AT related malicious URL (u0688998 .plsk .regruhosting .ru/wp-content/themes/twentytwentyone/assets/ .ss/SF-Express/e-invoice .php)

SID: 6000771Rev: 20 views
Sourcejulioliraup/antiphishing
CreatedMay 22, 2026
UpdatedMay 22, 2026
Classificationsocial-engineering
alert http $HOME_NET any -> any any (msg:"AT related malicious URL (u0688998 .plsk .regruhosting .ru/wp-content/themes/twentytwentyone/assets/ .ss/SF-Express/e-invoice .php)"; flow:established,to_server; http.uri; content:"/wp-content/themes/twentytwentyone/assets/.ss/SF-Express/e-invoice.php"; startswith; fast_pattern; http.host; content:"u0688998.plsk.regruhosting.ru"; endswith; reference:url,openphish.com; reference:url,github.com/julioliraup/Antiphishing; reference:url,julioliraup.github.io/ET/signature.html?sid=6000771; classtype:social-engineering; sid:6000771; rev:2; metadata:signature_severity Major, created_et 2026_05_10, updated_et 2025_05_11;)

Metadata

signature severityMajor
created et2026_05_10
updated et2025_05_11

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!