Back to Rule

Rule History

SID: 2020705 • Source: et/open

Versions (2)

Version DetailsCurrent

Rev: 8Mar 18, 2015, 12:00 PM

ET HUNTING Generic - Mozilla 4.0 EXE Request

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET HUNTING Generic - Mozilla 4.0 EXE Request"; flow:established,to_server; urilen:6<>15; http.uri; content:".exe"; endswith; http.user_agent; content:"Mozilla/4.0"; fast_pattern; bsize:11; classtype:misc-activity; sid:2020705; rev:8; metadata:attack_target Client_and_Server, created_at 2015_03_18, deployment Perimeter, confidence Low, signature_severity Informational, updated_at 2023_05_02; target:src_ip;)

Mar 18, 2015, 12:00 PM

May 2, 2023, 12:00 PM

Mar 18, 2015, 12:00 PM

May 31, 2024, 9:00 PM

rules/emerging-hunting.rules