The following is a sample Snort rules file.
var HTTP_PORTS [80,443,8080] var HOME_NET [10.0.0.0/8,192.168.0.0/16,172.16.0.0/12,169.254.0.0/16,1.0.0.0/8,2.0.0.0/8] var EXTERNAL_NET ![$HOME_NET,198.80.42.0/23,198.217.128.0/17,198.241.128.0/17,64.94.118.0/23,66.185.176.0/20] alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN TeleBots BCS-server CnC Beacon_NIDS779"; flow:established,to_server; urilen:1; content:"POST"; http_method; content:"value="; depth:6; http_client_body; fast_pattern; content:!"Content-Type|3a|"; http_header; content:!"Referer|3a|"; http_header; reference:url,www.welivesecurity.com/2016/12/13/rise-telebots-analyzing-disruptive-killdisk-attacks/; classtype:trojan-activity; sid:2023652; rev:1;)
Note
The variables and rules can be in separate files. If you are using separate files for variables and rules, ensure that you load the variables before loading the rules.