""ET TROJAN Athena Bot Nick in IRC""

SID: 2017716

Revision: 3

Class Type: trojan-activity

Metadata: created_at 2013_11_15, updated_at 2013_11_15

Reference:

  • md5

  • 859c2fec50ba1212dca9f00aa4a64ec4

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "NICK "

  • Value: "|5b|"

Within: 1

PCRE: "/^[A-Z]{3}|[UA]|[DL]|W([78]|_XP|VIS)|x(86|64)|/R"

Special Options:

source