""ET CURRENT_EVENTS Evil Redirector Leading to EK Apr 28 2016""

SID: 2022772

Revision: 2

Class Type: trojan-activity

Metadata: affected_product Web_Browsers, attack_target Client_Endpoint, created_at 2016_04_28, deployment Perimeter, signature_severity Major, tag Redirector, updated_at 2016_04_29

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,from_server

Contents:

  • Value: "|3d 22 5c 78 32|"

  • Value: "|3d 22 5c 78 36|"

  • Value: "|3d 22 5c 78 37|"

  • Value: ""

  • Value: !""

Within: 500

PCRE: "/^\s?