""ET TROJAN Possible IRC Bot Common PRIVMSG Commands""
SID: 2019486
Revision: 1
Class Type: trojan-activity
Metadata: created_at 2014_10_21, updated_at 2014_10_21
Reference:
Protocol: tcp
Source Network: $EXTERNAL_NET
Source Port: any
Destination Network: $HOME_NET
Destination Port: any
Flow: established,to_client
Contents:
- Value: "PRIVMSG " Depth: 8
Within:
PCRE: "/^[^\r\n]*?(?:p[ao]rt|udp|c?tcp|http|d(?:ie|ownload)|mail|c?back|(?:msg|notice)?flood)/Ri"
Special Options: