Back to Rule

Rule History

SID: 2044620 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 1Mar 14, 2023, 12:00 PM

ET HUNTING Possible Telegram Proxy Site (sendMessage)

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET HUNTING Possible Telegram Proxy Site (sendMessage)"; flow:established,to_server; http.uri; content:"/sendMessage?chat_id="; fast_pattern; http.host; content:!"api.telegram.org"; reference:url,core.telegram.org/bots/api#sendmessage; reference:md5,3402c9373726396598011ef6ec1ea243; classtype:unknown; sid:2044620; rev:1; metadata:created_at 2023_03_14, deployment Perimeter, deployment SSLDecrypt, confidence Medium, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_03_15;)

Mar 14, 2023, 12:00 PM

Mar 15, 2023, 12:00 PM

Sep 21, 2024, 3:00 AM

Aug 25, 2025, 9:35 PM

rules/emerging-hunting.rules