""ET CURRENT_EVENTS ING Group Credential Phish Landing Page 2022-12-02""

SID: 2041649

Revision: 1

Class Type: trojan-activity

Metadata: created_at 2022_12_02, updated_at 2022_12_02

Reference:

  • md5

  • fc68fded6fc19e85d37f244329c9ff45

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,to_client

Contents:

  • Value: "200"

  • Value: "<!-- saved from url="

  • Value: "http|2d|equiv|3d 22|refresh|22 20|content|3d 22|15|3b 20|url|3d 2e 2f|bestatigungsnachricht|2e|html|22|"

  • Value: "ING Login"

Within:

PCRE:

Special Options:

  • http_stat_code

  • file_data

source