ET PHISHING Observed Possible Phishing 2021-06-29

SID: 2033218Rev: 40 views
History
Sourceet/open
CreatedJuly 1, 2021
UpdatedMarch 25, 2024
Classificationsocial-engineering
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET PHISHING Observed Possible Phishing 2021-06-29"; flow:established,to_client; file.data; content:"Webmail Login"; fast_pattern; content:"action|3d 22|process.php|22|"; distance:0; content:"method|3d 22|post|22|"; distance:0; content:"target|3d 22 5f|top|22|"; distance:0; content:"style|3d 22|visibility|3a 22|>"; distance:0; reference:url,app.any.run/tasks/5fcdc0a0-7a79-4bcb-b2fb-3d358571d858/; classtype:social-engineering; sid:2033218; rev:4; metadata:attack_target Client_Endpoint, created_at 2021_07_01, deployment Perimeter, deprecation_reason Age, performance_impact Moderate, confidence Low, signature_severity Critical, tag Phishing, updated_at 2024_03_25, reviewed_at 2024_03_25, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1566, mitre_technique_name Phishing;)

Metadata

attack targetClient_Endpoint
created at2021_07_01
deploymentPerimeter
deprecation reasonAge
performance impactModerate
confidenceLow
signature severityCritical
tagPhishing
updated at2024_03_25
reviewed at2024_03_25
mitre tactic idTA0001
mitre tactic nameInitial_Access
mitre technique idT1566
mitre technique namePhishing

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!