03-06-2017 10:04 AM - edited 02-20-2020 09:03 PM
Hello,
I am getting 'MALWARE-CNC Win.Trojan.Glupteba C&C server READY command to client" alerts from Source port 10003 to high numbered destination ports in my network. Most of the source IP belongs a Linux server in my network.
Where can I find the snort rule for "MALWARE-CNC Win.Trojan.Glupteba C&C server READY command to client"?
Thanks,
Faisal
05-19-2017 01:04 PM
I checked some rule under the link, which i pasted below, Can you please check and see if it is useful:-
05-22-2017 02:25 AM
Hello,
since AMP is file based, you might need to check the retrospection event in Console. If you provide me SHA 256 of the file, we can look it up in cloud details for you.
David
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide