Does Astaro 5.0's IDS paterns include detection signatures for Phatbot and it's relatives?
If not, the following information may be useful:
Phatbot Information
This thread was automatically locked due to age.
Description: Agobot/Phatbot Infection Successful
Selector: tcp any any -> any any
Filter: flow:established; content:"221 Goodbye, have a good infection |3a 29 2e 0d 0a|"; dsize:40;
Description: Agobot/Phatbot Infection Successful
Selector: tcp any any -> any any
Filter: flow:established; content:"221 Goodbye, have a good infection |3a 29 2e 0d 0a|"; dsize:40;