Back to Rule

Rule History

SID: 2014149 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 6Jan 24, 2012, 12:00 PM

ET INFO Possible URL List or Clickfraud URLs Delivered To Client

alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET INFO Possible URL List or Clickfraud URLs Delivered To Client"; flow:established,from_server; content:"|0d 0a 0d 0a|http|3a|//"; content:"|7C|http|3a|//"; distance:0; content:"|0D 0A|http|3a|//"; distance:0; content:"|7C|http|3a|//"; distance:0; classtype:misc-activity; sid:2014149; rev:6; metadata:attack_target Client_Endpoint, created_at 2012_01_24, deployment Perimeter, confidence Low, signature_severity Informational, updated_at 2023_04_20; target:dest_ip;)

Jan 24, 2012, 12:00 PM

Apr 20, 2023, 12:00 PM

Jan 24, 2012, 12:00 PM

Sep 13, 2024, 3:01 PM

rules/emerging-info.rules