br>&gt; \
_______________________________________________<br>&gt; Snort-sigs mailing \
list<br>&gt; Snort-sigs@lists.sourceforge.net<br>&gt; \
https://lists.sourceforge.net/lists/listinfo/snort-sigs<br>&gt; \
http://www.snort.org<br>&gt; <br>&gt; <br>&gt; Please visit http://blog.snort.org for \
the latest news about Snort!<br></div> 		 	   		  </div></body> </html>



------------------------------------------------------------------------------
Managing the Performance of Cloud-Based Applications
Take advantage of what the Cloud has to offer - Avoid Common Pitfalls.
Read the Whitepaper.
http://pubads.g.doubleclick.net/gampad/clk?id=121051231&iu=/4140/ostg.clktrk

_______________________________________________
Snort-sigs mailing list
Snort-sigs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
http://www.snort.org


Please visit http://blog.snort.org for the latest news about Snort!

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic