ET PHISHING TA2730 Javascript Request 2026-08-06

7.0.35.0SID: 2071416Rev: 1Enabled4 views
Sourceet/open
Fileemerging-phishing.rules
CreatedAugust 7, 2026
UpdatedAugust 7, 2026
Classificationsocial-engineering
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET PHISHING TA2730 Javascript Request 2026-08-06"; flow:established,to_client; http.stat_code; content:"200"; http.content_len; byte_test:0,<=,450000,0,string,dec; http.response_body; content:"const"; startswith; content:"parseInt"; content:".push"; content:".shift"; content:"apiUrl"; fast_pattern; content:"siteName"; content:"new Proxy"; content:"config.js"; reference:url,urlscan.io/result/019fce1f-287e-7272-a0ec-e952047e373b/#transactions; classtype:social-engineering; sid:2071416; rev:1; metadata:attack_target Client_Endpoint, tls_state TLSDecrypt, created_at 2026_08_07, deployment Perimeter, deployment SSLDecrypt, performance_impact Moderate, confidence Medium, signature_severity Major, tag Phishing, tag TA2730, updated_at 2026_08_07; target:dest_ip;)

Metadata

attack targetClient_Endpoint
tls stateTLSDecrypt
created at2026_08_07
deploymentSSLDecrypt
performance impactModerate
confidenceMedium
signature severityMajor
tagTA2730
updated at2026_08_07

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!