Back to Rule

Rule History

SID: 2016583 • Source: et/open

Versions (5)

Version DetailsCurrent

Rev: 6Mar 15, 2013, 12:00 PM

ET INFO SUSPICIOUS Java Request to DNSDynamic Dynamic DNS Domain

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO SUSPICIOUS Java Request to DNSDynamic Dynamic DNS Domain"; flow:to_server,established; http.user_agent; content:"Java/1."; http.host; pcre:"/\.(?:d(?:ns(?:d(?:ynamic\.(?:com|net)|\.(?:info|me))|api\.info|get\.org|53\.biz)|dns01\.com)|(?:f(?:lashserv|e100|tp21)|adultdns|mysq1|wow64)\.net|(?:(?:ima|voi)p01|(?:user|ole)32|kadm5)\.com|t(?:tl60\.(?:com|org)|empors\.com|ftpd\.net)|s(?:sh(?:01\.com|22\.net)|ql01\.com)|http(?:(?:s443|01)\.com|80\.info)|n(?:s360\.info|tdll\.net)|x(?:ns01\.com|64\.me)|craftx\.biz)(\x3a\d{1,5})?$/"; classtype:bad-unknown; sid:2016583; rev:6; metadata:created_at 2013_03_15, confidence High, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_09_02;)

Mar 15, 2013, 12:00 PM

Sep 2, 2020, 12:00 PM

Sep 21, 2024, 3:00 AM

Dec 12, 2025, 10:34 PM

rules/emerging-info.rules