AT related malicious URL (citiretailservices .citibankonlline .com/?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9 .eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc3ODI4OTc4OSwiaWF0IjoxNzc4MjgyNTg5LCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMm1ybDV2aXI3ZmpzZDViMWswb3Zua20iLCJuYmYiOjE3NzgyODI1ODksInRzIjoxNzc4MjgyNTg5NjU4MzUyfQ .QNf98IHW1RRG-Tew01BV5BMob6WpAxGI-8JfgeDmjeQ&sid=e02c35f6-4b34-11f1-8f94-e353ff0638ce/)
Sourcejulioliraup/antiphishing
CreatedMay 22, 2026
UpdatedMay 22, 2026
Classificationsocial-engineering
alert http $HOME_NET any -> any any (msg:"AT related malicious URL (citiretailservices .citibankonlline .com/?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9 .eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc3ODI4OTc4OSwiaWF0IjoxNzc4MjgyNTg5LCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMm1ybDV2aXI3ZmpzZDViMWswb3Zua20iLCJuYmYiOjE3NzgyODI1ODksInRzIjoxNzc4MjgyNTg5NjU4MzUyfQ .QNf98IHW1RRG-Tew01BV5BMob6WpAxGI-8JfgeDmjeQ&sid=e02c35f6-4b34-11f1-8f94-e353ff0638ce/)"; flow:established,to_server; http.uri; content:"/?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc3ODI4OTc4OSwiaWF0IjoxNzc4MjgyNTg5LCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMm1ybDV2aXI3ZmpzZDViMWswb3Zua20iLCJuYmYiOjE3NzgyODI1ODksInRzIjoxNzc4MjgyNTg5NjU4MzUyfQ.QNf98IHW1RRG-Tew01BV5BMob6WpAxGI-8JfgeDmjeQ&sid=e02c35f6-4b34-11f1-8f94-e353ff0638ce/"; startswith; fast_pattern; http.host; content:"citiretailservices.citibankonlline.com"; endswith; reference:url,openphish.com; reference:url,github.com/julioliraup/Antiphishing; reference:url,julioliraup.github.io/ET/signature.html?sid=6000112; classtype:social-engineering; sid:6000112; rev:2; metadata:signature_severity Major, created_et 2026_05_10, updated_et 2025_05_11;)
References
Metadata
signature severityMajor
created et2026_05_10
updated et2025_05_11
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!