Back to Rule

Rule History

SID: 2012144 • Source: et/open

Versions (2)

Version DetailsCurrent

Rev: 3Jan 5, 2011, 12:00 PM

ET DELETED Possible Malware Related Numerical .co Domain Lookup

alert udp $HOME_NET any -> any 53 (msg:"ET DELETED Possible Malware Related Numerical .co Domain Lookup"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|02|co|00|"; fast_pattern; nocase; distance:0; pcre:"/\x00[0-9]{4,7}\x02co\x00/i"; reference:url,sign.kaffenews.com/?p=104; reference:url,www.isc.sans.org/diary.html?storyid=10165; classtype:bad-unknown; sid:2012144; rev:3; metadata:created_at 2011_01_05, signature_severity Unknown, updated_at 2019_07_26;)

Jan 5, 2011, 12:00 PM

Jul 26, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-deleted.rules