cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2660
Views
0
Helpful
2
Replies

MALWARE-CNC Win.Trojan.Glupteba C&C server READY command to client

Hello,

I am getting 'MALWARE-CNC Win.Trojan.Glupteba C&C server READY command to client" alerts from Source port 10003 to high numbered destination ports in my network. Most of the source IP belongs a Linux server in my network.

Where can I find the snort rule for "MALWARE-CNC Win.Trojan.Glupteba C&C server READY command to client"?

Thanks,

Faisal

2 Replies 2

Farhan Mohamed
Cisco Employee
Cisco Employee

I checked some rule under the link, which i pasted below, Can you please check and see if it is useful:-

https://www.snort.org/advisories/vrt-rules-2014-08-21

David Janulik
Cisco Employee
Cisco Employee

Hello,

since AMP is file based, you might need to check the retrospection event in Console. If you provide me SHA 256 of the file, we can look it up in cloud details for you.

David

Cyber security escalation engineer