""ET CURRENT_EVENTS Underminer EK Plugin Check""

SID: 2026424

Revision: 2

Class Type: trojan-activity

Metadata: affected_product Web_Browsers, attack_target Client_Endpoint, created_at 2018_09_28, deployment Perimeter, signature_severity Major, tag Underminer_EK, updated_at 2018_09_28

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,to_client

Contents:

  • Value: "Cache-Control|3a 20|private|3b 20|no-store|3b 20|no-cache|0d 0a|"

  • Value: "Content-Encoding|3a 20|gzip|0d 0a|"

  • Value: "name:location.hostname,init:function()"

  • Value: "document.body.appendChild(UserData.userData)"

  • Value: "D27CDB6E-AE6D-11cf-96B8-444553540000"

  • Value: ".setAttribute(|22|type|22|,|22|application/x-shockwave-flash|22|)"

  • Value: ".test(navigator.userAgent)?function"

  • Value: "map([|22|ShockwaveFlash.ShockwaveFlash|22|,|22|AcroPDF.PDF|22|,|22|PDF.PdfCtrl|22|,|22|QuickTime.QuickTime|22|,|22|RealPlayer|22|,|22|SWCtl.SWCtl|22|,|22|WMPlayer.OCX|22|,|22|AgControl.AgControl|22|,|22|Skype.Detection|22|]"

Within: 300

PCRE:

Special Options:

  • http_header

  • http_header

  • file_data

  • nocase

  • nocase

  • nocase

  • nocase

  • nocase

  • nocase

  • fast_pattern

source