TROJAN: ngrBot IRC Command and Control Activity

This signature detects the IRC Command and Control activity of the ngrBot, a malicious trojan. Users infected by this trojan can have their web traffic redirected and intercepted, which could lead to an exposure of sensitive data, like banking information. This trojan also has the ability to erase the boot sector of the hard drive, resulting in an unusable system. The source IP is infected and should be removed from the network for forensic analysis and malware removal.

Short Name
TROJAN:NGRBOT-ACTIVITY
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
TROJAN
Keywords
Activity Command Control IRC and ngrBot
Release Date
07/14/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown

Found a potential security threat?