Last 50 Rule Changes

Results from Main web retrieved at 07:03 (GMT)

#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing July 07 2016 M6`; flow:established,from server; content:`Server 3a ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing July 07 2016 M8`; flow:established,from server; content:`Server 3a ...
#alert http $HOME NET any $EXTERNAL NET any (msg:`ET DELETED Possible Neutrino EK Landing Landing URI Struct (fb set)`; flow:to server,established; content:!`Cookie ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing July 07 2016 M7`; flow:established,from server; content:`Server 3a ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing July 07 2016 M4`; flow:established,from server; content:`Server 3a ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing June 11 2016 M4 (with URI Primer)`; flow:established,from server ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing July 07 2016 M3`; flow:established,from server; content:`Server 3a ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing June 11 2016 M2`; flow:established,from server; content:`nginx`; ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino EK Landing Jul 04 2016 M1`; flow:established,from server; content:`Server 3a 20 nginx ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino EK Landing Jul 04 2016 M3`; flow:established,from server; content:`Server 3a 20 nginx ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing July 07 2016 M2`; flow:established,from server; content:`Server 3a ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino EK Landing Jul 04 2016 M2`; flow:established,from server; content:`Server 3a 20 nginx ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing July 07 2016 M1`; flow:established,from server; content:`Server 3a ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing June 11 2016 M3`; flow:established,from server; content:`Server 3a ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing June 11 2016`; flow:established,from server; content:`nginx`; http ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing July 07 2016 M5`; flow:established,from server; content:`Server 3a ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing May 31 2016`; flow:established,from server; content:`nginx`; http ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing June 11 2016 M2`; flow:established,from server; content:`nginx`; ...
#alert http $EXTERNAL NET 80 $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing Oct 19 2015`; flow:established,from server; file data; content:!` ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Angler EK encrypted payload Oct 19 (5)`; flow:established,to client; file data; content:` 91 29 83 ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Angler EK encrypted payload Oct 19 (6)`; flow:established,to client; file data; content:` 57 05 11 ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Possible Angler EK Redirector Sept 25 2015`; flow:to client,established; file data; content:``; pcre ...
#alert http $HOME NET any $EXTERNAL NET ! 80,8080,3128,3129 (msg:`ET DELETED Job314/Neutrino Reboot EK Payload Aug 19 2015`; flow:established,to server; content ...
#alert http $EXTERNAL NET 80 $HOME NET any (msg:`ET DELETED Job314/Neutrino EK Flash Exploit M2 Aug 02 2015`; flow:from server,established; flowbits:isset,ET.Neutrino ...
#alert http $HOME NET any $EXTERNAL NET any (msg:`ET DELETED Possible Job314/Neutrino Reboot EK Flash Exploit Jan 07 2015 M1`; flow:established,to server; content ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing Jan 07 2015`; flow:established,from server; content:`nginx`; http ...
#alert http $EXTERNAL NET 80 $HOME NET any (msg:`ET DELETED Job314/Neutrino EK Flash Exploit M3 Aug 02 2015`; flow:from server,established; flowbits:isset,ET.Neutrino ...
#alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:`ET DELETED Angler EK encrypted payload Oct 19 (4)`; flow:established,to client; file data; content:` 05 ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Job314/Neutrino Reboot EK Landing Aug 02 2015`; flow:established,from server; file data; content:`value ...
#alert http $HOME NET any $EXTERNAL NET any (msg:`ET DELETED Possible Job314/Neutrino Reboot EK Flash Exploit Jan 07 2015 M2`; flow:established,to server; content ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Angler EK encrypted payload Oct 19 (1)`; flow:established,to client; file data; content:` d8 57 45 ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Angler EK encrypted payload Oct 19 (2)`; flow:established,to client; file data; content:` d5 88 7d ...
#alert http $HOME NET any $EXTERNAL NET any (msg:`ET DELETED Job314/Neutrino EK Flash Exploit M1 Aug 02 2015 (IE)`; flow:to server,established; content:`x flash ...
#alert http $HOME NET any $EXTERNAL NET any (msg:`ET DELETED Angler EK Landing URI Struct Jun 15 M2`; flow:to server,established; urilen: 26; content:`/search? ...
#alert http $HOME NET any $EXTERNAL NET any (msg:`ET DELETED Possible Angler EK Landing URI Struct June 13 M3`; flow:established,to server; urilen:27114; content ...
#alert http $HOME NET any $EXTERNAL NET any (msg:`ET DELETED Possible Angler EK Landing URI Struct June 13 M2`; flow:established,to server; urilen:27114; content ...
#alert http $HOME NET any $EXTERNAL NET any (msg:`ET DELETED Angler EK Landing URI Struct Jun 11 M3`; flow:to server,established; urilen: 22; content:`/?`; offset ...
#alert http $HOME NET any $EXTERNAL NET any (msg:`ET DELETED Angler EK Landing URI Struct Jun 15`; flow:to server,established; urilen: 26; content:`/search?`; http ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Angler EK XTEA encrypted binary (29)`; flow:established,from server; file data; content:` EB BD 89 ...
#alert http $HOME NET any $EXTERNAL NET any (msg:`ET DELETED Angler EK Landing URI Struct Jun 15 M3`; flow:to server,established; urilen: 26; content:`/search? ...
#alert http $HOME NET any $EXTERNAL NET any (msg:`ET DELETED Angler EK Landing URI Struct Jun 11 M2`; flow:to server,established; urilen: 22; content:`/?`; offset ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Angler EK XTEA encrypted binary (16) M2`; flow:established,to client; file data; content:` 51 cb 7b ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Angler EK XTEA encrypted binary (28)`; flow:established,from server; file data; content:` EB BD 89 ...
#alert http $HOME NET any $EXTERNAL NET any (msg:`ET DELETED Angler EK Payload URI Struct May 28 2015 M1`; flow:to server,established; urilen: 51; content:`.`; ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Angler EK XTEA encrypted binary (26)`; flow:established,from server; file data; content:` 51 CB 7B ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Angler EK XTEA encrypted binary (27)`; flow:established,from server; file data; content:` 51 CB 7B ...
#alert http $HOME NET any $EXTERNAL NET any (msg:`ET DELETED Angler EK Landing URI Struct Jun 11`; flow:to server,established; urilen: 22; content:`/?`; offset ...
#alert http $HOME NET any $EXTERNAL NET any (msg:`ET DELETED Possible Angler EK Landing URI Struct June 13 M1`; flow:established,to server; urilen:27114; content ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Angler EK XTEA encrypted binary (11) M2`; flow:established,to client; file data; content:` 08 fe 4a ...
#alert http $EXTERNAL NET any $HOME NET any (msg:`ET DELETED Angler EK XTEA encrypted binary (15)`; flow:established,to client; file data; content:` c5 91 b0 40 ...
Number of topics: 50
Topic revision: r5 - 2014-01-10 - MattJonkman
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats