Back to Rule

Rule History

SID: 2009099 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 5Jul 30, 2010, 12:00 PM

ET P2P ThunderNetwork UDP Traffic

alert udp $HOME_NET 1024:65535 -> [$EXTERNAL_NET,!224.0.0.0/4] 1024:65535 (msg:"ET P2P ThunderNetwork UDP Traffic"; dsize:<38; content:"|32 00 00 00|"; depth:4; content:"|00 00 00 00|"; distance:1; threshold:type limit, track by_src, count 1, seconds 300; reference:url,xunlei.com; reference:url,en.wikipedia.org/wiki/Xunlei; classtype:policy-violation; sid:2009099; rev:5; metadata:created_at 2010_07_30, deprecation_reason False_Positive, confidence High, signature_severity Informational, updated_at 2026_02_23;)

Jul 30, 2010, 12:00 PM

Feb 23, 2026, 12:00 PM

Sep 21, 2024, 3:00 AM

Feb 23, 2026, 10:34 PM

rules/emerging-p2p.rules