Back to Rule

Rule History

SID: 2016921 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 7May 24, 2013, 12:00 PM

ET DELETED Suspicious Mozilla UA with no Space after colon

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET DELETED Suspicious Mozilla UA with no Space after colon"; flow:established,to_server; content:"User-Agent|3a|Mozilla"; http_header; nocase; fast_pattern:only; threshold: type limit,track by_src,count 2,seconds 60; classtype:trojan-activity; sid:2016921; rev:7; metadata:created_at 2013_05_24, signature_severity Unknown, updated_at 2023_07_06;)

May 24, 2013, 12:00 PM

Jul 6, 2023, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-deleted.rules