""ET INFO SUSPICIOUS Single JS file inside of ZIP Download (Observed as lure in malspam campaigns)""

SID: 2022636

Revision: 2

Class Type: misc-activity

Metadata: created_at 2016_03_22, updated_at 2016_03_24

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,to_client

Contents:

  • Value: "PK"

  • Value: "PK|01 02|"

  • Value: ".jsPK|05 06|"

Within: 2

PCRE: "/^.{42}[\x20-\x7f]{1,500}.jsPK\x05\x06.{4}\x01\x00\x01\x00/Rsi"

Special Options:

  • file_data

  • nocase

source