""ET CURRENT_EVENTS Successful mail .ru Credential Phish""

SID: 2039483

Revision: 1

Class Type: trojan-activity

Metadata: attack_target Client_Endpoint, created_at 2022_10_19, deployment Perimeter, performance_impact Low, signature_severity Major, updated_at 2022_10_19

Reference:

  • md5

  • 4ac6e228becc1e069a283722f9e1290d

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "POST"

  • Value: "l0g.php"

  • Value: "domain|3d|mail|2e|ru|26|userName|3d|" Depth: 24

  • Value: "|26|password|3d|"

Within:

PCRE: "/l0g.php$/U"

Special Options:

  • http_method

  • http_uri

  • fast_pattern

  • http_client_body

  • http_client_body

source