""ET EXPLOIT NTDump.exe Service Started port 445""

SID: 2001544

Revision: 8

Class Type: misc-activity

Metadata: created_at 2010_07_30, updated_at 2010_11_04

Reference:

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: $HOME_NET

Destination Port: 445

Flow: to_server,established

Contents:

  • Value: "|4e 00 74 00 44 00 75 00 6d 00 70 00 53 00 76 00 63 00 2e 00 65 00 78 00 65 00|"

Within:

PCRE:

Special Options:

source