alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET POLICY Binary Download Smaller than 1 MB Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:7;)
Added 2008-06-06 20:49:01 UTC
alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET POLICY Binary Download Smaller than 1 MB Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:7;)
Added 2008-06-06 20:49:01 UTC
alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:6;)
Added 2008-01-31 18:48:10 UTC
alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:6;)
Added 2008-01-31 18:48:10 UTC
alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:5;)
Added 2007-11-09 01:01:50 UTC
alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:5;)
Added 2007-11-09 01:01:50 UTC
alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:3;)
Added 2007-11-08 23:46:05 UTC
alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; isdataat: 76,relative; content:"This program "; distance: 0; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:3;)
Added 2007-11-08 23:46:05 UTC
alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:2;)
Added 2007-11-08 04:28:13 UTC
alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; content:"MZ"; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:2;)
Added 2007-11-08 04:28:13 UTC
alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE POLICY Binary Download Smaller than 1 MB -- Likely Hostile"; flow:established,from_server; flowbits:isset,BE.http.binary; content:"HTTP/1"; depth:6; pcre:"/\x0d\x0aContent-Length\: \d{0,6}\x0d\x0a/"; classtype:policy-violation; sid:2007671; rev:1;)
Added 2007-11-08 01:16:52 UTC