Back to Rule

Rule History

SID: 2019180 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 4Sep 16, 2014, 12:00 PM

ET EXPLOIT_KIT Malvertising Leading to EK Aug 19 2014 M4

alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT Malvertising Leading to EK Aug 19 2014 M4"; flow:established,to_client; http.server; bsize:5; content:"nginx"; http.header; content:"X-Powered-By|3a 20|PHP"; content:"text/javascript"; file.data; content:"if|28|[removed].indexOf|28|"; within:27; fast_pattern; pcre:"/^\s*?[\x22\x27](?P<var>[^\x22\x27]+)[\x22\x27]\s*?\x29\s*?==\s*?-1\x29\x7b[^\r\n]*?document\.cookie\s*?=\s*?[\x22\x27](?P=var)\s*?\x3d\s*?[^\r\n]+?[\r\n]*?$/Rsi"; content:"iframe"; content:"top"; pcre:"/^\s*?[\x3a\x3d]\s*?[\x22\x27]?\-/Rsi"; content:"left"; pcre:"/^\s*?[\x3a\x3d]\s*?[\x22\x27]?\-/Rsi"; classtype:exploit-kit; sid:2019180; rev:4; metadata:created_at 2014_09_16, confidence High, signature_severity Major, updated_at 2024_02_23;)

Sep 16, 2014, 12:00 PM

Feb 23, 2024, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-exploit_kit.rules