ET HUNTING HTTP Redirect Chain With Image Filetype in URI

SID: 2057440Rev: 111 views
History
Sourceet/open
CreatedNovember 13, 2024
UpdatedNovember 13, 2024
Classificationmisc-activity
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET HUNTING HTTP Redirect Chain With Image Filetype in URI"; flow:established,to_server; http.method; content:"GET"; http.uri; pcre:"/(?:png|jpg|jpeg)/"; content:"|3f|response|2d|content|2d|type|3d|"; fast_pattern; within:36; content:!"X-Amz-Algorithm="; classtype:misc-activity; sid:2057440; rev:1; metadata:attack_target Client_Endpoint, tls_state TLSDecrypt, created_at 2024_11_13, deployment Perimeter, deployment SSLDecrypt, confidence Medium, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_11_13;)

Metadata

attack targetClient_Endpoint
tls stateTLSDecrypt
created at2024_11_13
deploymentSSLDecrypt
confidenceMedium
signature severityInformational
tagDescription_Generated_By_Proofpoint_Nexus
updated at2024_11_13

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!