Back to Rule

Rule History

SID: 2015752 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 3Oct 1, 2012, 12:00 PM

ET DELETED Windows EXE with alternate byte XOR 51 - possible SofosFO/NeoSploit download

alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET DELETED Windows EXE with alternate byte XOR 51 - possible SofosFO/NeoSploit download"; flow:established,to_client; content:"|0d 0a|Mi"; isdataat:76,relative; content:"|54 5b 69 40 20 43 72 5c 67 41 61 5e 20 50 61 5d 6e 5c 74 13 62 56 20 41 75 5d 20 5a 6e 13 44 7c 53 13 6d 5c 64 56|"; distance:0; classtype:trojan-activity; sid:2015752; rev:3; metadata:created_at 2012_10_01, signature_severity Unknown, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)

Oct 1, 2012, 12:00 PM

Jul 26, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

Oct 1, 2025, 9:34 PM

rules/emerging-deleted.rules