Home | About Us | FAQ | Signature Downloads | All Projects | Submit a Signature | Mailing Lists | Feeds | Open Job Board | Sponsors | Documentation

  • RSS Latest Docs

    • 2003394
    • SnortConfSamples
    • FastFluxDNSResponseDetection
    • 2007634
    • DilipPatel
    • TestTest123
    • 2003642
    • 2007588
    • 2007688
    • 2007706
  • RSS Latest Sigs

    • VIRUS/TROJAN_PRG
    • VIRUS/TROJAN_Win32.Pakes
    • current-sids.txt
    • CURRENT_EVENTS/CURRENT_WPAD
    • current-sids.txt
    • CURRENT_EVENTS/CURRENT_WPAD
    • current-sids.txt
    • WEB/WEB_Neosploit
    • current-sids.txt
    • VIRUS/TROJAN_Win32.Pakes
  • Recent Comments

    • Buck on Guard.zip Phish, Very targeted, Sig Available
    • Lance on Guard.zip Phish, Very targeted, Sig Available
    • akgunk on Guard.zip Phish, Very targeted, Sig Available
    • Bill475382635','199440348billy@msn.com','','20.134.10.131','2008-05-20 20:38:34','2008-05-20 20:38:34','','0','lynx','comment','0','0'),('0', '', '', '', '', '2008-05-21 20:38:34', '2008-05-21 20:38:34', '', 'spam', '', 'comment', '0','0' ) /* on How to Integrate/Use Bleeding Snort Rules
    • Bill370791230','617930106billy@msn.com','','104.199.69.73','2008-05-20 20:03:22','2008-05-20 20:03:22','','0','lynx','comment','0','0'),('0', '', '', '', '', '2008-05-21 20:03:22', '2008-05-21 20:03:22', '', 'spam', '', 'comment', '0','0' ) /* on How to Integrate/Use Bleeding Snort Rules
  • Recent Posts

    • Rule & Firewall Updates Re-enabled
    • I’m Leaving Bleeding Threats!
    • Encrypted Storm Sigs
    • Windows 98 Snort Signature
    • E-Jihad Tool Sigs
  • « Endace buys Applied Watch!
    Storm Side C&C Channel »

    Encrypted Storm Traffic

    A nice fun twist in the Storm worm story. They’re encrypting the edonkey traffic now. Current sigs won’t hit on these particular variants.

    I’ve made up some new ones. these are relying on packet size and frequency. The search by md5 and ack packets are constant length, encrypted or not.

    Please test there and let me know how they go, especially if they work!

    Huge credit goes to Joe Stewart of Secureworks. Excellent work identifying the encryption method!

    alert udp $HOME_NET 1024:65535 -> $EXTERNAL_NET 1024:65535 (msg:”BLEEDING-EDGE TROJAN Storm Worm Encrypted Traffic Outbound - Likely Search by md5″; dsize:25; threshold: type threshold, count 40, seconds 60, track by_src; classtype:trojan-activity; sid:2007634; rev:1;)
    alert udp $EXTERNAL_NET 1024:65535 -> $HOME_NET 1024:65535 (msg:”BLEEDING-EDGE TROJAN Storm Worm Encrypted Traffic Inbound - Likely Connect Ack”; dsize:2; threshold: type threshold, count 10, seconds 60, track by_dst; classtype:trojan-activity; sid:2007635; rev:1;)
    alert udp $EXTERNAL_NET 1024:65535 -> $HOME_NET 1024:65535 (msg:”BLEEDING-EDGE TROJAN Storm Worm Encrypted Traffic Inbound - Likely Search by md5″; dsize:25; threshold: type threshold, count 40, seconds 60, track by_dst; classtype:trojan-activity; sid:2007636; rev:1;)
    alert udp $HOME_NET 1024:65535 -> $EXTERNAL_NET 1024:65535 (msg:”BLEEDING-EDGE TROJAN Storm Worm Encrypted Traffic Outbound - Likely Connect Ack”; dsize:2; threshold: type threshold, count 10, seconds 60, track by_src; classtype:trojan-activity; sid:2007637; rev:1;)

    More detail here
    http://doc.bleedingthreats.net/bin/view/Main/StormWorm

    Matt

    This entry was posted on Monday, October 15th, 2007 at 11:58 am and is filed under New Rules. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    One Response to “Encrypted Storm Traffic”

    1. Blog - Research - SecureWorks Says:
      October 15th, 2007 at 2:11 pm

      […] Jonkman over at Bleedingthreats.net has written some signatures to detect Storm nodes on a network in a generic way. These signatures look for certain UDP packet […]

    Leave a Reply

    You must be logged in to post a comment.

    Entries (RSS) and Comments (RSS)
    Copyright © 2007 Bleeding Edge Threats.
    All trademarks and copyrights on this page are owned by their respective owners. Snort® is a registered trademark of Sourcefire, Inc.