Back to Rule

Rule History

SID: 2022607 • Source: et/open

Versions (5)

Version DetailsCurrent

Rev: 3Mar 9, 2016, 12:00 PM

ET WEB_CLIENT Generic Fake Support Phone Scam Mar 9 M3

alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Generic Fake Support Phone Scam Mar 9 M3"; flow:established,from_server; file_data; content:"<title>ALERT"; fast_pattern; content:"makeNewPosition"; nocase; distance:0; content:"animateDiv"; nocase; distance:0; content:"div.fakeCursor"; nocase; distance:0; content:"<audio autoplay"; nocase; distance:0; classtype:social-engineering; sid:2022607; rev:3; metadata:created_at 2016_03_09, confidence Medium, signature_severity Minor, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_08_16;)

Mar 9, 2016, 12:00 PM

Aug 16, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

Dec 4, 2025, 10:34 PM

rules/emerging-web_client.rules