alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET SCAN ProxyReconBot? POST method to Mail"; flow:established,to_server; content:"POST"; http_method; content:"|3A|25 HTTP/"; fast_pattern; depth:200; reference:url,doc.emergingthreats.net/2003870; classtype:misc-attack; sid:2003870; rev:8;)

Added 2012-07-02 10:01:13 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET SCAN ProxyReconBot? POST method to Mail"; flow:established,to_server; content:"POST"; http_method; content:"|3A|25 HTTP/"; fast_pattern; depth:200; reference:url,doc.emergingthreats.net/2003870; classtype:misc-attack; sid:2003870; rev:8;)

Added 2012-06-29 18:13:22 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET SCAN ProxyReconBot? POST method to Mail"; flow:established,to_server; content:"POST"; http_method; content:"|3A|25 HTTP/"; depth:200; reference:url,doc.emergingthreats.net/2003870; classtype:misc-attack; sid:2003870; rev:7;)

Added 2011-10-12 19:14:21 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET SCAN ProxyReconBot? POST method to Mail"; flow:established,to_server; content:"POST"; http_method; content:"|3A|25 HTTP/"; depth:200; classtype: misc-attack; reference:url,doc.emergingthreats.net/2003870; sid:2003870; rev:7;)

Added 2011-09-14 22:27:28 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET SCAN ProxyReconBot? POST method to Mail"; flow:established,to_server; content:"POST"; http_method; content:"|3A|25 HTTP/"; depth:200; classtype: misc-attack; reference:url,doc.emergingthreats.net/2003870; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/SCAN/SCAN_ReconBot; sid:2003870; rev:7;)

Added 2011-02-04 17:22:48 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET SCAN ProxyReconBot? POST method to Mail"; content:"POST "; depth:5; content:"|3A|25 HTTP/"; within:200; flow:established,to_server; classtype: misc-attack; reference:url,doc.emergingthreats.net/2003870; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/SCAN/SCAN_ReconBot; sid:2003870; rev:5;)

Added 2010-03-08 13:53:45 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET SCAN ProxyReconBot? POST method to Mail"; content:"POST "; depth:5; content:"|3A|25 HTTP/"; within:200; flow:established,to_server; classtype: misc-attack; reference:url,doc.emergingthreats.net/2003870; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/SCAN/SCAN_ReconBot; sid:2003870; rev:5;)

Added 2010-03-08 13:53:45 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET SCAN ProxyReconBot? POST method to Mail"; content:"POST"; depth: 7; pcre:"/\x3a25 HTTP/"; flow:established,to_server; classtype: misc-attack; reference:url,doc.emergingthreats.net/2003870; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/SCAN/SCAN_ReconBot; sid:2003870; rev:3;)

Added 2009-02-12 18:21:19 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET SCAN ProxyReconBot? POST method to Mail"; content:"POST"; depth: 7; pcre:"/\x3a25 HTTP/"; flow:established,to_server; classtype: misc-attack; reference:url,doc.emergingthreats.net/2003870; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/SCAN/SCAN_ReconBot; sid:2003870; rev:3;)

Added 2009-02-12 18:21:19 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET SCAN ProxyReconBot? POST method to Mail"; content:"POST"; depth: 7; pcre:"/\x3a25 HTTP/"; flow:established,to_server; classtype: misc-attack; sid:2003870; rev:2;)

Added 2008-01-29 10:56:40 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET SCAN ProxyReconBot? POST method to Mail"; content:"POST"; depth: 7; pcre:"/\x3a25 HTTP/"; flow:established,to_server; classtype: misc-attack; sid:2003870; rev:2;)

Added 2008-01-29 10:56:40 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"BLEEDING-EDGE SCAN ProxyReconBot? POST method to Mail"; content:"POST"; depth: 7; pcre:"/\x3a25 HTTP/"; flow:established,to_server; classtype: misc-attack; sid:2003870; rev:1;)

Added 2007-05-24 20:57:40 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"BLEEDING-EDGE SCAN ProxyReconBot? POST method to Mail"; content:"POST"; depth: 7; pcre:"/\x3a25 HTTP/"; flow:established,to_server; classtype: misc-attack; sid:2003870; rev:1;)

Added 2007-05-24 14:15:20 UTC


Topic revision: r1 - 2012-07-02 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats