""ET SCADA [nsacyber/ELITEWOLF] Siemens S7 Redpoint NSE Request CPU Function Read SZL attempt""

SID: 2048689

Revision: 1

Class Type: attempted-recon

Metadata: created_at 2023_10_19, updated_at 2023_10_19, reviewed_at 2023_10_19

Reference:

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: $HOME_NET

Destination Port: 102

Flow: established,to_server

Contents:

  • Value: "|32 07 00 00 00 00 00 08 00 08|" Depth: 10

  • Value: "|00 01 12 04 11 44 01 00|"

Within: 16

PCRE:

Special Options:

  • fast_pattern

source