Back to Rule

Rule History

SID: 2025653 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 1May 10, 2018, 12:00 PM

ET PHISHING Possible Chalbhai (Multibrand) Phishing Landing 2018-05-10

alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET PHISHING Possible Chalbhai (Multibrand) Phishing Landing 2018-05-10"; flow:established,to_client; file_data; content:"function unhideBody()"; nocase; fast_pattern; content:"bodyElems"; distance:0; pcre:"/^\s*=\s*document\s*\.\s*getElementsByTagName\s*\(\s*[\x22\x27]body[\x22\x27]/Ri"; content:"bodyElems[0]"; distance:0; pcre:"/^\s*\.\s*style\s*\.\s*visibility\s*=\s*[\x22\x27]visible[\x22\x27]/Ri"; content:"style=|22|visibility:hidden|22 20|onload=|22|unhideBody()|22|"; nocase; distance:0; content:"<div id=|22|image1|22 20|style=|22|position|3a|absolute|3b 20|overflow|3a|hidden|3b 20|left|3a|"; nocase; distance:0; classtype:social-engineering; sid:2025653; rev:1; metadata:affected_product Web_Browsers, attack_target Client_Endpoint, created_at 2018_05_10, deployment Perimeter, confidence Medium, signature_severity Minor, tag Phishing, updated_at 2019_07_26;)

May 10, 2018, 12:00 PM

Jul 26, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-phishing.rules