""ET INFO Microsoft net.tcp Connection Initialization Activity""

SID: 2043233

Revision: 6

Class Type: bad-unknown

Metadata: affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2021_09_22, deployment Perimeter, signature_severity Informational, updated_at 2023_05_31, reviewed_at 2024_05_06, former_sid 2850027

Reference:

  • md5

  • 6b5c7d46224b4d7c38ec620c817867ad

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "|00 01 00 01 02 02|" Depth: 6

  • Value: "net.tcp|3a 2f 2f|"

  • Value: "|3a|"

  • Value: "|2f 03 08 0c|"

Within: 11

PCRE:

Special Options:

  • fast_pattern

source