alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY Set flow on rar file get"; flow:established,to_server; content:"GET "; depth:4; uricontent:".rar"; content:".rar HTTP/1."; flowbits:set,ET.rar_seen; flowbits:noalert; classtype:trojan-activity; sid:2008781; rev:2;)
Added 2008-11-18 12:15:22 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY Set flow on rar file get"; flow:established,to_server; content:"GET "; depth:4; uricontent:".rar"; content:".rar HTTP/1."; flowbits:set,ET.rar_seen; flowbits:noalert; classtype:trojan-activity; sid:2008781; rev:2;)
Added 2008-11-18 12:15:22 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY Set flow on rar file get"; flow:established,to_server; content:"GET "; depth:4; uricontent:".rar"; content:".rar HTTP/1."; flowbits:set,ET.rar_seen; flowbits:noalert; sid:2008781; rev:1;)
Added 2008-11-13 18:14:17 UTC