#alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY exe download without User Agent"; flow:established,to_server; content:"GET"; http_method; content:".exe"; http_uri; nocase; content:!"User-Agent|3a|"; http_header; content:!"download.windowsupdate.com"; http_header; content:!"mms|3a|//"; nocase; pcre:"/\.exe$/Ui"; reference:url,doc.emergingthreats.net/2003179; classtype:policy-violation; sid:2003179; rev:10;)

Added 2011-10-12 19:12:59 UTC


#alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY exe download without User Agent"; flow:established,to_server; content:"GET"; http_method; content:".exe"; http_uri; nocase; content:!"User-Agent|3a|"; http_header; content:!"download.windowsupdate.com"; http_header; content:!"mms|3a|//"; nocase; pcre:"/\.exe$/Ui"; classtype:policy-violation; reference:url,doc.emergingthreats.net/2003179; sid:2003179; rev:10;)

Added 2011-09-14 22:25:56 UTC


#alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY exe download without User Agent"; flow:established,to_server; content:"GET"; http_method; content:".exe"; http_uri; nocase; content:!"User-Agent|3a|"; http_header; content:!"download.windowsupdate.com"; http_header; content:!"mms|3a|//"; nocase; pcre:"/\.exe$/Ui"; classtype:policy-violation; reference:url,doc.emergingthreats.net/2003179; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/POLICY/POLICY_EXE_NoUserAgent; sid:2003179; rev:10;)

Added 2011-02-04 17:22:17 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY exe download without User Agent"; flow:established,to_server; content:"GET "; depth:4; uricontent:".exe"; nocase; content:!"User-Agent\:"; content:!"download.windowsupdate.com"; content:!"mms\://"; nocase; pcre:"/\.exe[^0-9A-Z_]+/Ui"; classtype:policy-violation; reference:url,doc.emergingthreats.net/2003179; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/POLICY/POLICY_EXE_NoUserAgent; sid:2003179; rev:7;)

Added 2009-11-20 15:45:42 UTC

It appears that Lavasoft's AdAware? program trigger this during installation and/or autoupdate.

GET /public/aawamber//files/_FREE_/_FILES_/_32_/AAWService.exe.file.lzma HTTP/1.1.

Host: lavasoft.hs.llnwd.net.

Connection: Keep-Alive.

Cache-Control: no-cache.

-- KevinBranch - 03 May 2010


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY exe download without User Agent"; flow:established,to_server; content:"GET "; depth:4; uricontent:".exe"; nocase; content:!"User-Agent\:"; content:!"download.windowsupdate.com"; content:!"mms\://"; nocase; pcre:"/\.exe[^0-9A-Z_]+/Ui"; classtype:policy-violation; reference:url,doc.emergingthreats.net/2003179; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/POLICY/POLICY_EXE_NoUserAgent; sid:2003179; rev:7;)

Added 2009-11-20 15:45:42 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY exe download without User Agent"; flow:established,to_server; content:"GET "; depth:4; uricontent:".exe"; nocase; content:!"User-Agent\:"; content:!"download.windowsupdate.com"; content:!"mms\://"; nocase; classtype:policy-violation; reference:url,doc.emergingthreats.net/2003179; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/POLICY/POLICY_EXE_NoUserAgent; sid:2003179; rev:6;)

Added 2009-02-11 19:00:24 UTC

False positive due to Dr Watson error reporting, suggest addition of content:!"dw20.exe"

-- TimBrigham - 18 Nov 2009

What domain is it reporting to for dr watson?

-- MattJonkman - 18 Nov 2009


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY exe download without User Agent"; flow:established,to_server; content:"GET "; depth:4; uricontent:".exe"; nocase; content:!"User-Agent\:"; content:!"download.windowsupdate.com"; content:!"mms\://"; nocase; classtype:policy-violation; reference:url,doc.emergingthreats.net/2003179; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/POLICY/POLICY_EXE_NoUserAgent; sid:2003179; rev:6;)

Added 2009-02-11 19:00:24 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY exe download without User Agent"; flow:established,to_server; content:"GET "; depth:4; uricontent:".exe"; nocase; content:!"User-Agent\:"; content:!"download.windowsupdate.com"; content:!"mms\://"; nocase; classtype:policy-violation; sid:2003179; rev:5;)

Added 2009-02-03 23:45:24 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY exe download without User Agent"; flow:established,to_server; content:"GET "; depth:4; uricontent:".exe"; nocase; content:!"User-Agent\:"; content:!"download.windowsupdate.com"; content:!"mms\://"; nocase; classtype:policy-violation; sid:2003179; rev:5;)

Added 2009-02-03 23:45:24 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY exe download without User Agent"; flow:established,to_server; uricontent:".exe"; nocase; content:".exe"; depth:150; nocase; content:"GET "; nocase; depth:4; offset:0; content:!"User-Agent\:"; content:!"download.windowsupdate.com"; content:!"mms\://"; nocase; classtype:policy-violation; sid:2003179; rev:4;)

Added 2008-01-31 18:48:09 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY exe download without User Agent"; flow:established,to_server; uricontent:".exe"; nocase; content:".exe"; depth:150; nocase; content:"GET "; nocase; depth:4; offset:0; content:!"User-Agent\:"; content:!"download.windowsupdate.com"; content:!"mms\://"; nocase; classtype:policy-violation; sid:2003179; rev:4;)

Added 2008-01-31 18:48:09 UTC


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"BLEEDING-EDGE POLICY exe download without User Agent"; flow:established,to_server; uricontent:".exe"; nocase; content:".exe"; depth:150; nocase; content:"GET "; nocase; depth:4; offset:0; content:!"User-Agent\:"; content:!"download.windowsupdate.com"; content:!"mms\://"; nocase; classtype:policy-violation; sid:2003179; rev:3;)

Added 2007-04-19 09:00:25 UTC

Added the get match to make sure this is in the first packet of the stream.

-- MattJonkman - 19 Apr 2007


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"BLEEDING-EDGE POLICY exe download without User Agent"; flow:established,to_server; uricontent:".exe"; nocase; content:".exe"; depth:150; nocase; content:!"User-Agent\:"; content:!"download.windowsupdate.com"; content:!"mms\://"; nocase; classtype:policy-violation; sid:2003179; rev:2;)



Topic revision: r5 - 2010-05-03 - KevinBranch
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats