Back to Rule

Rule History

SID: 2027565 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 2Jun 26, 2019, 12:00 PM

ET USER_AGENTS Fake Mozilla User-Agent String Observed (M0zilla)

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET USER_AGENTS Fake Mozilla User-Agent String Observed (M0zilla)"; flow:established,to_server; http.user_agent; content:"M0zilla|2f|"; depth:8; fast_pattern; content:"."; distance:1; within:1; reference:md5,c6c1292bf7dd1573b269afb203134b1d; classtype:trojan-activity; sid:2027565; rev:2; metadata:created_at 2019_06_26, confidence High, signature_severity Major, updated_at 2020_08_31;)

Jun 26, 2019, 12:00 PM

Aug 31, 2020, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-user_agents.rules