AT related malicious URL (strosin.fujiwar.site/redirect.html/?x=b2Q9MXN5aTZhMGI3MjE3NDZjNTd0MHRfb3V0dmxfUHJlbWl1bQ%3D%3D&\;v=NmtxeHA2&\;q=QzAwMDByZng4eXkydnluMDBnX3g0MTU5Nw%3D%3D&\;o=Zng4eXk%3D&\;u=Zng4eXk%3D&\;k=Zng4eXk%3D&\;m=X3g0&\;c=&\;l=&\;a=X3g0&\;r=X3g0&\;t=&\;y=X3g0&\;s=&\;b=X3g0M2w0dmgtMGx1M2htMg==4j3dDX)
Sourcejulioliraup/antiphishing
CreatedMay 22, 2026
UpdatedMay 22, 2026
Classificationsocial-engineering
alert http $HOME_NET any -> any any (msg:"AT related malicious URL (strosin.fujiwar.site/redirect.html/?x=b2Q9MXN5aTZhMGI3MjE3NDZjNTd0MHRfb3V0dmxfUHJlbWl1bQ%3D%3D&\;v=NmtxeHA2&\;q=QzAwMDByZng4eXkydnluMDBnX3g0MTU5Nw%3D%3D&\;o=Zng4eXk%3D&\;u=Zng4eXk%3D&\;k=Zng4eXk%3D&\;m=X3g0&\;c=&\;l=&\;a=X3g0&\;r=X3g0&\;t=&\;y=X3g0&\;s=&\;b=X3g0M2w0dmgtMGx1M2htMg==4j3dDX)"; flow:established,to_server; http.uri; content:"/redirect.html/?x=b2Q9MXN5aTZhMGI3MjE3NDZjNTd0MHRfb3V0dmxfUHJlbWl1bQ%3D%3D&|3b|v=NmtxeHA2&|3b|q=QzAwMDByZng4eXkydnluMDBnX3g0MTU5Nw%3D%3D&|3b|o=Zng4eXk%3D&|3b|u=Zng4eXk%3D&|3b|k=Zng4eXk%3D&|3b|m=X3g0&|3b|c=&|3b|l=&|3b|a=X3g0&|3b|r=X3g0&|3b|t=&|3b|y=X3g0&|3b|s=&|3b|b=X3g0M2w0dmgtMGx1M2htMg==4j3dDX"; startswith; fast_pattern; http.host; content:"strosin.fujiwar.site"; endswith; reference:url,openphish.com; reference:url,julioliraup.github.io/ET/signature.html?sid=6003601; classtype:social-engineering; sid:6003601; rev:1; metadata:signature_severity Major, created_et 2026_05_19;)
References
Metadata
signature severityMajor
created et2026_05_19
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!