""ET INFO SUSPICIOUS IRC - NICK and Possible Windows XP/7""

SID: 2017321

Revision: 8

Class Type: bad-unknown

Metadata: created_at 2013_08_13, updated_at 2015_08_17

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "NICK " Depth: 5

  • Value: !"|20|XP/7"

Within:

PCRE: "/^[^\r\n]*(?:W(?:in(?:dows)?)?[^a-z0-9]?(XP|[7-8])|Vista)/Ri"

Special Options:

source