alert dns $HOME_NET any -> any any (msg:"ET TROJAN Possible APT28 Phishing Domain in DNS Query"; dns_query; content:"yahoo-change-password.com"; nocase; isdataat:!1,relative; classtype:trojan-activity; sid:2029721; rev:1; metadata:affected_product Web_Browsers, attack_target Client_Endpoint, created_at 2020_03_23, deployment Perimeter, former_category MALWARE, signature_severity Major, updated_at 2020_11_09;)
Added 2020-11-09 19:10:18 UTC
alert dns $HOME_NET any -> any any (msg:"ET TROJAN Possible APT28 Phishing Domain in DNS Query"; dns_query; content:"yahoo-change-password.com"; nocase; isdataat:!1,relative; classtype:trojan-activity; sid:2029721; rev:1; metadata:affected_product Web_Browsers, attack_target Client_Endpoint, created_at 2020_03_23, deployment Perimeter, former_category MALWARE, signature_severity Major, updated_at 2020_03_23;)
Added 2020-08-05 19:17:48 UTC
alert dns $HOME_NET any -> any any (msg:"ET TROJAN Possible APT28 Phishing Domain in DNS Query"; dns_query; content:"yahoo-change-password.com"; nocase; isdataat:!1,relative; metadata: former_category MALWARE; classtype:trojan-activity; sid:2029721; rev:1; metadata:affected_product Web_Browsers, attack_target Client_Endpoint, deployment Perimeter, signature_severity Major, created_at 2020_03_23, updated_at 2020_03_23;)
Added 2020-03-24 02:58:52 UTC
alert dns $HOME_NET any -> any any (msg:"ET TROJAN Possible APT28 Phishing Domain in DNS Query"; dns_query; content:"yahoo-change-password.com"; nocase; isdataat:!1,relative; metadata: former_category MALWARE; classtype:trojan-activity; sid:2029721; rev:1; metadata:affected_product Web_Browsers, attack_target Client_Endpoint, deployment Perimeter, signature_severity Major, created_at 2020_03_23, updated_at 2020_03_23;)
Added 2020-03-24 02:13:12 UTC
alert dns $HOME_NET any -> any any (msg:"ET TROJAN Possible APT28 Phishing Domain in DNS Query"; dns_query; content:"yahoo-change-password.com"; nocase; isdataat:!1,relative; metadata: former_category MALWARE; classtype:trojan-activity; sid:2029721; rev:1; metadata:affected_product Web_Browsers, attack_target Client_Endpoint, deployment Perimeter, signature_severity Major, created_at 2020_03_23, updated_at 2020_03_23;)
Added 2020-03-23 20:11:44 UTC
alert dns $HOME_NET any -> any any (msg:"ET TROJAN Possible APT28 Phishing Domain in DNS Query"; dns_query; content:"yahoo-change-password.com"; nocase; isdataat:!1,relative; metadata: former_category MALWARE; classtype:trojan-activity; sid:2029721; rev:1; metadata:affected_product Web_Browsers, attack_target Client_Endpoint, deployment Perimeter, signature_severity Major, created_at 2020_03_23, updated_at 2020_03_23;)
Added 2020-03-23 20:04:24 UTC