Back to Rule

Rule History

SID: 2022606 • Source: et/open

Versions (5)

Version DetailsCurrent

Rev: 3Mar 9, 2016, 12:00 PM

ET WEB_CLIENT Generic Fake Support Phone Scam Mar 9 M2

alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Generic Fake Support Phone Scam Mar 9 M2"; flow:established,from_server; file_data; content:"//Flag we have not"; fast_pattern; nocase; content:"//The location of the page that we will load on a second pop"; nocase; distance:0; content:"//figure out what to use for default number"; nocase; distance:0; content:"//allow for the traffic source to send in their own default number"; nocase; distance:0; content:"//if no unformatted number just use it"; nocase; distance:0; classtype:social-engineering; sid:2022606; rev:3; metadata:created_at 2016_03_09, confidence Medium, signature_severity Minor, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_08_16;)

Mar 9, 2016, 12:00 PM

Aug 16, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

Dec 2, 2025, 11:34 PM

rules/emerging-web_client.rules