Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: InfoSec Handlers Diary Blog - SANS Internet Storm Center InfoSec Handlers Diary Blog

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Reports of Strange TCP Port 443 Behavior

Published: 2012-12-07
Last Updated: 2012-12-07 16:47:27 UTC
by Richard Porter (Version: 2)
0 comment(s)

A reader posted that they are observing strange TCP 443 behavior that looks like a fast flux [1] style pattern. They have a large snort sensor install base. Is anyone else seeing behavior like this? If so.... Got packets?

If you are seeing this behavior and are allowed please report it!



Richard Porter

--- ISC Handler on Duty

Keywords: faq fast flux
0 comment(s)
Diary Archives