<div dir="ltr"><div><br></div><div><a href="https://community.rapid7.com/community/metasploit/blog">https://community.rapid7.com/community/metasploit/blog</a><br></div><div><br></div><div>Proposed sig:</div><div><br></div>alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET CURRENT_EVENTS Possible Android CVE-2014_6041"; flow:from_server,established; content:"|5c|u0000javascript:"; nocase; reference:url,<a href="http://1337day.com/exploit/22581">1337day.com/exploit/22581</a>; classtype:trojan-activity; sid:1111111; rev:1;)<div><br clear="all"><div>Regards</div>-- <br><div dir="ltr">_______________________________<br><br>Jaime Blasco<div><br></div><div>AlienVault Labs Director<br><br><a href="http://www.ossim.com" target="_blank">www.ossim.com</a><br><a href="http://labs.alienvault.com" target="_blank">labs.alienvault.com</a><br>Email: <a href="mailto:jaime.blasco@alienvault.com" target="_blank">jaime.blasco@alienvault.com</a><br><br><a href="http://twitter.com/jaimeblascob" target="_blank">http://twitter.com/jaimeblascob</a><br></div></div>
</div></div>