Back to Rule

Rule History

SID: 2022579 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 2Mar 1, 2016, 12:00 PM

ET SCAN MySQL Malicious Scanning 1

alert tcp $EXTERNAL_NET any -> $HOME_NET 3306 (msg:"ET SCAN MySQL Malicious Scanning 1"; flow:to_server; content:"|00 03|"; offset:3; depth:2; content:"GRANT ALTER, ALTER ROUTINE"; distance:0; nocase; within:30; content:"TO root@% WITH"; fast_pattern; reference:url,isc.sans.edu/diary/Quick+Analysis+of+a+Recent+MySQL+Exploit/20781; classtype:bad-unknown; sid:2022579; rev:2; metadata:created_at 2016_03_01, confidence Medium, signature_severity Major, updated_at 2019_10_08;)

Mar 1, 2016, 12:00 PM

Oct 8, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-scan.rules