ET HUNTING HTTP 300-Series Redirect to file URI attempt

7.0.35.0SID: 2020976Rev: 6Enabled5 views
History
Sourceet/open
Fileemerging-hunting.rules
CreatedApril 23, 2015
UpdatedJuly 31, 2026
Classificationbad-unknown
alert http any any -> $HOME_NET any (msg:"ET HUNTING HTTP 300-Series Redirect to file URI attempt"; flow:established,to_client; http.stat_code; content:"3"; startswith; http.location; content:"file|3a 2f 2f|"; nocase; startswith; fast_pattern; reference:url,blog.cylance.com/redirect-to-smb; reference:url,blog.trendmicro.com/trendlabs-security-intelligence/resurrection-of-the-living-dead-the-redirect-to-smb-vulnerability/; classtype:bad-unknown; sid:2020976; rev:6; metadata:affected_product Any, attack_target Client_and_Server, tls_state plaintext, created_at 2015_04_23, deployment Perimeter, deployment Internal, former_category EXPLOIT, performance_impact Low, confidence Medium, signature_severity Major, tag Malicious_Redirect, updated_at 2026_07_31, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1189, mitre_technique_name Drive_by_Compromise; target:dest_ip;)

Metadata

affected productAny
attack targetClient_and_Server
tls stateplaintext
created at2015_04_23
deploymentInternal
former categoryEXPLOIT
performance impactLow
confidenceMedium
signature severityMajor
tagMalicious_Redirect
updated at2026_07_31
mitre tactic idTA0001
mitre tactic nameInitial_Access
mitre technique idT1189
mitre technique nameDrive_by_Compromise

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!