HTTP: Metasploit "JSObfu.new" JavaScript Obfuscation

This signature detects the behavior of the Metasploit JSObfu.new JavaScript Obfuscator. This is generally a strong indication of an attack attempt.

Extended Description

The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the url property to a certain ActiveX control in vpnweb.ocx, aka Bug ID CSCsy00904.

Short Name
SHELLCODE:JS:JSOBFU-NEW
Severity
Major
Recommended
False
Recommended Action
Drop
Category
SHELLCODE
Keywords
"JSObfu.new" CVE-2011-2039 JavaScript Metasploit Obfuscation
Release Date
11/10/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
CVSS Score

7.6

Found a potential security threat?