""ET CURRENT_EVENTS Sibhost Zip as Applet Archive July 08 2013""

SID: 2017166

Revision: 4

Class Type: trojan-activity

Metadata: created_at 2013_07_23, updated_at 2023_09_12, reviewed_at 2023_09_11

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,to_client

Contents:

  • Value: "jquery.js"

  • Value: "archive"

Within:

PCRE: "/^[\r\n\s]?=[\r\n\s]?[\x22\x27][^\x22\x27]+?.zip[\x22\x27]/Rsi"

Special Options:

  • file_data

  • fast_pattern

  • nocase

source