Back to Rule

Rule History

SID: 2022115 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 2Nov 17, 2015, 12:00 PM

ET INFO Serialized Java Object Calling Common Collection Function

alert tcp any any -> $HOME_NET any (msg:"ET INFO Serialized Java Object Calling Common Collection Function"; flow:to_server,established; content:"|ac ed 00 05 73 72 00|"; fast_pattern; content:"commons.collections"; nocase; distance:0; reference:url,github.com/foxglovesec/JavaUnserializeExploits; classtype:misc-activity; sid:2022115; rev:2; metadata:created_at 2015_11_17, former_category EXPLOIT, confidence High, signature_severity Informational, updated_at 2024_06_14;)

Nov 17, 2015, 12:00 PM

Jun 14, 2024, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-info.rules