""ET CURRENT_EVENTS Malicious Redirect 8x8 script tag""

SID: 2018053

Revision: 3

Class Type: trojan-activity

Metadata: created_at 2014_02_01, updated_at 2014_06_20

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,from_server

Contents:

  • Value: ".php?id="

  • Value: "/"

  • Value: "<script"

Within: 1

PCRE: "/^(?:(?!<\/script>).)?\ssrc\s?=\s*?[\x22\x27][^\x22\x27]+?\/[a-z0-9A-Z]{8}.php\?id=\d{6,9}[\x22\x27]/Rsi"

Special Options:

  • file_data

  • nocase

source