> IPv4 (TCP or SCTP) and dst port (43253 or 43753 or 63424 or 26424) So this is hiding network traffic from certain ports, which means that it should be easy enough to spot on spanports or netflow data Are there any good tools which detect malware from analysing network traffic, either things like machines doing wide range attempts to connect on 137/139/445, or burte forcing on 22 etc, but also for more advanced sear…
I wouldn’t mind having a hardware / software network analyzing combo. Could probably do something as a plugin for OpenWRT — check consistency, packet sizes, ports in use, outbound hosts, etc. Could auto flag suspicious endpoints for further analysis, and if found to be malware for anyone, gets shoved in a db and shared. Malware could always bounce traffic off of a known host but that would move the needle in any case…