WORM: Miniflame Command and Conrol Communication

This signature detects the command-and-control communication of miniflame, an independent, stripped down variant of famous botnet, Flame. The source IP might be infected and should be removed from network and analyzed for malicious activity.

Short Name
WORM:MINIFLAME-CNC
Severity
Major
Recommended
False
Recommended Action
Drop
Category
WORM
Keywords
Command Communication Conrol Miniflame and
Release Date
12/17/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?