10/27/2008

only some Snort rules detect some malicious traffic

Download the most effective malware infection detection Snort signatures as experienced by our Malware Honeynet.

Most Effective Malware-Related Snort Signatures  Sun Oct 26 11:24:52 2008

Phase = BotHunter infection phase: (scan, infection, egg download, C&C, outbound attack)
Malcode = Number of unique malware binaries that this rule fired on during the analysis window
Infects = Number of malware infections that this rule detected during the analysis window
Detects = 30-day signature detection rates based on exposure to 23035 malware infections

DetectsSIDFirstLastInfectsAuthorPhaseDescription
59%299913:105/1910/2513794 of 23035snortinbound exploitshellcode x86 0x90 unicode noop
47%5001684:9905/1910/2511030 of 23035bothunteregg downloadbothunter malware windows executable (p...
44%22466:705/1910/2510156 of 23035snortinbound exploitnetbios smb-ds ipc$ unicode share access
43%52123:306/0510/2510116 of 23035snortoutbound scanregistered free attack-responses micros...
37%292000032:9905/1910/258640 of 23035bothunterinbound exploitbothunter exploit lsa exploit
37%22000032:605/1910/258620 of 23035emerging threatsinbound exploitbleeding-edge exploit lsa exploit
36%2001683:305/1910/258354 of 23035emerging threatsegg downloadbleeding-edge malware windows executabl...
26%3000003:9905/1910/256065 of 23035bothunteregg downloadbothunter http-based .exe upload on bac...
24%3001441:105/1910/255570 of 23035snortegg downloadtftp get .exe from external source
24%1444:305/1910/255570 of 23035snortegg downloadtftp get from external source
24%2008120:105/1910/255570 of 23035emerging threatsegg downloadpolicy outbound tftp read request
19%3000000:9905/1910/254469 of 23035bothunteregg downloadbothunter http-based .exe upload on bac...
10%299998:105/1910/252440 of 23035snortinbound exploitshellcode x86 inc ebx noop
10%21390:505/1910/252440 of 23035snortinbound exploitregistered free shellcode x86 inc ebx noop
09%299906:105/1910/252239 of 23035snortinbound exploitshellcode x86 0x90 unicode noop
09%31000004:9905/1910/252127 of 23035bothunteregg downloadbothunter scrip-based windows egg downl...
06%2000352:605/1910/051389 of 23035emerging threatslocal attack prepattack response irc - dns request on...
05%3000006:9905/1910/011233 of 23035bothunteregg downloadbothunter malware executable upload
03%2002029:705/1910/25921 of 23035emerging threatsc&c channeltrojan bot - channel topic scan/expl...
03%2003603:205/1910/25713 of 23035emerging threatsc&c channeltrojan w32.virut.a joining an irc ch...

and the rest is even less....... 

don't count on the machine to stop all, count on the machine to stop some so you can treat the rest with your own intelligence and other tools....

13:17 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment