Back to Rule

Rule History

SID: 2021357 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 5Jun 26, 2015, 12:00 PM

ET WEB_CLIENT Fake AV Phone Scam Landing June 26 2015 M1

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET WEB_CLIENT Fake AV Phone Scam Landing June 26 2015 M1"; flow:established,to_server; content:"GET"; http_method; content:".php?cid="; http_uri; fast_pattern; content:"-w"; distance:0; http_uri; pcre:"/\.php\?cid=[0-9]+?-w[A-Z0-9]{23}$/U"; classtype:social-engineering; sid:2021357; rev:5; metadata:created_at 2015_06_26, confidence High, signature_severity Minor, updated_at 2019_08_16;)

Jun 26, 2015, 12:00 PM

Aug 16, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-web_client.rules