topleft topright

My Account

Account






Lost Password?
No account yet? Register

Feeds

 
Oderoor / Kraken / Bobax
Written by Matt Jonkman   
Monday, 07 April 2008
Whatever it turns out to be, we have some test sigs for it. References below to a Dambala release of the new 400k node botnet. Appears to be an existing well known one not nearly that large.

2008103 through 2008110 are out for it, initial draft type sigs.

The bot uses port 447 UDP mostly to communicate, but also seems to once in a while do a large transfer on TCP 447. This port is reserved for ddm-dfm Distributed File Management. Very rarely used as far as we can tell. The signatures above count on the fact that even if this is used it's likely not used over public networks. Please let us know if this isn't true. If you do use this protocol locally please consider a pass or suppression rule until we get better sigs.

References:

http://www.incidents.org/diary.html?storyid=4256

http://isc.sans.org/diary.html?storyid=4250

http://www.darkreading.com/document.asp?doc_id=144919
(May be FUD)

http://www.theregister.co.uk/2008/04/07/kraken_botnet_menace/ (also may be FUD)

Wiki at http://doc.emergingthreats.net/bin/view/Main/OdeRoor

Please report any falses at all!
 
UPnP Sigs
Written by Matt Jonkman   
Thursday, 03 April 2008

Put three new signatures up regarding UPnP. No new exploit or vulnerability, but we're seeing malware samples that are going straight to the local router on TCP UPnP port 2555. This is unusual, normal UPnP starts with UDP port 1900 to do discovery.

 

http://doc.emergingthreats.net/2008092

This sig will find Internal to Internal UPnP requests on port 2555. These are legal, but not normal. If you see this on a non-home network it's likely something you'll want to follow up on if you weren't doing it on purpose.

 

http://doc.emergingthreats.net/2008093

This is similar to above, but for requests coming from outside to your perimeter or internal net. This is never a good thing to have happening, and with recent issues of routers coming out of the box with external administration enabled, you'll want to know about these.

 

http://doc.emergingthreats.net/2008094

Similar here, from outside to your local net, but the TCP port 2555 version. This is not a normal discovery protocol, someone's trying to access your systems. Definitely needs attention!

 

Please report any issues!

 

Matt 

  

Last Updated ( Thursday, 03 April 2008 )
 
Nginx Server Sig
Written by Matt Jonkman   
Wednesday, 26 March 2008

Nginx ( http://nginx.net/ ) is a good http server and proxy. used in a lot of places for legitimate things. Unfortunately it's used most often in hosting or redirecting for malicious sites.

 

I've added sig 2008054 to catch these. This doesn't necessarily mean 100% that traffic is hostile, but it's worth checking into.  

 

As always please report any issues!

 

UPDATE: The existing sigs didn't work, too many legitimate sites using nginx. Have added two signatures to catch modified server version strings that are more likely to be hostile. 2008064  and 2008065.

Last Updated ( Friday, 28 March 2008 )
 
<< Start < Prev 1 2 3 4 5 6 7 8 9 10 Next > End >>

Results 13 - 16 of 48
Joomla Templates by JoomlaShack Joomla Templates