""ET EXPLOIT [NCC GROUP] Possible Bluekeep Inbound RDP Exploitation Attempt (CVE-2019-0708)""

SID: 2027369

Revision: 3

Class Type: attempted-admin

Metadata: attack_target Client_and_Server, created_at 2019_05_21, deployment Perimeter, deployment Internet, deployment Internal, malware_family Bluekeep, signature_severity Major, updated_at 2019_05_21

Reference:

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: any

Destination Port: 3389

Flow: to_server,established

Contents:

  • Value: "|03 00|" Depth: 2

  • Value: "|02 f0|"

  • Value: "|00 05 00 14 7c 00 01|"

  • Value: "|03 c0|"

  • Value: "MS_T120|00|"

Within: 372

PCRE:

Special Options:

  • nocase

  • fast_pattern

source