AT related malicious URL (red-mud-f702 .kendallelsaxbthtp0668 .workers .dev/email-notification2e3waXFarD_eFq_tvhuJl8ff%3Bfr%3D1lyxrntvqTbTboazV .AWccO3ZxPz8a78gk_aXXTrSbCR2jUDllDnMyiTKvp4YMycirUlo .Bp8iie . .AAA .0 .0 .Bp8iie .AWfdP6EKabBlBt6U0GYa0PcIPxQ)
Sourcejulioliraup/antiphishing
CreatedMay 22, 2026
UpdatedMay 22, 2026
Classificationsocial-engineering
alert http $HOME_NET any -> any any (msg:"AT related malicious URL (red-mud-f702 .kendallelsaxbthtp0668 .workers .dev/email-notification2e3waXFarD_eFq_tvhuJl8ff%3Bfr%3D1lyxrntvqTbTboazV .AWccO3ZxPz8a78gk_aXXTrSbCR2jUDllDnMyiTKvp4YMycirUlo .Bp8iie . .AAA .0 .0 .Bp8iie .AWfdP6EKabBlBt6U0GYa0PcIPxQ)"; flow:established,to_server; http.uri; content:"/email-notification2e3waXFarD_eFq_tvhuJl8ff%3Bfr%3D1lyxrntvqTbTboazV.AWccO3ZxPz8a78gk_aXXTrSbCR2jUDllDnMyiTKvp4YMycirUlo.Bp8iie..AAA.0.0.Bp8iie.AWfdP6EKabBlBt6U0GYa0PcIPxQ"; startswith; fast_pattern; http.host; content:"red-mud-f702.kendallelsaxbthtp0668.workers.dev"; endswith; reference:url,openphish.com; reference:url,github.com/julioliraup/Antiphishing; reference:url,julioliraup.github.io/ET/signature.html?sid=6001598; classtype:social-engineering; sid:6001598; rev:2; metadata:signature_severity Major, created_et 2026_05_11, updated_et 2025_05_11;)
References
Metadata
signature severityMajor
created et2026_05_11
updated et2025_05_11
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!