ET PHISHING TA2730 Javascript Request 2026-08-06
Sourceet/open
Fileemerging-phishing.rules
CreatedAugust 7, 2026
UpdatedAugust 7, 2026
Classificationsocial-engineering
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET PHISHING TA2730 Javascript Request 2026-08-06"; flow:established,to_client ; http.stat_code; content:"200"; http.content_len; byte_test:0,<=,450000,0,string,dec ; http.response_body; content:"const"; startswith; content:"parseInt"; content:".push"; content:".shift"; content:"apiUrl"; fast_pattern; content:"siteName"; content:"new Proxy"; content:"config.js"; reference:url,urlscan.io/result/019fce1f-287e-7272-a0ec-e952047e373b/#transactions ; classtype:social-engineering; sid:2071416; rev:1; metadata:attack_target Client_Endpoint, tls_state TLSDecrypt, created_at 2026_08_07, deployment Perimeter, deployment SSLDecrypt, performance_impact Moderate, confidence Medium, signature_severity Major, tag Phishing, tag TA2730, updated_at 2026_08_07; target:dest_ip;)
Metadata
attack targetClient_Endpoint
tls stateTLSDecrypt
created at2026_08_07
deploymentSSLDecrypt
performance impactModerate
confidenceMedium
signature severityMajor
tagTA2730
updated at2026_08_07
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!