Back to Rule

Rule History

SID: 2022603 • Source: et/open

Versions (5)

Version DetailsCurrent

Rev: 3Mar 9, 2016, 12:00 PM

ET WEB_CLIENT Generic Fake Support Phone Scam Mar 8

alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Generic Fake Support Phone Scam Mar 8"; flow:established,from_server; file_data; content:"onload=|22|myFunction|28 29 3b 22|"; fast_pattern; nocase; content:"onclick=|22|myFunction|28 29 3b 22|"; nocase; content:"onkeydown=|22|myFunction|28 29 3b 22|"; nocase; content:"onunload=|22|myFunction|28 29 3b 22|"; nocase; content:"<audio"; nocase; pcre:"/^[^\r\n]+autoplay=[\x22\x27]autoplay/Rsi"; content:"TOLL FREE"; nocase; classtype:social-engineering; sid:2022603; rev:3; metadata:created_at 2016_03_09, confidence Medium, signature_severity Minor, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_08_16;)

Mar 9, 2016, 12:00 PM

Aug 16, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

Nov 4, 2025, 10:34 PM

rules/emerging-web_client.rules