""ET CURRENT_EVENTS Fifth Third Banking Credential Phish Landing Page 2022-12-07""

SID: 2042186

Revision: 1

Class Type: trojan-activity

Metadata: affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, created_at 2022_12_07, deployment Perimeter, signature_severity Major, updated_at 2022_12_07

Reference:

  • md5

  • 7a5b7e176c644215f3d64969483ac580

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,to_client

Contents:

  • Value: "200"

  • Value: "include|20 27 2e 2e 2f|blocker|2e|php|27 3b|"

  • Value: "include|20 27 2e 2e 2f|antirobot|2e|php|27 3b|"

  • Value: "include|20 27 2e 2e 2f|bt|2e|php|27 3b|"

  • Value: "include|20 27 2e 2e 2f|blocking|2e|php|27 3b|"

  • Value: "Fifth Third Banking Login|20 7c 20|Fifth Third Bank"

  • Value: "|3c|style|20|type|3d 22|text|2f|css|22 3e|"

Within:

PCRE:

Special Options:

  • http_stat_code

  • file_data

source