""GPL NETBIOS SMB startup folder unicode access""

SID: 2102177

Revision: 5

Class Type: attempted-recon

Metadata: created_at 2010_09_23, updated_at 2012_01_16

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: 139

Flow: to_server,established

Contents:

  • Value: "|00|" Depth: 1

  • Value: "|FF|SMB2" Depth: 5 Offset: 4

  • Value: "|5C 00|S|00|t|00|a|00|r|00|t|00| |00|M|00|e|00|n|00|u|00 5C 00|P|00|r|00|o|00|g|00|r|00|a|00|m|00|s|00 5C 00|S|00|t|00|a|00|r|00|t|00|u|00|p"

Within:

PCRE:

Special Options:

  • nocase

source