Back to Rule

Rule History

SID: 2021066 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 2May 7, 2015, 12:00 PM

ET VOIP Possible Misuse Call from Cisco ooh323

alert tcp $EXTERNAL_NET any -> $HOME_NET 1720 (msg:"ET VOIP Possible Misuse Call from Cisco ooh323"; flow:to_server,established; content:"|28 06|cisco|00|"; offset:14; depth:8; content:"|b8 00 00 27 05|ooh323|06|"; within:60; reference:url,videonationsltd.co.uk/2015/04/h-323-cisco-spam-calls/; classtype:misc-attack; sid:2021066; rev:2; metadata:created_at 2015_05_07, confidence Medium, signature_severity Informational, updated_at 2020_08_19;)

May 7, 2015, 12:00 PM

Aug 19, 2020, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-voip.rules