""ET TROJAN Backdoor.Win32.Dorkbot.AR Join IRC channel""
SID: 2016768
Revision: 4
Class Type: trojan-activity
Metadata: created_at 2013_04_18, updated_at 2014_03_31
Reference:
-
md5
-
7e76c7db8706511fc59508af4aef27fa
Protocol: tcp
Source Network: $HOME_NET
Source Port: any
Destination Network: $EXTERNAL_NET
Destination Port: any
Flow: to_server,established
Contents:
- Value: "NICK n|7B|"
Within:
PCRE: "/^\S{2,3}\x7c\S+?[au]\x7D\w{2,11}\x0d?\x0a/Ri"
Special Options:
- nocase