Back to Rule

Rule History

SID: 2017652 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 9Nov 1, 2013, 12:00 PM

ET DELETED Possible Neutrino EK Landing URI Format Nov 1 2013

alert http $HOME_NET any -> $EXTERNAL_NET 8000 (msg:"ET DELETED Possible Neutrino EK Landing URI Format Nov 1 2013"; flow:established,to_server; urilen:18<>37; content:"GET"; http_method; content:"?"; http_uri; offset:6; depth:11; content:"="; http_uri; distance:5; within:8; pcre:"/^\/[a-z]{5,14}\?[a-z]{5,12}=\d{6,7}$/U"; classtype:exploit-kit; sid:2017652; rev:9; metadata:created_at 2013_11_01, signature_severity Unknown, updated_at 2019_07_26;)

Nov 1, 2013, 12:00 PM

Jul 26, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-deleted.rules