Versions (3)
Version DetailsCurrent
Rev: 4 • Jul 1, 2021, 12:00 PMET PHISHING Observed Possible Phishing 2021-06-29
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET PHISHING Observed Possible Phishing 2021-06-29"; flow:established,to_client; file.data; content:"Webmail Login"; fast_pattern; content:"action|3d 22|process.php|22|"; distance:0; content:"method|3d 22|post|22|"; distance:0; content:"target|3d 22 5f|top|22|"; distance:0; content:"style|3d 22|visibility|3a 22|>"; distance:0; reference:url,app.any.run/tasks/5fcdc0a0-7a79-4bcb-b2fb-3d358571d858/; classtype:social-engineering; sid:2033218; rev:4; metadata:attack_target Client_Endpoint, created_at 2021_07_01, deployment Perimeter, deprecation_reason Age, performance_impact Moderate, confidence Low, signature_severity Critical, tag Phishing, updated_at 2024_03_25, reviewed_at 2024_03_25, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1566, mitre_technique_name Phishing;)
Jul 1, 2021, 12:00 PM
Mar 25, 2024, 12:00 PM
Jul 1, 2021, 12:00 PM
Sep 13, 2024, 3:01 PM
rules/emerging-phishing.rules