[Emerging-Sigs] SIG: ET CURRENT_EVENTS Possible Redirection to Unknown Exploit Pack

Kevin Ross kevross33 at googlemail.com
Thu Oct 20 18:25:24 EDT 2011


alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET CURRENT_EVENTS
Possible Redirection to Unknown Exploit Pack"; flow:established,to_client;
content:"document.write|28|unescape|28 22|%3Cscript src=|27 22 20 2B 20|;
nocase; classtype:misc-attack; reference:url,
http://www.kahusecurity.com/2011/malware-infection-from-new-exploit-pack/;
sid:1449991; rev:1;)
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.emergingthreats.net/pipermail/emerging-sigs/attachments/20111020/040a76f5/attachment.html


More information about the Emerging-sigs mailing list