""ET INFO Suspicious User Agent (Autoupdate)""

SID: 2003337

Revision: 18

Class Type: trojan-activity

Metadata: created_at 2010_07_30, deployment Perimeter, deployment alert_only, performance_impact Low, confidence Low, signature_severity Informational, updated_at 2023_05_31

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "User-Agent|3a| Autoupdate"

  • Value: !"Host|3a| update.nai.com"

  • Value: !"McAfeeAutoUpdate"

  • Value: !"nokia.com"

  • Value: !"sophosupd.com"

  • Value: !"sophosupd.net"

  • Value: !" Creative AutoUpdate v"

  • Value: !"wholetomato.com"

  • Value: !".acclivitysoftware.com"

Within:

PCRE:

Special Options:

  • nocase

  • http_header

  • nocase

  • http_header

  • nocase

  • http_header

  • nocase

  • http_header

  • nocase

  • http_header

  • nocase

  • http_header

  • http_header

  • http_header

  • http_header

source