Signature
alert udp $EXTERNAL_NET any -> $HOME_NET 161 (msg:"OS-WINDOWS Microsoft Windows getbulk request attempt"; flow:to_server; content:"|30|"; depth:1; content:"|02 01 01 04|"; within:4; distance:1; byte_jump:1,0,relative; content:"|A5|"; content:"|02|"; within:1; distance:1; byte_jump:1,0,relative; content:"|02|"; within:1; content:!"|00|"; within:1; distance:1; content:"|02|"; within:1; distance:2; byte_jump:1,0,relative; byte_test:1,>,20,-1,relative; metadata:policy max-detect-ips drop, policy security-ips drop, service snmp; reference:cve,2006-5583; reference:url,technet.microsoft.com/en-us/security/bulletin/MS06-074; classtype:attempted-admin; sid:12198; rev:17;)