Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # PROTOCOL-DNS TMG Firewall Client long host entry exploit attempt
- suppress gen_id 3, sig_id 19187
- # ET CHAT IRC USER command
- suppress gen_id 1, sig_id 2002023
- # ET CHAT IRC NICK command
- suppress gen_id 1, sig_id 2002024
- # ET CHAT IRC JOIN command
- suppress gen_id 1, sig_id 2002025
- # ET CHAT IRC PRIVMSG command
- suppress gen_id 1, sig_id 2002026
- # ET CHAT IRC PING command
- suppress gen_id 1, sig_id 2002027
- # ET CHAT IRC PONG response
- suppress gen_id 1, sig_id 2002028
- # http_inspect client
- suppress gen_id 119, sig_id 1
- suppress gen_id 119, sig_id 2
- suppress gen_id 119, sig_id 3
- suppress gen_id 119, sig_id 4
- suppress gen_id 119, sig_id 5
- suppress gen_id 119, sig_id 6
- suppress gen_id 119, sig_id 7
- suppress gen_id 119, sig_id 8
- suppress gen_id 119, sig_id 9
- suppress gen_id 119, sig_id 10
- suppress gen_id 119, sig_id 11
- suppress gen_id 119, sig_id 12
- suppress gen_id 119, sig_id 13
- suppress gen_id 119, sig_id 14
- suppress gen_id 119, sig_id 15
- suppress gen_id 119, sig_id 16
- suppress gen_id 119, sig_id 17
- suppress gen_id 119, sig_id 18
- suppress gen_id 119, sig_id 19
- suppress gen_id 119, sig_id 20
- suppress gen_id 119, sig_id 21
- suppress gen_id 119, sig_id 22
- suppress gen_id 119, sig_id 23
- suppress gen_id 119, sig_id 24
- suppress gen_id 119, sig_id 25
- suppress gen_id 119, sig_id 26
- suppress gen_id 119, sig_id 27
- suppress gen_id 119, sig_id 28
- suppress gen_id 119, sig_id 29
- suppress gen_id 119, sig_id 30
- suppress gen_id 119, sig_id 31
- suppress gen_id 119, sig_id 32
- suppress gen_id 119, sig_id 33
- suppress gen_id 119, sig_id 34
- # http_inspect server
- suppress gen_id 120, sig_id 1
- suppress gen_id 120, sig_id 2
- suppress gen_id 120, sig_id 3
- suppress gen_id 120, sig_id 4
- suppress gen_id 120, sig_id 5
- suppress gen_id 120, sig_id 6
- suppress gen_id 120, sig_id 7
- suppress gen_id 120, sig_id 8
- suppress gen_id 120, sig_id 9
- suppress gen_id 120, sig_id 10
- suppress gen_id 120, sig_id 11
- #ET POLICY GNU/Linux APT User-Agent Outbound likely related to package management
- suppress gen_id 1, sig_id 2013504
- #ET POLICY libwww-perl User-Agent
- suppress gen_id 1, sig_id 2013030
- # ET POLICY Python-urllib/ Suspicious User Agent
- suppress gen_id 1, sig_id 2013031
- # (spp_ssl) Invalid Client HELLO after Server HELLO Detected
- suppress gen_id 137, sig_id 1
- # INDICATOR-COMPROMISE Suspicious .pw dns query
- suppress gen_id 1, sig_id 28039
- # ET POLICY curl User-Agent Outbound
- suppress gen_id 1, sig_id 2013028
- # (spp_ssh) Challenge-Response Overflow exploit
- suppress gen_id 128, sig_id 1
- # ET POLICY Protocol 41 IPv6 encapsulation potential 6in4 IPv6 tunnel active
- suppress gen_id 1, sig_id 2012141
- # ET POLICY PE EXE or DLL Windows file download HTTP
- suppress gen_id 1, sig_id 2018959
- # ET SCAN Potential SSH Scan OUTBOUND
- suppress gen_id 1, sig_id 2003068
- # ET POLICY Suspicious inbound to MSSQL port 1433
- suppress gen_id 1, sig_id 2010935
- # ET SCAN Sipvicious Scan
- suppress gen_id 1, sig_id 2008578
- # ET SCAN Sipvicious User-Agent Detected (friendly-scanner)
- suppress gen_id 1, sig_id 2011716
- # ET POLICY Suspicious inbound to mySQL port 3306
- suppress gen_id 1, sig_id 2010937
- # ET POLICY Android Dalvik Executable File Download
- suppress gen_id 1, sig_id 2016856
- # ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging)
- suppress gen_id 1, sig_id 2015744
- # ET INFO Packed Executable Download
- suppress gen_id 1, sig_id 2014819
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement