RE : Re: RE : Re: Sig idea - try2check.me
Thx Elhoim,
Check again copy/paste tcp flow please and reference url...
Another idea: add byte_test !& 128 for detect dns request ...
If (only) stream5 udp are enabled : Adding on udp rule, flow to_server...
Best Regards
Rmkml
-------- Original message --------
Subject: Re: RE : Re: [Emerging-Sigs] Sig idea - try2check.me
From: DA
To: rmkml <at> yahoo.fr,jonkman <at> gmail.com,Emerging-sigs <at> emergingthreats.net
CC:
Hi
I indeed borked my copy/paste kung-fu.. :)
alert udp any any -> any 53 (msg:"try2check.me Carding Checker Site DNS
Connection"; content:"|09|try2check|02|me|00|"; nocase;
classtype:bad-unknown; sid:5000001;
ref:"https://cert.xmco.fr/blog/index.php?post/2012/02/23/Try2check.me%2C-le-maillon-fort";
rev:2;)
alert tcp any any -> any 53 (msg:"try2check.me Carding Checker Site DNS
Connection"; content:"|09|try2check|02|me|00|"; nocase;
flow:established,to_/server/; classtype:bad-unknown; sid:5000002;
ref:"https://cert.xmco.fr/blog/index.php?post/2012/02/23/Try2check.me%2C-le-maillon-fort";
rev:2;)
Regards,
elhoim
On 24/02/12 18:56, rmkml <at> yahoo.fr wrote:
> Hi Elhoim,
> Nice rules,
> But Im curious why the second content (0x09) please ?
> Maybe add flow to_server ?
> Maybe nocase are on wrong place ?
> Best Regards
> Rmkml
>
>
>
> -------- Original message -------- Subject: Re: [Emerging-Sigs] Sig
> idea - try2check.me From: Matthew Jonkman To: elhoim <at> gmail.com CC:
> Emerging-sigs <at> emergingthreats.net
>
> Nice, thanks AD.
>
> ANyone have a few minutes to pull the ssl cert from a few hits and see
> if it's consistent? We could sig that as well.
>
> Matt
>
>
> On Feb 24, 2012, at 4:13 AM, AD wrote:
>
> > It is a credit card checker for the carders.
> > They are security conscious, and use a unique hostname & port per
> > client, and https.
> >
> > According to the article they are quite popular in the underground.
> >
> > And thus, here is a little sig to find if some of your users are using
> > that site:
> >
> > alert udp any any -> any 53 (msg: " |09|try2check|02|me|00|";
> > content:"|09|"; nocase; classtype:bad-unknown; sid:5000001;
> >
> ref:"https://cert.xmco.fr/blog/index.php?post/2012/02/23/Try2check.me%2C-le-maillon-fort";
> > rev:1;)
> > alert tcp any any -> any 53 (msg: " |09|try2check|02|me|00|";
> > content:"|09|"; nocase; classtype:bad-unknown; sid:5000002;
> >
> ref:"https://cert.xmco.fr/blog/index.php?post/2012/02/23/Try2check.me%2C-le-maillon-fort";
> > rev:1;)
> >
> >
> > References
> > in french -
> https://cert.xmco.fr/blog/index.php?post/2012/02/23/Try2check.me%2C-le-maillon-fort
>
<div>Thx Elhoim,<div><br></div>
<div>Check again copy/paste tcp flow please and reference url...</div>
<div><br></div>
<div>Another idea: add byte_test !& 128 for detect dns request ...</div>
<div><br></div>
<div>If (only) stream5 udp are enabled : Adding on udp rule, flow to_server...</div>
<div>Best Regards</div>
<div>Rmkml</div>
<div><br></div>
<br><br>
-------- Original message --------
Subject: Re: RE : Re: [Emerging-Sigs] Sig idea - try2check.me
From: DA
To: rmkml <at> yahoo.fr,jonkman <at> gmail.com,Emerging-sigs <at> emergingthreats.net
CC:
<br><br><div>Hi<br><br>I indeed borked my copy/paste kung-fu.. :)<br><br>alert udp any any -> any 53 (msg:"try2check.me Carding Checker Site DNS<br>Connection"; content:"|09|try2check|02|me|00|"; nocase;<br>classtype:bad-unknown; sid:5000001;<br>ref:"https://cert.xmco.fr/blog/index.php?post/2012/02/23/Try2check.me%2C-le-maillon-fort";<br>rev:2;)<br>alert tcp any any -> any 53 (msg:"try2check.me Carding Checker Site DNS<br>Connection"; content:"|09|try2check|02|me|00|"; nocase;<br> flow:established,to_/server/; classtype:bad-unknown; sid:5000002;<br>ref:"https://cert.xmco.fr/blog/index.php?post/2012/02/23/Try2check.me%2C-le-maillon-fort";<br>rev:2;)<br><br>Regards,<br>elhoim<br><br>On 24/02/12 18:56, rmkml <at> yahoo.fr wrote:<br>> Hi Elhoim,<br>> Nice rules,<br>> But Im curious why the second content (0x09) please ?<br>> Maybe add flow to_server ?<br>> Maybe nocase are on wrong place ?<br>> Best Regards<br>> Rmkml<br>><br>><br>><br>> -------- Original message -------- Subject: Re: [Emerging-Sigs] Sig<br>> idea - try2check.me From: Matthew Jonkman To: elhoim <at> gmail.com CC:<br>> Emerging-sigs <at> emergingthreats.net<br>><br>> Nice, thanks AD.<br>><br>> ANyone have a few minutes to pull the ssl cert from a few hits and see<br>> if it's consistent? We could sig that as well.<br>><br>> Matt<br>><br>><br>> On Feb 24, 2012, at 4:13 AM, AD wrote:<br>><br>> > It is a credit card checker for the carders.<br>> > They are security conscious, and use a unique hostname & port per<br>> > client, and https.<br>> ><br>> > According to the article they are quite popular in the underground.<br>> ><br>> > And thus, here is a little sig to find if some of your users are using<br>> > that site:<br>> ><br>> > alert udp any any -> any 53 (msg: " |09|try2check|02|me|00|";<br>> > content:"|09|"; nocase; classtype:bad-unknown; sid:5000001;<br>> ><br>> ref:"https://cert.xmco.fr/blog/index.php?post/2012/02/23/Try2check.me%2C-le-maillon-fort";<br>> > rev:1;)<br>> > alert tcp any any -> any 53 (msg: " |09|try2check|02|me|00|";<br>> > content:"|09|"; nocase; classtype:bad-unknown; sid:5000002;<br>> ><br>> ref:"https://cert.xmco.fr/blog/index.php?post/2012/02/23/Try2check.me%2C-le-maillon-fort";<br>> > rev:1;)<br>> ><br>> ><br>> > References<br>> > in french -<br>> https://cert.xmco.fr/blog/index.php?post/2012/02/23/Try2check.me%2C-le-maillon-fort<br>><br><br>
</div> </div>