""ET TROJAN Likely Bot Nick in IRC (USA +..)""
SID: 2008124
Revision: 5
Class Type: trojan-activity
Metadata: created_at 2010_07_30, updated_at 2011_10_21
Reference:
Protocol: tcp
Source Network: $HOME_NET
Source Port: any
Destination Network: $EXTERNAL_NET
Destination Port: any
Flow: established,to_server
Contents:
-
Value: "NICK " Depth: 5
-
Value: "USA"
Within: 10
PCRE:
Special Options: