""GPL NETBIOS SMB-DS ADMIN$ unicode share access""

SID: 2102475

Revision: 9

Class Type: protocol-command-decode

Metadata: created_at 2010_09_23, updated_at 2011_09_20

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: 445

Flow: established,to_server

Contents:

  • Value: "|00|" Depth: 1

  • Value: "|FF|SMBu"

  • Value: "A|00|D|00|M|00|I|00|N|00 24 00 00 00|"

Within: 5

PCRE:

Special Options:

  • nocase

source