ET DOS MC-SQLR Response Outbound Possible DDoS Participation


Query · suricata

content:"|05|"; depth:1;
content:"ServerName|3b|"; nocase;
content:"InstanceName|3b|"; distance:0;
content:"IsClustered|3b|"; distance:0;
content:"Version|3b|"; distance:0;
threshold:type both,track by_src,count 30,seconds 60;
Raw source ET DOS MC-SQLR Response Outbound Possible DDoS Participation · Suricata
Esc
Published by Emerging Threats Open ↗, licensed under BSD 3-Clause ↗. Line breaks added for readability; the rule is otherwise unchanged.
alert udp $HOME_NET 1434 -> $EXTERNAL_NET any (
    msg:"ET DOS MC-SQLR Response Outbound Possible DDoS Participation";
    content:"|05|"; depth:1;
    content:"ServerName|3b|"; nocase;
    content:"InstanceName|3b|"; distance:0;
    content:"IsClustered|3b|"; distance:0;
    content:"Version|3b|"; distance:0;
    threshold:type both,track by_src,count 30,seconds 60;
    reference:url,kurtaubuchon.blogspot.com.es/2015/01/mc-sqlr-amplification-ms-sql-server.html;
    classtype:attempted-dos;
    sid:2020305; rev:4;
    metadata:created_at 2015_01_23, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;
)

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.