ET PHISHING HiStats Lookalike Domain in TLS SNI (histats .top)
Sourceet/open
Fileemerging-phishing.rules
CreatedJuly 24, 2026
UpdatedJuly 24, 2026
Classificationtrojan-activity
alert tls $HOME_NET any -> $EXTERNAL_NET any (msg:"ET PHISHING HiStats Lookalike Domain in TLS SNI (histats .top)"; flow:established,to_server ; tls.sni; dotprefix; content:".histats.top"; endswith; fast_pattern; classtype:trojan-activity; sid:2071278; rev:1; metadata:created_at 2026_07_24, performance_impact Low, confidence High, signature_severity Minor, updated_at 2026_07_24;)
Metadata
created at2026_07_24
performance impactLow
confidenceHigh
signature severityMinor
updated at2026_07_24
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!