CHAT: w3tw0rk Or Pitbul IRC Bot Remote Code Execution

This signature detects chat patterns associated with the w3tw0rk or Pitbul IRC BotNet. Computers infected with malware can use the Internet Relay Chat protocol to "phone home" for instructions by the Botnet controller. It may also be a false positive.

Short Name
CHAT:IRC:BOTNET:W3TW0RK-RCE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
CHAT
Keywords
Bot Code Execution IRC Or Pitbul Remote w3tw0rk
Release Date
08/18/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/6667
False Positive
Unknown

Found a potential security threat?