SUC026 : DataCha0s Web Scanner/Robot

  • Use Case Reference : SUC026
  • Use Case Title : DataCha0s Web Scanner/Robot
  • Use Case Detection : IDS / HTTP logs
  • Attacker Class : Opportunists
  • Attack Sophistication : Unsophisticated
  • Source IP(s) : Random
  • Source Countries : Most of US and Brasil
  • Source Port(s) : Random
  • Destination Port(s) : 80/TCP, 443/TCP

Possible(s) correlation(s) :

  • DataCha0s bot.

Source(s) :

Emerging Threats SIG 2003616 triggers are :

  • The HTTP header should contain “DataCha0s” User Agent string. Example : User-Agent: DataCha0s/2.0
  • The source port could be any FROM EXTERNAL_NET in destination of an HOME_NET HTTP_PORTS.
SIG 2003616 1 Week events activity
SIG 2003616 1 Week events activity
SIG 2003616 1 month events activity
SIG 2003616 1 month events activity
1 Month TOP 10 source IPs for SIG 2003616
1 Month TOP 10 source IPs for SIG 2003616
TOP 20 source countries for SIG 2003616
TOP 20 source countries for SIG 2003616