alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET USER_AGENTS Fake Mozilla User-Agent String Observed (M0zilla)"; flow:established,to_server; content:"M0zilla|2f|"; http_user_agent; depth:8; fast_pattern; content:"."; http_user_agent; distance:1; within:1; metadata: former_category USER_AGENTS; reference:md5,c6c1292bf7dd1573b269afb203134b1d; classtype:trojan-activity; sid:2027565; rev:1; metadata:created_at 2019_06_26, updated_at 2019_06_26;)

Added 2019-06-26 19:54:27 UTC


Topic revision: r1 - 2019-06-26 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats