Back to Rule

Rule History

SID: 2025790 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 2Jul 6, 2018, 12:00 PM

ET NETBIOS PolarisOffice Insecure Library Loading - SMB ASCII

alert tcp $HOME_NET [445,139] -> any any (msg:"ET NETBIOS PolarisOffice Insecure Library Loading - SMB ASCII"; flow:from_server; content:"SMB"; offset:4; depth:5; byte_test:1,!&,0x80,7,relative; content:"puiframeworkproresenu|2E|dll"; nocase; distance:0; fast_pattern; reference:cve,2018-12589; reference:url,exploit-db.com/exploits/44985; classtype:attempted-user; sid:2025790; rev:2; metadata:attack_target Client_Endpoint, created_at 2018_07_06, cve CVE_2018_12589, deployment Perimeter, signature_severity Informational, updated_at 2021_09_09;)

Jul 6, 2018, 12:00 PM

Sep 9, 2021, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-netbios.rules