ET HUNTING Byte-order mark UTF-16BE (big endian)

SID: 2055646Rev: 155 views
Sourceet/open
CreatedAugust 30, 2024
UpdatedAugust 30, 2024
Classificationmisc-activity
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET HUNTING Byte-order mark UTF-16BE (big endian)"; flow:established,to_client; flowbits:set,ET.BOM.utf16be; flowbits:noalert; http.response_body; content:"|fe ff|"; startswith; fast_pattern; content:!"|00 00|"; within:2; reference:url,learn.microsoft.com/en-us/windows/win32/intl/using-byte-order-marks; reference:url,isc.sans.edu/diary/31204; classtype:misc-activity; sid:2055646; rev:1; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, affected_product Windows_11, attack_target Client_Endpoint, tls_state TLSDecrypt, created_at 2024_08_30, deployment Perimeter, deployment SSLDecrypt, confidence High, signature_severity Informational, updated_at 2024_08_30; target:dest_ip;)

Metadata

affected productWindows_11
attack targetClient_Endpoint
tls stateTLSDecrypt
created at2024_08_30
deploymentSSLDecrypt
confidenceHigh
signature severityInformational
updated at2024_08_30

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!