#alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO Dotted Quad Host PS1 Request"; flow:established,from_client; flowbits:isset,http.dottedquadhost; flowbits:set,http.dottedquadhost.ps1; flowbits:unset,http.dottedquadhost; http_request_line; content:".ps1 HTTP/1."; nocase; fast_pattern; classtype:bad-unknown; sid:2027259; rev:3; metadata:attack_target Client_Endpoint, created_at 2019_04_23, former_category INFO, performance_impact Significant, signature_severity Minor, updated_at 2021_03_18;)
Added 2021-03-18 18:10:45 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO Dotted Quad Host PS1 Request"; flow:established,from_client; flowbits:isset,http.dottedquadhost; flowbits:set,http.dottedquadhost.ps1; flowbits:unset,http.dottedquadhost; http_request_line; content:".ps1 HTTP/1."; nocase; fast_pattern; classtype:bad-unknown; sid:2027259; rev:3; metadata:attack_target Client_Endpoint, created_at 2019_04_23, deployment Perimeter, former_category INFO, performance_impact Significant, signature_severity Minor, updated_at 2020_04_08;)
Added 2020-08-05 19:16:11 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO Dotted Quad Host PS1 Request"; flow:established,from_client; flowbits:isset,http.dottedquadhost; flowbits:set,http.dottedquadhost.ps1; flowbits:unset,http.dottedquadhost; http_request_line; content:".ps1 HTTP/1."; nocase; fast_pattern; metadata: former_category INFO; classtype:bad-unknown; sid:2027259; rev:3; metadata:attack_target Client_Endpoint, deployment Perimeter, signature_severity Minor, created_at 2019_04_23, performance_impact Significant, updated_at 2020_04_08;)
Added 2020-04-08 18:33:54 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO Dotted Quad Host PS1 Request"; flow:established,from_client; flowbits:isset,http.dottedquadhost; flowbits:set,http.dottedquadhost.ps1; flowbits:unset,http.dottedquadhost; content:".ps1"; http_uri; nocase; fast_pattern; isdataat:!1,relative; metadata: former_category INFO; classtype:bad-unknown; sid:2027259; rev:2; metadata:attack_target Client_Endpoint, deployment Perimeter, signature_severity Minor, created_at 2019_04_23, performance_impact Significant, updated_at 2019_09_28;)
Added 2019-10-01 08:29:40 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO Dotted Quad Host PS1 Request"; flow:established,from_client; flowbits:isset,http.dottedquadhost; flowbits:set,http.dottedquadhost.ps1; flowbits:unset,http.dottedquadhost; content:".ps1"; http_uri; nocase; fast_pattern; isdataat:!1,relative; metadata: former_category INFO; classtype:bad-unknown; sid:2027259; rev:2; metadata:attack_target Client_Endpoint, deployment Perimeter, signature_severity Minor, created_at 2019_04_23, performance_impact Significant, updated_at 2019_09_28;)
Added 2019-10-01 04:24:03 UTC
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET INFO Dotted Quad Host PS1 Request"; flow:established,from_client; flowbits:isset,http.dottedquadhost; flowbits:set,http.dottedquadhost.ps1; flowbits:unset,http.dottedquadhost; content:".ps1"; http_uri; nocase; fast_pattern; isdataat:!1,relative; metadata: former_category INFO; classtype:bad-unknown; sid:2027259; rev:2; metadata:attack_target Client_Endpoint, deployment Perimeter, signature_severity Minor, created_at 2019_04_23, performance_impact Significant, updated_at 2019_04_23;)
Added 2019-04-23 19:38:17 UTC