HTTP: Internet Explorer "IFRAME" Tag SMB Source

This signature detects an HTML file containing an "IFRAME" tag with a source set that points to a location on an SMB share. Attackers can be attempting to deliver malware to the target system. Note: Network administrators can use this technique for legitimate purposes.

Extended Description

IFRAME tags pointing to SMB share resources may indicate that an attack is being attempted, though legitimate uses do exist.

Short Name
HTTP:STC:IE:IFRAME-SMB
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
"IFRAME" Explorer Internet SMB Source Tag
Release Date
07/15/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Occasionally

Found a potential security threat?