""ET SCAN LeakIX Inbound User-Agent""
SID: 2049255
Revision: 1
Class Type: misc-activity
Metadata: created_at 2023_11_20, deployment Perimeter, deployment SSLDecrypt, performance_impact Low, signature_severity Informational, updated_at 2023_11_20
Reference:
Protocol: tcp
Source Network: $EXTERNAL_NET
Source Port: any
Destination Network: $HOME_NET
Destination Port: $HTTP_PORTS
Flow: established,to_server
Contents:
-
Value: "|28|l9scan|2f|"
-
Value: "|3b 20 2b|https|3a 2f 2f|leakix|2e|net"
Within:
PCRE: "/^User-Agent\x3a\x20[^\r\n]+\x28l9scan\x2f[^\r\n]+\x3b\x20\x2bhttps\x3a\x2f\x2fleakix\x2enet/Hmi"
Special Options:
-
http_header
-
fast_pattern
-
http_header