ET MALWARE IRC Potential bot scan/exploit command
Query · suricata
flowbits:isset,is_proto_irc;
flow:established,from_server;
content:"PRIVMSG|20|"; depth:8;
content:"|3a|"; within:30;
pcre:"/(ntscan [0-9]{1,4} [0-9]{1,4}|dcom\.self|scan\.(start|stop)|scan ([0-9]{1,3}\.[0-9]{1,3})|(advscan|exploited|asc|xscan|xploit|adv\.start) (webdav|netbios|ntpass|dcom(2|135|445|1025)|mssql|lsass|optix|upnp|dcass|beagle[12]|mydoom|netdevil|DameWare|kuang2|sub7|iis5ssl|wkssvc|wks1|mysql|wkssvcOth|wkssvcENG|arkeia|arcserve|wins|veritas|netbackup|asn))/i";
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata flowbits
is_proto_irc- ET CHAT IRC USER command
- ET CHAT IRC NICK command
- ET CHAT IRC JOIN command
- ET CHAT IRC PRIVMSG command
- ET CHAT IRC PING command
- ET CHAT IRC PONG response
- ET CHAT IRC USER Likely bot with 0 0 colon checkin
- ET CHAT IRC USER Off-port Likely bot with 0 0 colon checkin
- GPL CHAT IRC DCC file transfer request
- GPL CHAT IRC DCC chat request
- GPL CHAT IRC Channel join
- ET DELETED B0tN3t IRCbotnet