Identified Download Of Suspicious SCT File Over HTTP
Publish Date: 16 Juni 2016
Schweregrad:: Kritisch
Hinweisdatum: 16 Juni 2016
Beschreibung
Microsoft enables scripts that are embedded in an HTML document or in a Windows Scripting Host file to access COM+ objects. An attacker can create COM+ objects in script code stored in an Extensible Markup Language (XML) files, such files are called 'scriptlets' to execute command on the remote host. This is a heuristic based rule which identifies the download of such 'scriptlets' files over HTTP.
Trend Micro Lösungen
Apply associated Trend Micro DPI Rules.
Lösungen
Trend Micro Deep Security DPI Rule Number: 1007644