Back to Rule

Rule History

SID: 2024463 • Source: et/open

Versions (2)

Version DetailsCurrent

Rev: 3Jul 12, 2017, 12:00 PM

ET DELETED Successful Generic 107 Phish Jul 13 2017

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET DELETED Successful Generic 107 Phish Jul 13 2017"; flow:to_server,established; content:"POST"; http_method; content:"-login.id-107sbtd9cbhsbt"; nocase; http_header; fast_pattern:4,20; pcre:"/^Host\x3a\x20[^\r\n]+\-login\.id\-107sbtd9cbhsbt[^\r]+$/Hmi"; classtype:credential-theft; sid:2024463; rev:3; metadata:affected_product Web_Browsers, attack_target Client_Endpoint, created_at 2017_07_12, deployment Perimeter, signature_severity Major, tag Phishing, updated_at 2019_07_26;)

Jul 12, 2017, 12:00 PM

Jul 26, 2019, 12:00 PM

Jul 12, 2017, 12:00 PM

May 31, 2024, 9:00 PM

rules/emerging-deleted.rules