Versions (4)
Version DetailsCurrent
Rev: 2 • Sep 20, 2024, 12:00 PMET PHISHING Generic Credential Phish Landing Page (2024-09-20)
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET PHISHING Generic Credential Phish Landing Page (2024-09-20)"; flow:established,to_client; http.stat_code; content:"200"; http.response_body; content:"discord"; nocase; fast_pattern; content:"application/json"; distance:0; content:".php"; distance:0; content:"password"; nocase; distance:0; classtype:social-engineering; sid:2056031; rev:2; metadata:attack_target Client_Endpoint, tls_state TLSDecrypt, created_at 2024_09_20, deployment Perimeter, deployment SSLDecrypt, deprecation_reason False_Positive, performance_impact Moderate, confidence Low, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_11_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1566, mitre_technique_name Phishing;)
Sep 20, 2024, 12:00 PM
Nov 17, 2025, 12:00 PM
Sep 21, 2024, 3:00 AM
Nov 17, 2025, 10:34 PM
rules/emerging-phishing.rules