""ET CURRENT_EVENTS GrandSoft EK IE Exploit Jan 30 2018""

SID: 2025272

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2018_01_30, updated_at 2018_01_30

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,from_server

Contents:

  • Value: "|3d 20 22 2c|&h|22|"

  • Value: "4d"

  • Value: "5a"

  • Value: "responseBody"

  • Value: "Dim|20|"

  • Value: "Dim|20|"

  • Value: "Win32_OperatingSystem"

Within: 20

PCRE:

Special Options:

  • file_data

  • nocase

  • nocase

  • nocase

  • nocase

  • nocase

  • nocase

  • nocase

source