""ET INFO Windows Commands and Variables in DNS Reply""
SID: 2038931
Revision: 1
Class Type: bad-unknown
Metadata: attack_target Client_Endpoint, created_at 2022_09_22, deployment Perimeter, signature_severity Informational, updated_at 2022_09_22
Reference:
Protocol: udp
Source Network: any
Source Port: 53
Destination Network: $HOME_NET
Destination Port: any
Flow:
Contents:
- Value: "|00 10 00 01|"
Offset: 2
-
Value: "|24|env|3a|"
-
Value: "copy|20|"
-
Value: "cd|20|"
Within:
PCRE:
Special Options:
- fast_pattern