A customer stumbled across an interesting chunk of heavily obfuscated JavaScript that was the first page in a chain of events leading to a BlackHole exploit kit. The code was of interest, because it looked nothing like BlackHhole redirect pages we’d seen before. The new rules quickly produced a pile of false positives – it seems that Google, among others, like the hex-escape quote marks in those calls. The rules are off by default in all policies, but administrators who are willing to review events for obviously evil are encouraged to turn them on.”]
Source: https://blog.talosintelligence.com/2012/07/power-of-open-source-intelligence.html