ET EXPLOIT_KIT GrandSoft PDF Payload Download
Sourceet/open
CreatedApril 17, 2013
UpdatedNovember 5, 2020
Classificationexploit-kit
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET EXPLOIT_KIT GrandSoft PDF Payload Download"; flow:established,to_server; flowbits:set,et.exploitkitlanding; http.method; content:"GET"; http.user_agent; content:"http|3a|//"; fast_pattern; startswith; http.start; pcre:"/^GET (?P<uri>(\/[A-Za-z0-9]+)?\/\d+\/\d+)\sHTTP\/1\.1\r\nUser-Agent\x3a\x20http\x3a\/\/(?P<host>[^\r\n]+)(?P=uri)\r\nHost\x3a\x20(?P=host)\r\n(\r\n)?$/"; classtype:exploit-kit; sid:2016764; rev:19; metadata:created_at 2013_04_17, signature_severity Major, updated_at 2020_11_05;)
Metadata
created at2013_04_17
signature severityMajor
updated at2020_11_05
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!