Back to Rule

Rule History

SID: 2017653 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 15Nov 1, 2013, 12:00 PM

ET DELETED Possible Neutrino EK Java Exploit/Payload Download Nov 1 2013

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET DELETED Possible Neutrino EK Java Exploit/Payload Download Nov 1 2013"; flow:established,to_server; content:"Java/1."; http_user_agent; pcre:"/^\/[a-z]{5,14}\?[a-z]{5,12}=[a-z]{6,11}$/U"; reference:url,pastebin.com/194D8UuK; classtype:exploit-kit; sid:2017653; rev:15; metadata:created_at 2013_11_01, signature_severity Unknown, updated_at 2019_07_26;)

Nov 1, 2013, 12:00 PM

Jul 26, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-deleted.rules