Back to Rule

Rule History

SID: 2069030 • Source: et/open

Versions (2)

Version DetailsCurrent

Rev: 2Apr 27, 2026, 12:00 PM

ET PHISHING DeviceCode Phishing Landing Page Observed

alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET PHISHING DeviceCode Phishing Landing Page Observed"; flow:established,to_client; http.response_body; content:"exclusive|20|Copilot|20|features|20|built"; content:"Follow|20|the|20|link|20|below|20|and|20|enter|20|the|20|code|3a|"; fast_pattern; classtype:social-engineering; sid:2069030; rev:2; metadata:affected_product Web_Browsers, attack_target Client_Endpoint, tls_state TLSDecrypt, created_at 2026_04_27, deployment Perimeter, deployment SSLDecrypt, confidence Medium, signature_severity Critical, updated_at 2026_05_01; target:dest_ip;)

Apr 27, 2026, 12:00 PM

May 1, 2026, 12:00 PM

Apr 27, 2026, 10:34 PM

May 1, 2026, 8:34 PM

rules/emerging-phishing.rules