IDP/IPS “Snort” Signatures for DNS Changer

Thanks to the Emerging Threats community, we have updated and maintained signatures for DNS Changer. These signatures would be critical to an organization to spot and remediate violated machines in their network.

Please check out this updated list here (DNS Changer Signatures)

What is the “Emerging Threats community?” The community produces the fastest moving and most diverse Suricata and SnortRulesets and firewall rules available. The community Open content is free to use by any user or organization, commercial or private. The community only ask that when you detect new threats in your environment or write new rules suitable for public release that you share that intelligence with the community at large through our mailing lists, or directly at threats@emergingthreats.net. The community updates these rulesets as new information surfaces (usually several times a day 7 days a week) and highly recommend you update at least twice a week to stay up to date. Daily is your best bet.