Home | About Us | FAQ | Signature Downloads | All Projects | Submit a Signature | Mailing Lists | Feeds | Open Job Board | Sponsors | Documentation

  • RSS Latest Docs

    • 2003394
    • SnortConfSamples
    • FastFluxDNSResponseDetection
    • 2007634
    • DilipPatel
    • TestTest123
    • 2003642
    • 2007588
    • 2007688
    • 2007706
  • RSS Latest Sigs

    • VIRUS/TROJAN_PRG
    • VIRUS/TROJAN_Win32.Pakes
    • current-sids.txt
    • CURRENT_EVENTS/CURRENT_WPAD
    • current-sids.txt
    • CURRENT_EVENTS/CURRENT_WPAD
    • current-sids.txt
    • WEB/WEB_Neosploit
    • current-sids.txt
    • VIRUS/TROJAN_Win32.Pakes
  • Recent Comments

    • gabrix on I’m Leaving Bleeding Threats!
    • Buck on Guard.zip Phish, Very targeted, Sig Available
    • Lance on Guard.zip Phish, Very targeted, Sig Available
    • akgunk on Guard.zip Phish, Very targeted, Sig Available
    • Bill475382635','199440348billy@msn.com','','20.134.10.131','2008-05-20 20:38:34','2008-05-20 20:38:34','','0','lynx','comment','0','0'),('0', '', '', '', '', '2008-05-21 20:38:34', '2008-05-21 20:38:34', '', 'spam', '', 'comment', '0','0' ) /* on How to Integrate/Use Bleeding Snort Rules
  • Recent Posts

    • Rule & Firewall Updates Re-enabled
    • I’m Leaving Bleeding Threats!
    • Encrypted Storm Sigs
    • Windows 98 Snort Signature
    • E-Jihad Tool Sigs
  • « New MS DNS Vulnerability!
    Temporary MS DNS Rule »

    Storm worm email rules

    In light of the number of storm worm emails out there, it’s been suggested we put some sigs up for them. The attachments are predictable, so they’re pretty reliable sigs:

    alert tcp any any -> $HOME_NET 25 (msg:”BLEEDING-EDGE CURRENT EVENTS Probable Storm Worm Email Inbound (patch-)”; flow:established,to_server; content:”filename=|22|patch|2e|”; nocase; pcre:”/patch-\d{4,5}\x2ezip/i”; classtype:attempted-admin; reference:url,isc.sans.org/diary.html?storyid=2612; sid:2003571; rev:1;)

    alert tcp any any -> $HOME_NET 25 (msg:”BLEEDING-EDGE CURRENT EVENTS Probable Storm Worm Email Inbound (bugfix-)”; flow:established,to_server; content:”filename=|22|bugfix|2e|”; nocase; pcre:”/bugfix-\d{4,5}\x2ezip/i”; classtype:attempted-admin; reference:url,isc.sans.org/diary.html?storyid=2612; sid:2003572; rev:1;)

    alert tcp any any -> $HOME_NET 25 (msg:”BLEEDING-EDGE CURRENT EVENTS Probable Storm Worm Email Inbound (hotfix-)”; flow:established,to_server; content:”filename=|22|hotfix|2e|”; nocase; pcre:”/hotfix-\d{4,5}\x2ezip/i”; classtype:attempted-admin; reference:url,isc.sans.org/diary.html?storyid=2612; sid:2003573; rev:1;)

    alert tcp any any -> $HOME_NET 25 (msg:”BLEEDING-EDGE CURRENT EVENTS Probable Storm Worm Email Inbound (removal-)”; flow:established,to_server; content:”filename=|22|removal|2e|”; nocase; pcre:”/removal-\d{4,5}\x2ezip/i”; classtype:attempted-admin; reference
    :url,isc.sans.org/diary.html?storyid=2612; sid:2003574; rev:1;)

    Please let me know how they fare. We’ll remove them in a week or so, once the volume drops.

    Matt

    This entry was posted on Friday, April 13th, 2007 at 3:55 pm and is filed under General, New Rules. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Leave a Reply

    You must be logged in to post a comment.

    Entries (RSS) and Comments (RSS)
    Copyright © 2007 Bleeding Edge Threats.
    All trademarks and copyrights on this page are owned by their respective owners. Snort® is a registered trademark of Sourcefire, Inc.