alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET CURRENT_EVENTS US Bank Phishing Landing"; flow:established,to_client; content:"200"; http_stat_code; file_data; content:"href=|22|index|25|5D_files/"; nocase; content:"src=|22|index|25|5D_files/"; nocase; distance:0; fast_pattern; content:"PersonalID Step"; nocase; distance:0; classtype:trojan-activity; sid:2025619; rev:1; metadata:affected_product Web_Browsers, attack_target Client_Endpoint, created_at 2018_06_21, deployment Perimeter, former_category PHISHING, signature_severity Critical, tag Phishing, updated_at 2020_08_25, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1566, mitre_technique_name Phishing;) <p /> </h2> <p /> Added 2021-07-02 17:57:16 UTC <p /> <p /> <form method="post" action="https://doc.emergingthreats.net/bin/save/Main/2025619" enctype="multipart/form-data" id="threadmode0" name="threadmode0"><input type="hidden" name="crypttoken" value="cd35d49afb5a30334192fd63e56a196a" /><div class="commentPlugin commentPluginPromptBox" style="margin: 5px 0;"> <div><textarea rows="5" cols="80" name="comment" class="twikiTextarea" wrap="soft" style="width: 100%" onfocus="if(this.value=='Please enter documentation, comments, false positives, or concerns with this signature. Press the Attach button below to add samples or Pcaps.')this.value=''" onblur="if(this.value=='')this.value='Please enter documentation, comments, false positives, or concerns with this signature. Press the Attach button below to add samples or Pcaps.'">Please enter documentation, comments, false positives, or concerns with this signature. Press the Attach button below to add samples or Pcaps.</textarea></div><div style="padding: 5px 0 0 0;"><input type="submit" value="Add to Documentation" class="twikiButton" /></div> </div><!--/commentPlugin--> <input type="hidden" name="comment_action" value="save" /> <input type="hidden" name="comment_type" value="threadmode" /> <input type="hidden" name="comment_index" value="0" /></form> <p /> <hr> <p /> <p /> <p /> <h2> <p /> <p /> alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET CURRENT_EVENTS US Bank Phishing Landing"; flow:established,to_client; content:"200"; http_stat_code; file_data; content:"href=|22|index|25|5D_files/"; nocase; content:"src=|22|index|25|5D_files/"; nocase; distance:0; fast_pattern; content:"<title>PersonalID Step"; nocase; distance:0; classtype:trojan-activity; sid:2025619; rev:1; metadata:affected_product Web_Browsers, attack_target Client_Endpoint, created_at 2018_06_21, deployment Perimeter, former_category CURRENT_EVENTS, signature_severity Minor, tag Phishing, updated_at 2018_06_21;) <p /> </h2> <p /> Added 2020-08-05 19:14:43 UTC <p /> <p /> <p /> <hr> <p /> <p /> <p /> <h2> <p /> <p /> alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET CURRENT_EVENTS US Bank Phishing Landing"; flow:established,to_client; content:"200"; http_stat_code; file_data; content:"href=|22|index|25|5D_files/"; nocase; content:"src=|22|index|25|5D_files/"; nocase; distance:0; fast_pattern; content:"<title>PersonalID Step"; nocase; distance:0; metadata: former_category CURRENT_EVENTS; classtype:trojan-activity; sid:2025619; rev:1; metadata:affected_product Web_Browsers, attack_target Client_Endpoint, deployment Perimeter, tag Phishing, signature_severity Minor, created_at 2018_06_21, updated_at 2018_06_21;) <p /> </h2> <p /> Added 2018-06-21 17:44:48 UTC <p /> <p /> <p /> <hr> <p /></div><!-- /patternTopic--> <p /> <p /> </div><!-- /patternContent--> <hr /> This topic: Main<span class='twikiSeparator'> > </span>2025619</span> <br /> Topic revision: r1 - 2021-07-02 - TWikiGuest </div><!-- /patternMainContents--> </div><!-- /patternMain--> </div><!-- /patternFloatWrap--> <div class="clear"> </div> </div><!-- /patternOuter--><div id="patternBottomBar"><div id="patternBottomBarContents"><div id="patternWebBottomBar"><div class="twikiCopyright"><span class="twikiRight"> <a href="http://twiki.org/"><img src="/pub/TWiki/TWikiLogos/T-badge-88x31.gif" alt="This site is powered by the TWiki collaboration platform" width="88" height="31" title="This site is powered by the TWiki collaboration platform" border="0" /></a></span><span class="twikiRight" style="padding:0 10px 0 10px"> <a href="http://www.perl.org/"><img src="/pub/TWiki/TWikiLogos/perl-logo-88x31.gif" alt="Powered by Perl" width="88" height="31" title="Powered by Perl" border="0" /></a></span><span class="twikiRight"> <a href="http://twiki.org/"><img src="/pub/TWiki/TWikiLogos/T-logo-80x15.gif" alt="This site is powered by the TWiki collaboration platform" width="80" height="15" title="This site is powered by the TWiki collaboration platform" border="0" /></a></span>Copyright © Emerging Threats <br /></div><!--/patternWebBottomBar--></div><!-- /patternBottomBarContents--></div><!-- /patternBottomBar--> </div><!-- /patternPage--> </div><!-- /patternPageShadow--> </div><!-- /patternScreen--> </body></html>