Versions (3)
Version DetailsCurrent
Rev: 6 • Jan 24, 2012, 12:00 PMET INFO Possible URL List or Clickfraud URLs Delivered To Client
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET INFO Possible URL List or Clickfraud URLs Delivered To Client"; flow:established,from_server; content:"|0d 0a 0d 0a|http|3a|//"; content:"|7C|http|3a|//"; distance:0; content:"|0D 0A|http|3a|//"; distance:0; content:"|7C|http|3a|//"; distance:0; classtype:misc-activity; sid:2014149; rev:6; metadata:attack_target Client_Endpoint, created_at 2012_01_24, deployment Perimeter, confidence Low, signature_severity Informational, updated_at 2023_04_20; target:dest_ip;)
Jan 24, 2012, 12:00 PM
Apr 20, 2023, 12:00 PM
Jan 24, 2012, 12:00 PM
Sep 13, 2024, 3:01 PM
rules/emerging-info.rules