Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Generic IRC Client Detection / Generic Botnet Detection

Info

Synopsis

The remote host is running an IRC client.

Description

The remote host appears to be running a machine that has installed an IRC client. IRC is a protocol for messaging. In many cases, IRC is used for botnet C&C traffic.

Solution

Manually inspect the machine for malicious processes to ensure that the IRC traffic is innocuous in nature.