HTTP: Metasploit "JSObfu.new" JavaScript Obfuscation
This signature detects the behavior of the Metasploit JSObfu.new JavaScript Obfuscator. This is generally a strong indication of an attack attempt.
Extended Description
The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Windows, and on Windows Mobile, downloads a client executable file (vpndownloader.exe) without verifying its authenticity, which allows remote attackers to execute arbitrary code via the url property to a certain ActiveX control in vpnweb.ocx, aka Bug ID CSCsy00904.
References
CVE: CVE-2011-2039
URL: https://community.rapid7.com/community/metasploit/blog/2011/07/08/jsobfu
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
7.6