Rule Category

MALWARE-CNC -- Snort has detected a Comand and Control (CNC) rule violation, most likely for commands and calls for files or other stages from the control server. The alert indicates a host has been infiltrated by an attacker, who is using the host to make calls for files, as a call-home vector for other malware-infected networks, for shuttling traffic back to bot owners, etc.

Alert Message

MALWARE-CNC Phoenix exploit kit post-compromise behavior

Rule Explanation

Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors. Impact: CVSS base score 5.1 CVSS impact score 6.4 CVSS exploitability score 4.9 confidentialityImpact PARTIAL integrityImpact PARTIAL availabilityImpact PARTIAL Details: Ease of Attack:

What To Look For

No information provided

Known Usage

No public information

False Positives

No known false positives

Contributors

Talos research team. This document was generated from data supplied by the national vulnerability database, a product of the national institute of standards and technology. For more information see [nvd].

Rule Groups

No rule groups

CVE

Additional Links

Rule Vulnerability

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2006-0003
Loading description
CVE-2007-5659
Loading description
CVE-2008-0655
Loading description
CVE-2008-2992
Loading description
CVE-2008-5353
Loading description
CVE-2009-0927
Loading description
CVE-2009-3867
Loading description
CVE-2009-4324
Loading description
CVE-2010-0188
Loading description
CVE-2010-0248
Loading description
CVE-2010-0840
Loading description
CVE-2010-0842
Loading description
CVE-2010-0866
Loading description
CVE-2010-1240
Loading description
CVE-2010-1297
Loading description
CVE-2011-2110
Loading description
CVE-2011-2140
Loading description
CVE-2011-2371
Loading description
CVE-2011-3544
Loading description
CVE-2011-3659
Loading description
CVE-2012-0500
Loading description
CVE-2012-0507
Loading description
CVE-2012-0779
Loading description