HTTP: Microsoft ActiveX Control ClassID Obfuscation

This signature detects attempts to obfuscate the ClassID of an ActiveX control. Such activity is currently being used in the wild by malware on popular websites. This could also trigger on marketing websites that also obfuscate their JavaScript. Care should be taken during research of sites that trigger on this signature.

Short Name
HTTP:STC:ACTIVEX:CLSID-OBFUS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX ClassID Control Microsoft Obfuscation
Release Date
06/07/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown

Found a potential security threat?