""ET CURRENT_EVENTS Malicious iframe""

SID: 2016297

Revision: 3

Class Type: trojan-activity

Metadata: created_at 2013_01_29, updated_at 2013_01_29, reviewed_at 2024_01_25

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,from_server

Contents:

  • Value: "<iframe"

  • Value: "scrolling=auto frameborder=no align=center height=2 width=2"

Within: 59

PCRE: "/^((?!<\/iframe>).)?[\r\n\s]+name[\r\n\s]=[\r\n\s]*(?P[\x22\x27])?(Twitter|Google+)(?P=q)?[\r\n\s]+/R"

Special Options:

  • file_data

source