""ET WEB_CLIENT SUSPICIOUS Java Lang Runtime in Response""

SID: 2018172

Revision: 1

Class Type: bad-unknown

Metadata: created_at 2014_02_25, updated_at 2014_02_25

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: any

Flow: from_server,established

Contents:

  • Value: !"|CA FE BA BE|"

  • Value: "getClass"

  • Value: "java.lang.Runtime"

  • Value: "getRuntime"

  • Value: "exec"

  • Value: "script"

Within: 4

PCRE:

Special Options:

  • file_data

  • nocase

  • nocase

  • nocase

  • nocase

  • nocase

source