""ET INFO Executable Download from dotted-quad Host""

SID: 2016141

Revision: 5

Class Type: bad-unknown

Metadata: attack_target Client_and_Server, created_at 2013_01_03, deployment Perimeter, performance_impact Significant, signature_severity Informational, updated_at 2024_04_09

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: ".exe"

  • Value: ".exe HTTP/1."

  • Value: "Host|3A 20|"

  • Value: "|2E|"

  • Value: "|2E|"

  • Value: "|2E|"

Within: 3

PCRE: "/^Host\x3A\x20[0-9]{1,3}\x2E[0-9]{1,3}\x2E[0-9]{1,3}\x2E[0-9]{1,3}(\x3A|\x0D\x0A)/Hmi"

Special Options:

  • http_uri

  • nocase

  • http_header

  • http_header

  • http_header

  • http_header

source