Back to Rule

Rule History

SID: 2007569 • Source: et/open

Versions (2)

Version DetailsCurrent

Rev: 11Jul 30, 2010, 12:00 PM

ET DELETED QQPass Related User-Agent Infection Checkin (App4)

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET DELETED QQPass Related User-Agent Infection Checkin (App4)"; flow:to_server,established; content:"User-Agent|3a| App"; http_header; content:!"Host|3a| liveupdate.symantecliveupdate.com|0d 0a|"; http_header; pcre:"/^User-Agent\: App\d/Hmi"; classtype:trojan-activity; sid:2007569; rev:11; metadata:created_at 2010_07_30, signature_severity Unknown, updated_at 2019_07_26;)

Jul 30, 2010, 12:00 PM

Jul 26, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-deleted.rules