""ET INFO .exe File requested over FTP""

SID: 2014906

Revision: 2

Class Type: misc-activity

Metadata: attack_target Client_and_Server, created_at 2012_06_15, deployment Perimeter, deployment alert_only, signature_severity Informational, updated_at 2023_05_01

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: 21

Flow: established,to_server

Contents:

  • Value: "RETR" Depth: 4

  • Value: ".exe|0d 0a|"

Within:

PCRE: "/^RETR\s+[^\r\n]+?\x2eexe\r?$/m"

Special Options:

source