""ET VOIP Possible Misuse Call from MERA RTU""
SID: 2022022
Revision: 1
Class Type: misc-attack
Metadata: created_at 2015_11_03, updated_at 2015_11_03
Reference:
Protocol: tcp
Source Network: $EXTERNAL_NET
Source Port: any
Destination Network: $HOME_NET
Destination Port: 1720
Flow: to_server,established
Contents:
- Value: "|22 c0 09 00 7a b7 07|MERA RTU|08|"
Within:
PCRE:
Special Options: