ET EXPLOIT_KIT Evil Redirector Leading to EK Jul 02
Sourceet/open
CreatedJuly 2, 2015
UpdatedMarch 17, 2022
Classificationexploit-kit
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT_KIT Evil Redirector Leading to EK Jul 02"; flow:established,from_server; file_data; content:"|2e 73 70 6c 69 74 28 22 22 29 2e 72 65 76 65 72 73 65 28 29 2e 6a 6f 69 6e 28 22 22 29 2e 73 70 6c 69 74 28 22 22 29 2e 72 65 76 65 72 73 65 28 29 2e 6a 6f 69 6e 28 22 22 29 5d 2e 62 6f 72 64 65 72 20 3d 20 22 6e 6f 6e 65 22 3b|"; fast_pattern; content:" +="; pcre:"/^\s+\d{1,2}\x3b\s+else\s+(?P<var>[a-z]+)\s+\-=\s+\d{1,2}\x3b\s+return\s+[a-z]+\.charAt\x28(?P=var)\/\d{1,2}\x29\x7d/R"; classtype:exploit-kit; sid:2021374; rev:3; metadata:affected_product Web_Browsers, attack_target Client_Endpoint, created_at 2015_07_02, deployment Perimeter, confidence High, signature_severity Major, tag Redirector, updated_at 2022_03_17;)
Metadata
affected productWeb_Browsers
attack targetClient_Endpoint
created at2015_07_02
deploymentPerimeter
confidenceHigh
signature severityMajor
tagRedirector
updated at2022_03_17
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!