2015-01-07 - DRIDEX ACTIVITY

NOTICE:

ASSOCIATED FILES:

 

NOTES:

 

MALWARE

 

TRAFFIC

TRAFFIC FROM AN INFECTION:

 

TCP CONNECTIONS ATTEMPTED, BUT RESET BY SERVER:

 

ALERTS

Emerging Threats and ETPRO rulesets from Sguil on Security Onion (without ET POLICY or ET INFO events):

Sourcefire VRT ruleset from Snort 2.9.7.0 on Debian 7 (not including preprocessor events):

 

Click here to return to the main page.