AT related malicious URL (dropship.mach95.dev/esgetransfer3baosgeublicfari537.html?eta=loror@d40fb4ee05924b7d16ed8de5b6e1999b6feb.net)
Sourcejulioliraup/antiphishing
CreatedMay 22, 2026
UpdatedMay 22, 2026
Classificationsocial-engineering
alert http $HOME_NET any -> any any (msg:"AT related malicious URL (dropship.mach95.dev/esgetransfer3baosgeublicfari537.html?eta=loror@d40fb4ee05924b7d16ed8de5b6e1999b6feb.net)"; flow:established,to_server; http.uri; content:"/esgetransfer3baosgeublicfari537.html?eta=loror@d40fb4ee05924b7d16ed8de5b6e1999b6feb.net"; startswith; fast_pattern; http.host; content:"dropship.mach95.dev"; endswith; reference:url,openphish.com; reference:url,julioliraup.github.io/ET/signature.html?sid=6003078; classtype:social-engineering; sid:6003078; rev:1; metadata:signature_severity Major, created_et 2026_05_18;)
References
Metadata
signature severityMajor
created et2026_05_18
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!