alert dns $HOME_NET any -> any any (msg:"ET INFO Observed DNS Query for OpenNIC? Alternative DNS TLD (.gopher)"; dns_query; content:".gopher"; nocase; isdataat:!1,relative; reference:url,wiki.opennic.org/opennic/dot; classtype:bad-unknown; sid:2029969; rev:2; metadata:attack_target Client_Endpoint, created_at 2020_04_20, deployment Perimeter, former_category HUNTING, signature_severity Informational, updated_at 2020_11_16;)

Added 2020-11-16 19:08:26 UTC


alert dns $HOME_NET any -> any any (msg:"ET INFO Observed DNS Query for OpenNIC? Alternative DNS TLD (.gopher)"; dns_query; content:".gopher"; nocase; isdataat:!1,relative; reference:url,wiki.opennic.org/opennic/dot; classtype:bad-unknown; sid:2029969; rev:2; metadata:attack_target Client_Endpoint, created_at 2020_04_20, deployment Perimeter, former_category HUNTING, signature_severity Informational, updated_at 2020_04_20;)

Added 2020-08-05 19:18:02 UTC


alert dns $HOME_NET any -> any any (msg:"ET INFO Observed DNS Query for OpenNIC? Alternative DNS TLD (.gopher)"; dns_query; content:".gopher"; nocase; isdataat:!1,relative; metadata: former_category HUNTING; reference:url,wiki.opennic.org/opennic/dot; classtype:bad-unknown; sid:2029969; rev:2; metadata:attack_target Client_Endpoint, deployment Perimeter, signature_severity Informational, created_at 2020_04_20, updated_at 2020_04_20;)

Added 2020-04-20 19:37:01 UTC


Topic revision: r1 - 2020-11-17 - TWikiGuest
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats