Back to Rule

Rule History

SID: 2016778 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 8Apr 20, 2013, 12:00 PM

ET DNS Query to a *.pw domain - Likely Hostile

alert dns $HOME_NET any -> any any (msg:"ET DNS Query to a *.pw domain - Likely Hostile"; dns.query; content:".pw"; nocase; endswith; content:!".u.pw"; endswith; nocase; classtype:bad-unknown; sid:2016778; rev:8; metadata:created_at 2013_04_20, confidence Medium, signature_severity Informational, updated_at 2020_11_19, reviewed_at 2024_04_22;)

Apr 20, 2013, 12:00 PM

Nov 19, 2020, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-dns.rules