Finding SRC IP on Snort (CnC)



  • I'm getting this alert every few times a day

    [1:2404324:4427] ET CNC Feodo Tracker Reported CnC Server TCP group 13 [Classification: A Network Trojan was Detected] [Priority: 1] {TCP} MY-WAN-IP-HERE:14121 -> 213.230.210.230:443

    I have snort enabled on WAN and LAN

    WAN is block
    LAN is alert

    All rules are enabled on both, with some suppressed to suit my network.

    But i can't find the source ip that is causing the outbound connection, it only show the WAN.

    My SIEM is picking up this from the logs forwarded to it from PfSense

    Nov 13 09:48:51 LOCAL-GATEWAY-IP-HERE snort[5096]: [1:2404324:4427] ET CNC Feodo Tracker Reported CnC Server TCP group 13 [Classification: A Network Trojan was Detected] [Priority: 1] {TCP} MY_WAN_ADDRESS_HERE:35518 -> 213.2 30.210.230:443

    I can't anywhere find the source, can someone advise why the snort on the lan isnt picking this up?



  • The source on mine was the yoyo adserver list I had enabled in pfblockerNG package.