#alert http $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET DELETED Suspicious User Agent
WebUpdate?"; flow:established,to_server; content:"|0d 0a|User-Agent|3a|
WebUpdate?|0d 0a|"; reference:url,doc.emergingthreats.net/2010600; classtype:trojan-activity; sid:2010600; rev:4; metadata:created_at 2010_07_30, former_category HUNTING, updated_at 2021_06_23;)
Added 2022-05-19 19:05:57 UTC
#alert http $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET DELETED Suspicious User Agent
WebUpdate?"; flow:established,to_server; content:"|0d 0a|User-Agent|3a|
WebUpdate?|0d 0a|"; reference:url,doc.emergingthreats.net/2010600; classtype:trojan-activity; sid:2010600; rev:3; metadata:created_at 2010_07_30, former_category HUNTING, updated_at 2021_06_23;)
Added 2021-06-23 19:31:43 UTC
#alert http $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET DELETED Suspicious User Agent
WebUpdate?"; flow:established,to_server; content:"|0d 0a|User-Agent|3a|
WebUpdate?|0d 0a|"; reference:url,doc.emergingthreats.net/2010600; classtype:trojan-activity; sid:2010600; rev:3; metadata:created_at 2010_07_30, updated_at 2020_10_19;)
Added 2020-10-19 19:37:45 UTC
#alert http $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET DELETED Suspicious User Agent
WebUpdate?"; flow:established,to_server; content:"|0d 0a|User-Agent|3a|
WebUpdate?|0d 0a|"; reference:url,doc.emergingthreats.net/2010600; classtype:trojan-activity; sid:2010600; rev:3; metadata:created_at 2010_07_30, updated_at 2019_10_11;)
Added 2019-10-11 19:56:31 UTC
#alert http $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET DELETED Suspicious User Agent
WebUpdate?"; flow:established,to_server; content:"|0d 0a|User-Agent|3a|
WebUpdate?|0d 0a|"; reference:url,doc.emergingthreats.net/2010600; classtype:trojan-activity; sid:2010600; rev:3; metadata:created_at 2010_07_30, updated_at 2010_07_30;)
Added 2018-09-13 19:41:30 UTC
Added 2018-09-13 17:54:41 UTC
#alert http $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET DELETED Suspicious User Agent
WebUpdate?"; flow:established,to_server; content:"|0d 0a|User-Agent|3a|
WebUpdate?|0d 0a|"; reference:url,doc.emergingthreats.net/2010600; classtype:trojan-activity; sid:2010600; rev:3; metadata:created_at 2010_07_30, updated_at 2010_07_30;)
Added 2017-08-07 21:03:44 UTC
#alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET DELETED Suspicious User Agent
WebUpdate?"; flow:established,to_server; content:"User-Agent|3a|
WebUpdate?|0d 0a|"; http_header; reference:url,doc.emergingthreats.net/2010600; classtype:trojan-activity; sid:2010600; rev:4;)
Added 2011-12-15 18:09:43 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET USER_AGENTS Suspicious User Agent
WebUpdate?"; flow:established,to_server; content:"User-Agent|3a|
WebUpdate?|0d 0a|"; http_header; reference:url,doc.emergingthreats.net/2010600; classtype:trojan-activity; sid:2010600; rev:4;)
Added 2011-10-12 19:30:09 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET USER_AGENTS Suspicious User Agent
WebUpdate?"; flow:established,to_server; content:"User-Agent|3a|
WebUpdate?|0d 0a|"; http_header; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2010600; sid:2010600; rev:4;)
Added 2011-09-14 22:43:20 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET USER_AGENTS Suspicious User Agent
WebUpdate?"; flow:established,to_server; content:"User-Agent|3a|
WebUpdate?|0d 0a|"; http_header; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2010600; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/USER_AGENTS/USER_AGENTS_Suspicious; sid:2010600; rev:4;)
Added 2011-02-04 17:30:12 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET USER_AGENTS Suspicious User Agent
WebUpdate?"; flow:established,to_server; content:"|0d 0a|User-Agent\:
WebUpdate?|0d 0a|"; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2010600; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/USER_AGENTS/USER_AGENTS_Suspicious; sid:2010600; rev:1;)
Added 2009-12-29 10:00:52 UTC
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET USER_AGENTS Suspicious User Agent
WebUpdate?"; flow:established,to_server; content:"|0d 0a|User-Agent\:
WebUpdate?|0d 0a|"; classtype:trojan-activity; reference:url,doc.emergingthreats.net/2010600; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/USER_AGENTS/USER_AGENTS_Suspicious; sid:2010600; rev:1;)
Added 2009-12-29 09:58:49 UTC