2021-03-18 17:44:15 +00:00
|
|
|
# Title: Phishing URL Snort2 Ruleset
|
2021-04-09 00:06:41 +00:00
|
|
|
# Updated: Fri, 09 Apr 2021 00:06:35 UTC
|
2021-03-18 17:44:15 +00:00
|
|
|
# Expires: 1 day (update frequency)
|
|
|
|
# Homepage: https://gitlab.com/curben/phishing-filter
|
2021-03-19 00:09:38 +00:00
|
|
|
# License: https://gitlab.com/curben/phishing-filter#license
|
2021-03-18 17:44:15 +00:00
|
|
|
# Source: https://www.phishtank.com/ & https://openphish.com/
|
2021-04-02 12:06:43 +00:00
|
|
|
|
|
|
|
# Notice: https://curben.gitlab.io/phishing-filter-mirror is moved to https://curben.gitlab.io/malware-filter
|
2021-04-04 00:06:31 +00:00
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"00001062.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000001; rev:1;)
|
2021-04-06 00:06:40 +00:00
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"000032818.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000002; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"00005832.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000003; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"00025612.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000004; rev:1;)
|
2021-04-06 12:07:02 +00:00
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"000340053.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000005; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"01db3205053754908.temporary.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000006; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"01lombard.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000007; rev:1;)
|
2021-04-07 00:06:44 +00:00
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"02-billing-secure.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000008; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"02-billing-support.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000009; rev:1;)
|
2021-04-09 00:06:41 +00:00
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"02alertbilling.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000010; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"02billingupdate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000011; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"04x3w.weblium.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200000012; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"07dd96.htmlcomponentservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000013; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"0c584d61-0ba8-48fe-8709-44323bfc47c1.htmlcomponentservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000014; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"0hnx138db.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000015; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"0s.nrxwo2lo.ozvs4y3pnu.cmla.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000016; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"0s.ozvs4y3pnu.nblz.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000017; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"0zqp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000018; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.114.16.4"; content:"Host"; http_header; classtype:attempted-recon; sid:200000019; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"103.2.117.18"; content:"Host"; http_header; classtype:attempted-recon; sid:200000020; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.168.173.244"; content:"Host"; http_header; classtype:attempted-recon; sid:200000021; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.168.173.248"; content:"Host"; http_header; classtype:attempted-recon; sid:200000022; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"104.197.161.143"; content:"Host"; http_header; classtype:attempted-recon; sid:200000023; rev:1;)
|
2021-04-07 12:23:12 +00:00
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"106.12.192.247"; content:"Host"; http_header; classtype:attempted-recon; sid:200000024; rev:1;)
|
2021-04-08 12:07:09 +00:00
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"107.162.152.176"; content:"Host"; http_header; classtype:attempted-recon; sid:200000025; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"10c56fb8-6ae8-4d40-bb14-a3890c961371.htmlcomponentservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000026; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.125.21.66"; content:"Host"; http_header; classtype:attempted-recon; sid:200000027; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"113.161.144.143"; content:"Host"; http_header; classtype:attempted-recon; sid:200000028; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"11dbs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000029; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"123.58.197.18"; content:"Host"; http_header; classtype:attempted-recon; sid:200000030; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"123bantuancovid-19.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000031; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"13-64-245-133.cprapid.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000032; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"13.82.85.210"; content:"Host"; http_header; classtype:attempted-recon; sid:200000033; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"130.211.30.154"; content:"Host"; http_header; classtype:attempted-recon; sid:200000034; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"132689---bet035.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000035; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"134.122.177.22"; content:"Host"; http_header; classtype:attempted-recon; sid:200000036; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"138bet6.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000037; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"14.63.195.13"; content:"Host"; http_header; classtype:attempted-recon; sid:200000038; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"141.193.196.74"; content:"Host"; http_header; classtype:attempted-recon; sid:200000039; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"141.193.196.75"; content:"Host"; http_header; classtype:attempted-recon; sid:200000040; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"148.204.63.249"; content:"Host"; http_header; classtype:attempted-recon; sid:200000041; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"148.66.129.253"; content:"Host"; http_header; classtype:attempted-recon; sid:200000042; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"149.210.143.165"; content:"Host"; http_header; classtype:attempted-recon; sid:200000043; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"156489999899.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000044; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"157.230.240.184"; content:"Host"; http_header; classtype:attempted-recon; sid:200000045; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"157.240.18.15"; content:"Host"; http_header; classtype:attempted-recon; sid:200000046; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"157.240.18.35"; content:"Host"; http_header; classtype:attempted-recon; sid:200000047; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"157.240.194.18"; content:"Host"; http_header; classtype:attempted-recon; sid:200000048; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"157.240.194.35"; content:"Host"; http_header; classtype:attempted-recon; sid:200000049; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"157.240.22.35"; content:"Host"; http_header; classtype:attempted-recon; sid:200000050; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"159.203.115.201"; content:"Host"; http_header; classtype:attempted-recon; sid:200000051; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"159.65.133.234"; content:"Host"; http_header; classtype:attempted-recon; sid:200000052; rev:1;)
|
2021-04-09 00:06:41 +00:00
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"159.89.97.78"; content:"Host"; http_header; classtype:attempted-recon; sid:200000053; rev:1;)
|
2021-04-08 12:07:09 +00:00
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"165.22.103.235"; content:"Host"; http_header; classtype:attempted-recon; sid:200000054; rev:1;)
|
2021-04-09 00:06:41 +00:00
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"165.227.38.13"; content:"Host"; http_header; classtype:attempted-recon; sid:200000055; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"172.217.21.162"; content:"Host"; http_header; classtype:attempted-recon; sid:200000056; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"173.212.239.242"; content:"Host"; http_header; classtype:attempted-recon; sid:200000057; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"174.138.36.47"; content:"Host"; http_header; classtype:attempted-recon; sid:200000058; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"18-144-26-91.cprapid.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000059; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.16.26.234"; content:"Host"; http_header; classtype:attempted-recon; sid:200000060; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.16.26.235"; content:"Host"; http_header; classtype:attempted-recon; sid:200000061; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.16.26.236"; content:"Host"; http_header; classtype:attempted-recon; sid:200000062; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.16.26.237"; content:"Host"; http_header; classtype:attempted-recon; sid:200000063; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.16.30.218"; content:"Host"; http_header; classtype:attempted-recon; sid:200000064; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.16.30.219"; content:"Host"; http_header; classtype:attempted-recon; sid:200000065; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.16.30.220"; content:"Host"; http_header; classtype:attempted-recon; sid:200000066; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.16.30.221"; content:"Host"; http_header; classtype:attempted-recon; sid:200000067; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.16.30.222"; content:"Host"; http_header; classtype:attempted-recon; sid:200000068; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.16.43.122"; content:"Host"; http_header; classtype:attempted-recon; sid:200000069; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.16.43.123"; content:"Host"; http_header; classtype:attempted-recon; sid:200000070; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.16.43.124"; content:"Host"; http_header; classtype:attempted-recon; sid:200000071; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.16.43.125"; content:"Host"; http_header; classtype:attempted-recon; sid:200000072; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"182.16.43.126"; content:"Host"; http_header; classtype:attempted-recon; sid:200000073; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.151.204.9"; content:"Host"; http_header; classtype:attempted-recon; sid:200000074; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.177.54.1"; content:"Host"; http_header; classtype:attempted-recon; sid:200000075; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.177.54.2"; content:"Host"; http_header; classtype:attempted-recon; sid:200000076; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"185.177.54.9"; content:"Host"; http_header; classtype:attempted-recon; sid:200000077; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"190854.8b.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000078; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"193.135.153.242"; content:"Host"; http_header; classtype:attempted-recon; sid:200000079; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"194.147.142.232"; content:"Host"; http_header; classtype:attempted-recon; sid:200000080; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"1amazon-amazon.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000081; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"1c0b6640eb.nxcli.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000082; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"1d921d2f.orson.website"; content:"Host"; http_header; classtype:attempted-recon; sid:200000083; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"1dom.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200000084; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"1i960ya4tnm.typeform.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000085; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"1inich.exchange"; content:"Host"; http_header; classtype:attempted-recon; sid:200000086; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"1klasses-grunde.mmtest.dk"; content:"Host"; http_header; classtype:attempted-recon; sid:200000087; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"2-57-122-7.cprapid.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000088; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"2.136.95.251"; content:"Host"; http_header; classtype:attempted-recon; sid:200000089; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"201.182.212.21"; content:"Host"; http_header; classtype:attempted-recon; sid:200000090; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"2020.171905.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000091; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"20200907234120.lamworld.co.bw"; content:"Host"; http_header; classtype:attempted-recon; sid:200000092; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"2021contestnike2021.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000093; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"203.114.112.70"; content:"Host"; http_header; classtype:attempted-recon; sid:200000094; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"205.204.101.13"; content:"Host"; http_header; classtype:attempted-recon; sid:200000095; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"206.189.85.218"; content:"Host"; http_header; classtype:attempted-recon; sid:200000096; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"208.113.129.11"; content:"Host"; http_header; classtype:attempted-recon; sid:200000097; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"208.82.115.230"; content:"Host"; http_header; classtype:attempted-recon; sid:200000098; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"209.97.188.25"; content:"Host"; http_header; classtype:attempted-recon; sid:200000099; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"212897764576871473832-dot-bn058.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000100; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.118.241.26"; content:"Host"; http_header; classtype:attempted-recon; sid:200000101; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.118.241.27"; content:"Host"; http_header; classtype:attempted-recon; sid:200000102; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.118.241.28"; content:"Host"; http_header; classtype:attempted-recon; sid:200000103; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"216.118.241.29"; content:"Host"; http_header; classtype:attempted-recon; sid:200000104; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"217505.8b.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000105; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"217651.8b.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000106; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"219betasus.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000107; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.186.13.91"; content:"Host"; http_header; classtype:attempted-recon; sid:200000108; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"222.231.3.128"; content:"Host"; http_header; classtype:attempted-recon; sid:200000109; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"2482689012.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000110; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"24a69f75.orson.website"; content:"Host"; http_header; classtype:attempted-recon; sid:200000111; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"24yrs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000112; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"25tnr.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000113; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"27976a9732.nxcli.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000114; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"2c3262d59d2716553.tempsite.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000115; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"2f0e2b9c590073489f82edf022826b77d4944aff63bcab34475de3a3apaneid.s3-web.eu-de.cloud-object-storage.appdomain.cloud"; content:"Host"; http_header; classtype:attempted-recon; sid:200000116; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"2fa.bthei.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000117; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"2zse2v3hzag375l56kx2din4am--m-facebook-com.translate.goog"; content:"Host"; http_header; classtype:attempted-recon; sid:200000118; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"3.129.10.45"; content:"Host"; http_header; classtype:attempted-recon; sid:200000119; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"30ywc.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000120; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"31.13.71.1"; content:"Host"; http_header; classtype:attempted-recon; sid:200000121; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"31jan.page.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000122; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"3251151565141.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000123; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"32e0bbaa3c3745914.temporary.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000124; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"34.70.209.251"; content:"Host"; http_header; classtype:attempted-recon; sid:200000125; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"34567765678.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000126; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"346-pembatalan.forumz.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200000127; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"35.186.228.86"; content:"Host"; http_header; classtype:attempted-recon; sid:200000128; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"35.199.84.117"; content:"Host"; http_header; classtype:attempted-recon; sid:200000129; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"35.239.58.234"; content:"Host"; http_header; classtype:attempted-recon; sid:200000130; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"37.59.98.31"; content:"Host"; http_header; classtype:attempted-recon; sid:200000131; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"38192786.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000132; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"386f9e87.ithemeshosting.com.php73-39.lan3-1.websitetestlink.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000133; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"39.105.75.57"; content:"Host"; http_header; classtype:attempted-recon; sid:200000134; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"3deya6i.blob.core.windows.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000135; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"3dhome.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200000136; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"3dinfosecurity.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000137; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"3ff7c459-86b2-4f6d-b6b0-ba6402ef6cb0.htmlcomponentservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000138; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"3glite.wapka.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200000139; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"3mvirugambakkam.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000140; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"3no.ro"; content:"Host"; http_header; classtype:attempted-recon; sid:200000141; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"3wondersexpeditions.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000142; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"43-245-61-213.cprapid.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000143; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.238.23.82"; content:"Host"; http_header; classtype:attempted-recon; sid:200000144; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.40.130.40"; content:"Host"; http_header; classtype:attempted-recon; sid:200000145; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"45.76.76.126"; content:"Host"; http_header; classtype:attempted-recon; sid:200000146; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"4566778899.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000147; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"456787675432.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000148; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"4574c5a83f3739528.temporary.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000149; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"46.101.162.235"; content:"Host"; http_header; classtype:attempted-recon; sid:200000150; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.254.68.135"; content:"Host"; http_header; classtype:attempted-recon; sid:200000151; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"47.74.231.192"; content:"Host"; http_header; classtype:attempted-recon; sid:200000152; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"472a4262-a2a1-4785-b3aa-4816cba070ed.htmlcomponentservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000153; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"48tlp.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000154; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"4a102d0dfd.nxcli.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000155; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"4c.vc"; content:"Host"; http_header; classtype:attempted-recon; sid:200000156; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"4datasolution.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000157; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"4jv02.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000158; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"4lxkd.r.ag.d.sendibm3.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000159; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"4vkjkwex22wbmemxbmimva-on.drv.tw"; content:"Host"; http_header; classtype:attempted-recon; sid:200000160; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"51.255.64.58"; content:"Host"; http_header; classtype:attempted-recon; sid:200000161; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"51.fi"; content:"Host"; http_header; classtype:attempted-recon; sid:200000162; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"51_24_51.nagoriktv.com."; content:"Host"; http_header; classtype:attempted-recon; sid:200000163; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"51jianli.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000164; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"52.139.34.8"; content:"Host"; http_header; classtype:attempted-recon; sid:200000165; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"52.139.36.41"; content:"Host"; http_header; classtype:attempted-recon; sid:200000166; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"52.229.94.252"; content:"Host"; http_header; classtype:attempted-recon; sid:200000167; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"52.235.24.152"; content:"Host"; http_header; classtype:attempted-recon; sid:200000168; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"537-pulih.forumz.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200000169; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"54-218-67-64.cprapid.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000170; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"54-245-159-189.cprapid.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000171; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"54.81.240.14"; content:"Host"; http_header; classtype:attempted-recon; sid:200000172; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"5464534654.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000173; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"54olh3ouquem2021.starvillam.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000174; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"55899082.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000175; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"55bgf.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000176; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"5a020n63fc2dr.nuasan.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200000177; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"5b0f6cb9-0485-4fc7-9775-eb74bb45bbf6.htmlcomponentservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000178; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"5bn0j.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000179; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"5co.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000180; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"5pider.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000181; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"5thavegroominglounge.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000182; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"5x.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200000183; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"5x726-alternate.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000184; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"60minutesoffame.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000185; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"627-pembatalan.forumz.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200000186; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"629afe26.orson.website"; content:"Host"; http_header; classtype:attempted-recon; sid:200000187; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"63.240.155.81"; content:"Host"; http_header; classtype:attempted-recon; sid:200000188; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"638ca12d-ba2f-451c-8418-faf56b7de7ff.htmlcomponentservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000189; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"650vm.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000190; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"6525625662.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000191; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"67.205.108.141"; content:"Host"; http_header; classtype:attempted-recon; sid:200000192; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"67deac72043739575.tempsite.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000193; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"68.178.252.133"; content:"Host"; http_header; classtype:attempted-recon; sid:200000194; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"6e33r.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000195; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"728-blocking.forumz.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200000196; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"73906d.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000197; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"74.220.202.158"; content:"Host"; http_header; classtype:attempted-recon; sid:200000198; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"75-119-152-172.cprapid.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000199; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"779zt.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000200; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.108.89.240"; content:"Host"; http_header; classtype:attempted-recon; sid:200000201; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"78.143.96.35"; content:"Host"; http_header; classtype:attempted-recon; sid:200000202; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"7d54v.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000203; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"7d6aed06963830457.temporary.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000204; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"7df8a50b123873451.temporary.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000205; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"7ku50.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000206; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"7wr4u.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000207; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"7yatra.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000208; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"7yu3v.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000209; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"8010361370310234068010361370310234.blogspot.be"; content:"Host"; http_header; classtype:attempted-recon; sid:200000210; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"804signs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000211; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"82.165.27.36"; content:"Host"; http_header; classtype:attempted-recon; sid:200000212; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"87.106.20.236"; content:"Host"; http_header; classtype:attempted-recon; sid:200000213; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"8d07d4571bd4.ngrok.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000214; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"8dw5g.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000215; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"8hsfskj-alternate.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000216; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"8hsfskj.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000217; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"8so.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000218; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"90a6903b-75ff-445e-893e-c69d2807dd96.htmlcomponentservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000219; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"9291588.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000220; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"934354637282-343432.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000221; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"97c8bbe5983862569.temporary.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000222; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"9d62cfee-59b3-42a8-9542-4b3a32692792.htmlcomponentservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000223; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"9khnh.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000224; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"a-a5a5.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000225; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"a0519874.xsph.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000226; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"a0531056.xsph.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000227; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"a1k19.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200000228; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"a37cbe.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000229; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aaekt.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000230; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aalfin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000231; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aanaqa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000232; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aanvraag-abn-amro.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200000233; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aapdshop.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000234; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aarogyamcafe.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000235; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aatkasays.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000236; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ab453bbe-3b65-47cf-9eca-798689d971d5.htmlcomponentservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000237; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"abcexpresslogistics.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000238; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"abcsofia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000239; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"abhijit623461.github.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000240; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"abn-amro-klantenservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000241; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"absaonline2021.website2.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200000242; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"absolute-accessscaffolding.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200000243; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"absolutepleasure.com.my"; content:"Host"; http_header; classtype:attempted-recon; sid:200000244; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"abtekdoor.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000245; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"abundancebythedrop.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000246; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ac-bastion.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000247; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"acc-noic2seguridadicloud.yangsuenhianaja.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000248; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accareindia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000249; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"acce-de.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200000250; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"acce-der.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200000251; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"acceso-endesa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000252; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"access-revoke-app.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000253; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"access.deka-eu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000254; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accessdevice-secure.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200000255; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accesso-protetto-clienti.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000256; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accjh5-iiuyh-kffn.s3-eu-west-1.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000257; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accorservorg.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000258; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"account-netflix.secure-returngov-hm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000259; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"account.fido.validation.information.ssl-truechannel.radyotom.com.tr"; content:"Host"; http_header; classtype:attempted-recon; sid:200000260; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"account.paxful.com.unissenseafrica.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000261; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"account2fa-login.authenticationzone.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000262; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accountbilling-ee-secure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000263; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accountchckecker-update-now.drpiza.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000264; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accountprotection-resetpairing-gb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000265; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accounts-google-sign-in.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000266; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accounts-login-telekom.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000267; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accounts-newpayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000268; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accounts.paxful-security.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000269; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accounts.paxful.com.bitsope.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000270; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accounts.paxful.com.paxful-security.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000271; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accounts.paxful.com.unissenseafrica.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000272; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accountspecialist.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200000273; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accountupdate.support"; content:"Host"; http_header; classtype:attempted-recon; sid:200000274; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accout-update-check-my-jcb-co-jp.bcbnh.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000275; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accout-update-check-my-jcb-co-jp.cnzhb.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000276; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accout-update-check-my-jcb-co-jp.db048j.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000277; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accout-update-check-my-jcb-co-jp.di208d.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000278; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accout-update-check-my-jcb-co-jp.fkvykdkql.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000279; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accout-update-check-my-jcb-co-jp.gu4c6s.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000280; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accout-update-check-my-jcb-co-jp.gu872a.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000281; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"acczrty8-ikiuy-yoo.s3-eu-west-1.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000282; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"acessobbauto.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000283; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"acessobradesco.digital"; content:"Host"; http_header; classtype:attempted-recon; sid:200000284; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"achatventelbcoinacess.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000285; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"acm1.eimae.iwc.static.c11n.topconcepthk.com.hk"; content:"Host"; http_header; classtype:attempted-recon; sid:200000286; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"acoustic.how-toplayguitar-today.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000287; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"actionfilmz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000288; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"activar.tus.transferencias.en.linea.viabcp.com.pe.vendum.ro"; content:"Host"; http_header; classtype:attempted-recon; sid:200000289; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"active-page-term-dashboard-advanced.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200000290; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"active-page-term-dashboard-inc.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200000291; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"actualizacionesmovilesenlinea-viabcpbeta.atschihuahua.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000292; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"actualizarplanilla.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200000293; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"acumulandoponto.myddns.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200000294; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"acupuncture-easily.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000295; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"adads.agrometalfrio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000296; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"adamfeber.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000297; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"added-new-payees.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000298; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"addidasnike20202021.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000299; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"adeliken.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000300; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"adfee.com.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200000301; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"adidas-mx.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200000302; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"adjustbeard.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000303; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"admak.qa"; content:"Host"; http_header; classtype:attempted-recon; sid:200000304; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.baragor.se"; content:"Host"; http_header; classtype:attempted-recon; sid:200000305; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.casa.it.happyhouseitalia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000306; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"admin.ipaoo.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200000307; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"adminivericentrics.wapka.website"; content:"Host"; http_header; classtype:attempted-recon; sid:200000308; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"adminssilologin.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000309; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"adnet8.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000310; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"adporbe.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200000311; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"adpunemploymentclaims.sharefile.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000312; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"adscouponaccountscampaign.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000313; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"advance-verify-secure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000314; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"advancedlearningdynamics.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000315; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"adx-exchancesegu2bn-gibcx.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000316; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aecbank.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000317; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aenth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000318; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aero-flot.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000319; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aero-flot.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200000320; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"affiece-45.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000321; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"affordablesignguys.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000322; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"afiliacionvirtualcrfi.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000323; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"afinephotographer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000324; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agatebo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000325; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agence-orange-receptions.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000326; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agenciadigitalsur.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200000327; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agendabeliving.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000328; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agendatebancofalabella.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000329; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agent-casar-update.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000330; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agent.joinf.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000331; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aggiornacontobn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000332; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aglimmer-laundry.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000333; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agri-depart-region.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000334; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agri72.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200000335; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agri85.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200000336; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agrimetiersmartinique.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200000337; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agrofile.ir"; content:"Host"; http_header; classtype:attempted-recon; sid:200000338; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agrology-electrodialysis.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000339; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agrostarauto.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000340; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agrothesis.ir"; content:"Host"; http_header; classtype:attempted-recon; sid:200000341; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agsitesreis.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000342; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ah.com.ge"; content:"Host"; http_header; classtype:attempted-recon; sid:200000343; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ahcacademy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000344; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ahmeddawod.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000345; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aibbankings.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000346; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aibpayeenewservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000347; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aibroiservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000348; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimazon.34va9cd2w56y.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000349; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimazon.bv5qx71lmr9je.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000350; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimazon.co-jp-8avhup6brqzm.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000351; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimazon.co-jp-ih791ndygpzt.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000352; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimazon.co-jp-iheo3cp64fv2.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000353; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimazon.co-jp-k1w74lr6u3jg.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000354; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimazon.co-jp-kau45iqf2b9w.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000355; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimazon.e83lqy71j9g4.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000356; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimazon.gxrklj64pzqa.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000357; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimazon.hse59tdc64f3.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000358; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimozan.co-jp-amonzaonamzoan.icu"; content:"Host"; http_header; classtype:attempted-recon; sid:200000359; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimozan.co-jp-aziamzoaznom.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000360; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimtex.pk"; content:"Host"; http_header; classtype:attempted-recon; sid:200000361; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aimzoan.co-jp-azmiazonm.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000362; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"airbnb.es.listing-rent-16111122335-booking.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200000363; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aishwaryainteriors.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200000364; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"akmsystems.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000365; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aksesbisnes.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000366; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"akshartours.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000367; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aksoydanismanlik.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000368; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aktuen.co.jp.japanmy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000369; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aladdinstar.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000370; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alamdi.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000371; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alangwadinma.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000372; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alareentading-catalog.page.tl"; content:"Host"; http_header; classtype:attempted-recon; sid:200000373; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alaskanmalamute.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200000374; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"albel.intnet.mu"; content:"Host"; http_header; classtype:attempted-recon; sid:200000375; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alcesterstatebank.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000376; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alealtaseguros.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000377; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alergiaalpolen.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000378; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alert-payee-delete.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000379; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alerta-interbank.personas-bienvenido.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000380; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alertedpayeeinfo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000381; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alerts-for-lloyds-bank.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000382; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alerts-payee-new.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000383; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alessandromari.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000384; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alex-diplom.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000385; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alexgarrido.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000386; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alfaindustrials.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200000387; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alfrescocomforts.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000388; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"algamedia.es"; content:"Host"; http_header; classtype:attempted-recon; sid:200000389; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"algoass.co.za"; content:"Host"; http_header; classtype:attempted-recon; sid:200000390; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"algotextil.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000391; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alhajajy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000392; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aliah.ac.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200000393; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alicetruecolors.com.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200000394; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aliciabot.azurewebsites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000395; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alienfoodedibles.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000396; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alimajed1.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000397; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alinhador3d.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000398; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alkawaterdiy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000399; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"allegro-pl-7e2a33.ingress-daribow.easywp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000400; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"allegrosmart.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000401; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"allenhgm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000402; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alliance4consumersusa.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000403; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"allstarlax.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000404; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alpha-lam.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000405; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alpha-mail-server2.ddns.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200000406; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alpinemountaingear.com.np"; content:"Host"; http_header; classtype:attempted-recon; sid:200000407; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alpineridgefinancial.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000408; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alquileres.com.py"; content:"Host"; http_header; classtype:attempted-recon; sid:200000409; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alquilervillora.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000410; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alreaaiaa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000411; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alternatifklinik.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000412; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alumdecor.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000413; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aluna.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200000414; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amaaz0n-c0-jp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000415; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amakuzon-check-co-jp.ninemax2103.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000416; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amakuzon-check-co-jp.ninemax2104.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000417; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amakuzon.co-jp.skyrim2303.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000418; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amakuzon.co-jp.skyrim2304.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000419; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amakuzon.zhhaygpfvfwqewzq.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000420; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amamamnazon.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000421; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amaozn.co.jp.ytbfq.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000422; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amaxcarrentals.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200000423; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazenno.vevbmse.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000424; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazom.jp.hshbnq.bar"; content:"Host"; http_header; classtype:attempted-recon; sid:200000425; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.b7f.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000426; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.b8n.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000427; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.c5j.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000428; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.d7v.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000429; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.d8e.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000430; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.f3m.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000431; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.g4h.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000432; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.g4w.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000433; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.i4h.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000434; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.j5v.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000435; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.j9c.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000436; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.l4a.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000437; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.n5h.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000438; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.n6m.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000439; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.q3p.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000440; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.q5x.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000441; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.r2e.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000442; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.s6y.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000443; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.u6j.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000444; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.u7n.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000445; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.u7o.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000446; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.v4s.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000447; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.w7p.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000448; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.x8g.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000449; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.y5r.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000450; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-co-jp.ljmaoyg.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000451; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-company.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200000452; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-gcatech.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000453; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-id-safety-center-signin-openid-page-max-infomation.gpgqyf.bar"; content:"Host"; http_header; classtype:attempted-recon; sid:200000454; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-id-safety-center-signin-openid-page-max-infomation.jgbyly.bar"; content:"Host"; http_header; classtype:attempted-recon; sid:200000455; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-id-safety-center-signin-openid-page-max-infomation.josgws.bar"; content:"Host"; http_header; classtype:attempted-recon; sid:200000456; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-id-safety-center-signin-openid-page-max-infomation.jzuwjw.bar"; content:"Host"; http_header; classtype:attempted-recon; sid:200000457; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-id-safety-center-signin-openid-page-max-infomation.rxxvpu.bar"; content:"Host"; http_header; classtype:attempted-recon; sid:200000458; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-tokyoj.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200000459; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.co-jp-aiizmoanm.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000460; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.co-jp-aizmanoanm.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000461; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.co-jp-aizmnoanm.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000462; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.co-jp-aozimanoan.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000463; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.co-jp-azimanoanm.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000464; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.co-jp-azmoan.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000465; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.co-jp-info.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200000466; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.co.jp.cmcbeauty.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000467; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.co.jp.shjqsan.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000468; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.co.jp.twq56.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000469; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.de.signin.verification.openid.5935156.globthirsgare.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200000470; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.fsddjc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000471; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.gunzejp.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000472; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.shaibsjjjwnmpjyguiiopo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000473; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon.update.njwbyx.rest"; content:"Host"; http_header; classtype:attempted-recon; sid:200000474; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazoncomjpgvheqowri.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000475; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazonhelp02.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000476; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazonjpcougyefkjsdyuernb.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000477; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazonlogistics-ap-northeast-1.amazonlogistics.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200000478; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazoon.jkrmxkoqmnxlqsfgh.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000479; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazouo-jp.zlmfeia.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000480; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazovpsee.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000481; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ambientaris.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000482; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ambienteprotegido.foregon.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000483; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ambills.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000484; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ameinvoice.vn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000485; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ameport.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000486; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"americanarza.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000487; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amguevara.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000488; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ami-manera.es"; content:"Host"; http_header; classtype:attempted-recon; sid:200000489; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amidabuli.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000490; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amiozanm.co-jp-azomiazmoznozanmazon.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000491; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amizoan.co-jp-aiozmiazonam.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000492; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amizoan.co-jp-aizmiazonam.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000493; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ammazonams.temp.swtest.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000494; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ammoniagold.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000495; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amnbyn.online"; content:"Host"; http_header; classtype:attempted-recon; sid:200000496; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amosleh.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000497; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amozanm-rrbrb.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200000498; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amozanm-rrere.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200000499; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ams-eg.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000500; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amtazon.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200000501; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amzn-secureteam.ddns.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000502; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amzoneozoierngviooer.poerlaamaopirnreoizxiocx.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200000503; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anarchitecturestudio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000504; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anatomyofselling.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000505; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anatran.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200000506; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anazon.co.jp.mxcdfa.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000507; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anazon.co.jp.zzweiyu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000508; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anbf.adv.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000509; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anchovyhighschool.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000510; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"andares.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000511; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"andersonstrategic.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200000512; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"andinorealestate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000513; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"andreasales.mybigcommerce.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000514; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"andrewcarr.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000515; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"andromedaassociation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000516; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"angebote-d15b5db6a5f2.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000517; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"angiemaymiller.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000518; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"angiemaymiller.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000519; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anglo-fan.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000520; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"angularjs-qgoay2.stackblitz.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000521; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"animalrescue.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200000522; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"animalwelfareinc.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000523; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anjoe.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000524; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ankama-prize.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000525; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ankama-store.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000526; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anpront-noice-amoeomn.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200000527; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"antaresns.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000528; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anthonyajohnson.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000529; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anthonz.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000530; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"antiguatabernaqueirolo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000531; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"antrorse-searches.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000532; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anu-nsti-moo.s3-eu-west-1.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000533; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anzteam.support"; content:"Host"; http_header; classtype:attempted-recon; sid:200000534; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aparicio.website"; content:"Host"; http_header; classtype:attempted-recon; sid:200000535; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"apesigam.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000536; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.alqadam.uz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000537; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"api.stasto.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200000538; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aplist2021.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000539; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"apoga.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000540; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"app-dec-access.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000541; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"app-indmillenium.3utilities.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000542; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"app-list-82059.casa"; content:"Host"; http_header; classtype:attempted-recon; sid:200000543; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"app-manage-requests.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000544; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"app-onlinemobileappsecurehalifacxappsecure.mrtraveller.ir"; content:"Host"; http_header; classtype:attempted-recon; sid:200000545; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.ganoexcelcambodiaclinic.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000546; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"app.surveymethods.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000547; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"app28.greenmail.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200000548; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"apparats.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000549; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"appatualizecef.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000550; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"appieid.us.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000551; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"apple-paybillingdetails.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000552; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"appleid.apple.com.ac-count.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200000553; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"appleid.apple.com.iqf331.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000554; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"appleid.apple.com.nvw5q.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000555; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"appleid.apple.com.vhee33.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000556; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"appleid.locationinfo.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000557; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"appleid.xivxb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000558; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"appleid.xivxc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000559; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"appleld.appleint.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000560; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"applepaymentpartner.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000561; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"applepoem.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000562; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"applewriters.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000563; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"appmiseajourconnectfromagenceregionnalconnect.u977365cx7.ha005.t.justns.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000564; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"apporg.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000565; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"apptan-aktivierung.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200000566; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"appupdatesecurehalifaxonlineappupdate-verification.empastesanabalon.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200000567; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"apreciapharma.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200000568; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aprescountds.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000569; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aprescountsg.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000570; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aqtv.tv"; content:"Host"; http_header; classtype:attempted-recon; sid:200000571; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aquisempretemhoje.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000572; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aracebrasil.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200000573; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arambadaowoojeo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000574; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arcadewatch.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000575; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arcd2-tgfe-yhbgg.s3-eu-west-1.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000576; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"archost.net.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200000577; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arcomindia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000578; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ardatrzm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000579; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"areaclienti-sella.gdrappresentanza.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200000580; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"argaautorepair.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000581; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"argenahomebanqbe.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000582; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"argus-garage-doors-repair.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000583; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arigalvanizados.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200000584; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arigo.ng"; content:"Host"; http_header; classtype:attempted-recon; sid:200000585; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arimanurung.skom.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200000586; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arislm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000587; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arleiti.sslblindado.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000588; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arm79875.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000589; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"armata-neagra.ro"; content:"Host"; http_header; classtype:attempted-recon; sid:200000590; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arnaoone.co.ip.vzvacoe.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000591; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arnazon-update-account.kwxdyk.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000592; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arnazoon.co.jp.vjhsfxc.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000593; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aromatic.webenliven.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200000594; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arrow.kvalitne.cz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000595; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arrowcase.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000596; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arslanlogistics.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000597; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"artdecorstudio.ro"; content:"Host"; http_header; classtype:attempted-recon; sid:200000598; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"artekcamp.tumblr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000599; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"artfullyrestless.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000600; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arthatmco.fun"; content:"Host"; http_header; classtype:attempted-recon; sid:200000601; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"articles.investing-fund.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000602; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"artsuperstar.tv"; content:"Host"; http_header; classtype:attempted-recon; sid:200000603; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"arubadominio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000604; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ascent-scaffolding.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200000605; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"asdsadf.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000606; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ash14213.mfs.gg"; content:"Host"; http_header; classtype:attempted-recon; sid:200000607; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"asiadiscoversolutions.azureedge.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000608; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"asiastarchsolutions.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000609; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"askalaney.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000610; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"askarmotorluaraclar.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000611; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"asorange.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200000612; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"asp403r.paperless.com.pe"; content:"Host"; http_header; classtype:attempted-recon; sid:200000613; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"assawomanva.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000614; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"assessoria-finan.webnode.pt"; content:"Host"; http_header; classtype:attempted-recon; sid:200000615; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"assets.cdnxz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000616; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"assistance-le-boncoin.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000617; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"assistenzaintesaonline.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000618; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"assnat.cm"; content:"Host"; http_header; classtype:attempted-recon; sid:200000619; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"astronmic.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200000620; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"atelieadrika.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000621; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"atendimentoltau24hrs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000622; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"atillasample.ir"; content:"Host"; http_header; classtype:attempted-recon; sid:200000623; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ativacao-online73681.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000624; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"atomicalchemy.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200000625; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"att.guide"; content:"Host"; http_header; classtype:attempted-recon; sid:200000626; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"att_t1.godaddysites.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000627; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"attconfi.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000628; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"attemplate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000629; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"attempt-redelivery-mail.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000630; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"attemptedloginverify-hali.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000631; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"attendance.philpowercorp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000632; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"attmarchserviceupgrade.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000633; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"attmsverificationmail.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000634; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"attne.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000635; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"attnet4.aidaform.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000636; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"attnett.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000637; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"attpanel.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200000638; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"attreactivatemailingconnect787373hsbdc3337789893ff78.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000639; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"atttnois.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000640; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"attyahooemailcustomerupdateservices.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000641; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"attyahooupgrade.webflow.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000642; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"atu685.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200000643; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"atualizacao-online547864.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000644; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"atualizaonline2533.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000645; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"atualizarcartao.kinghost.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000646; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aubootlegger.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000647; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aucoindesrues.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000648; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"audioprobootcamp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000649; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"auditmessages.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000650; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"auriane-facebook.surge.sh"; content:"Host"; http_header; classtype:attempted-recon; sid:200000651; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aushotel.es"; content:"Host"; http_header; classtype:attempted-recon; sid:200000652; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aut0problemsamazon.servequake.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000653; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"auth-cancel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000654; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"auth-verifypostage.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000655; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"auth-via-cancellation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000656; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"auth.friparts.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000657; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"authboxncbkpaquymmailssocl.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000658; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"authcli630-webmail-cloud401.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000659; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"authdevice-secure.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200000660; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"authentic.device-uk.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200000661; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"authenticate-secure.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200000662; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"authenticottawavalley.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200000663; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"authorcheck.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000664; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"authorisemyregistereddevice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000665; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"authorisemytransfer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000666; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"authorisetransfer-online.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000667; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"auto24.email"; content:"Host"; http_header; classtype:attempted-recon; sid:200000668; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"autoamzn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000669; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"autoatendimento.caixaresidencial.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000670; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"autodiscover.gre.ac.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200000671; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"autodiscover.ryder-dutton.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200000672; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"autodiscover.sandrsecurity.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000673; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"autopecaonline.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000674; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"autorizador5.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000675; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"autoscurt24.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200000676; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"autosource.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200000677; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"autosrobadoschile.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000678; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"avadvertising.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200000679; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"avestafinance.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000680; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aviapoisk.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000681; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"avioni.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000682; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"avtoban-service.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000683; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"avtovokzal24.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000684; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"awl.li"; content:"Host"; http_header; classtype:attempted-recon; sid:200000685; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"awptdh.webwave.dev"; content:"Host"; http_header; classtype:attempted-recon; sid:200000686; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"axinaux.nepware.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000687; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"axxp3-hhee-jihbn.s3-eu-west-1.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000688; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ayaproperty.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000689; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ayjegvgm.livedrive.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000690; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"azimuth.vip"; content:"Host"; http_header; classtype:attempted-recon; sid:200000691; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"azosimoveis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000692; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"azurefetcherstorage.blob.core.windows.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000693; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"b-pembatalan.forumz.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200000694; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"b2bchdistribution.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000695; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"b4xe1.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000696; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"b55qf.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000697; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"baanvitaminsea.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000698; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"baccredomatic.crowdicity.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000699; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bacencaixadigital.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000700; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"backnote.notelet.so"; content:"Host"; http_header; classtype:attempted-recon; sid:200000701; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"backtthisowlong.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000702; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"badge-helpers.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200000703; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bakerrecklaw.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000704; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"balitransithotel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000705; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ballincollege.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000706; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"balloonexperienceholland.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200000707; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bamboobypanda.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000708; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"banca-montpaschidisiena.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000709; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bancaporinternet-netinterbankpe11.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000710; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bancaporinternetsit.interbank.pe"; content:"Host"; http_header; classtype:attempted-recon; sid:200000711; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bancodecomercio.elegroup.com.pe"; content:"Host"; http_header; classtype:attempted-recon; sid:200000712; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bancogaliicia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000713; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bancoiing.site44.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000714; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bancoiinng.site44.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000715; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bancomercantil-org.haxsecurity.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000716; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bangbuzz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200000717; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bank-of-america-secure00.dns05.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000718; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bank-project.surge.sh"; content:"Host"; http_header; classtype:attempted-recon; sid:200000719; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bankia-es.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000720; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"banking.de-id1877au901501fj82ca7fnas9basssdfhswhboa802bauc248naxx.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000721; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"banking.sparkasse.de-id1877au901501fj82a7fn3a54dx2gsboac8s02bauc248naxx.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000722; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"banking.sparkasse.de-id1877au901501fj82a7fna329bhcwhboac8vs02bauc248naxx.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000723; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bankingitaucard.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000724; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bankingportal03.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000725; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bannerb.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000726; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"banreservasdigital.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000727; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"baradua.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200000728; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"barbourone9.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000729; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"baseballforbid.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000730; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"baseilictreivnoicernrt7.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200000731; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"basement2billionaire.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000732; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"batterybazaaronline.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000733; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"baycrane.mobi"; content:"Host"; http_header; classtype:attempted-recon; sid:200000734; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bbatualizaapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000735; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bbcartoes.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000736; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bbsuporteacesso24horas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000737; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bbysolutions.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000738; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bc1.paiementervice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000739; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcolomb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000740; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcp.futbolfinanciero.com.pe"; content:"Host"; http_header; classtype:attempted-recon; sid:200000741; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcparepare.beacukai.go.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200000742; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcpsonasegurabeta-viabcp.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200000743; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcpzonasegurasbetas.cndigisol.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000744; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcpzonsegurabeta-vlabcp-com.cruoaicr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000745; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bdlands.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000746; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"beansbulletsbandagesandyou.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000747; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"beastflexfitness.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000748; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"beaverwood-benzotriazine.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000749; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"beelightfood.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000750; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bei-sweden.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000751; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"belasouthernertt.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000752; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"belekinas023.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000753; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"benamejicityofbaseball.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000754; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"benenergie-dz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000755; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"benficiary-comfirmation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000756; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"benjim.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000757; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bepostreportissues15.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000758; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ber-vel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000759; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"berrybluefarms.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000760; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bertges.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000761; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bestchange.freelancers.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200000762; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bestchanged.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000763; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bestdailynews.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000764; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bestfive.main.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200000765; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"besthomeworkhelp.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000766; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bestofdance.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000767; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bet.travel"; content:"Host"; http_header; classtype:attempted-recon; sid:200000768; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betqiuqiu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000769; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betterbacktogether.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000770; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betterbodynet.acemlnc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000771; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bex.freefire682.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200000772; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bexwebmailupdate.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000773; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bezorging.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000774; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bg1s.byethost7.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000775; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bg7t.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000776; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bgms.cit.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000777; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bh068.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000778; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"biblio-emi.md"; content:"Host"; http_header; classtype:attempted-recon; sid:200000779; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bibliotecabayer.org.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200000780; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bibwebshop.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000781; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bicicentroslezama.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000782; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bikes-marketplace-item.billabonghighrewa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000783; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"billing-error-problem47.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000784; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"billing-errorhelp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000785; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"billing-gb-update.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000786; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"billing-information-ee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000787; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"billingfailure-o2.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000788; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"billingo2auth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000789; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"billiob.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200000790; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bimdur.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000791; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bimkelo0.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000792; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"binance-china.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000793; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"binarybenliveload.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000794; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bingoshop.rs"; content:"Host"; http_header; classtype:attempted-recon; sid:200000795; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"biocurerx.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000796; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"biquyetcongai.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000797; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bir365.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000798; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bitcoin495.vip"; content:"Host"; http_header; classtype:attempted-recon; sid:200000799; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bitpanda-exchange-wallet.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000800; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"biventf.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000801; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blancstaging.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000802; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bliiss.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200000803; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blinusa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000804; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blissfulhomeng.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000805; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blockchain-policy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000806; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blocks.rn86.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000807; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.cellprofiler.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000808; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.cotiabank.paypal-login.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200000809; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.powerlexis.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000810; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.premiershop.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000811; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.srinathenterprises.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200000812; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blog.weiwanjia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000813; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blok-faceboook.mypi.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200000814; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bloomb2b.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000815; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bloquenegro.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200000816; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blubrown.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000817; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bluefish-digital.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000818; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blueteak.0fees.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200000819; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blusyne.lt"; content:"Host"; http_header; classtype:attempted-recon; sid:200000820; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bmbhartischool.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000821; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bmvorai.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000822; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bmw1.mypets.ws"; content:"Host"; http_header; classtype:attempted-recon; sid:200000823; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bncontactodigital1.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000824; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bncontactodigitalbncrficr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000825; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bo.zaixy117.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200000826; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bogdonovlerer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000827; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"boggze.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000828; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"boiclub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000829; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bokep-xnxx7.jkub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000830; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bokepress2020.dns2.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200000831; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bokepwhatsapp01.ezua.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000832; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"boletimdo2.sslblindado.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000833; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bolicarp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000834; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bolong3d.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000835; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"boma-ren.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000836; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bonds-oldschools-runescapes.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000837; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bonuscenter-us.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000838; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bonyansoole.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000839; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bookersbridge.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000840; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bookfbs.evangsamuelministries.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000841; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"booking.darkhotel.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200000842; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"booysensnsons.co.za"; content:"Host"; http_header; classtype:attempted-recon; sid:200000843; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bosnewpaye.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000844; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bottsproperties.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000845; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"box.royal-eng.ps"; content:"Host"; http_header; classtype:attempted-recon; sid:200000846; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"boxdelivery.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000847; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bpl.kr"; content:"Host"; http_header; classtype:attempted-recon; sid:200000848; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bpmca.eatlbd.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000849; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"br4.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200000850; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"br622.teste.website"; content:"Host"; http_header; classtype:attempted-recon; sid:200000851; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bracefox.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000852; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brasilgraf.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000853; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"breakevents.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200000854; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"breakingthelimits.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000855; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bredbanque--email.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000856; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bredconnect-fr.surge.sh"; content:"Host"; http_header; classtype:attempted-recon; sid:200000857; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brigida_cossette.gitlab.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000858; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"broguish-pointer.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000859; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brooks-polska.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000860; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brooks-sneakers.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200000861; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brooks-turkiye.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000862; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brookscanadashoes.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200000863; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brookschuhesale.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200000864; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brooksitalia.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200000865; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brooksrebajas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000866; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brooksrunning-shoes.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200000867; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brooksrunningsg.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000868; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brooksrunningshoes.us.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000869; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brooksrunningshoesoutlet.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200000870; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brooksshoesuk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000871; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brookssouthafrica.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000872; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"broomesoho.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200000873; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brudesh.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000874; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brunoalmeidanet.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000875; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bruor.by"; content:"Host"; http_header; classtype:attempted-recon; sid:200000876; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brusselsarport.be"; content:"Host"; http_header; classtype:attempted-recon; sid:200000877; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bruxellons.be"; content:"Host"; http_header; classtype:attempted-recon; sid:200000878; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bsdsv-trfgt-yhnbv.s3-eu-west-1.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000879; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bsjdigital.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000880; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bss.edu.ge"; content:"Host"; http_header; classtype:attempted-recon; sid:200000881; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bt-billing.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200000882; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bt-broadband.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000883; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bt-service.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000884; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"btbusinessbill.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000885; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"btccmx.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000886; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"btcerath.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000887; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"btcloudworkvoicemessage.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000888; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"btinternetwebsite.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000889; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"btmaila.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000890; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"buildingtradesnetwork.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000891; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bujikena.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000892; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"busanopen.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000893; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"businessandfootball.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000894; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"businesspolicy.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200000895; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"buycrystalmeth.se"; content:"Host"; http_header; classtype:attempted-recon; sid:200000896; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"buyelectronicsnyc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000897; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"buysuplldufomf.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000898; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"buzzgraphics.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000899; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bvbahealthypharmacy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000900; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bwplusburaidah.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000901; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bwpremierlagrande.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000902; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bxb.gr"; content:"Host"; http_header; classtype:attempted-recon; sid:200000903; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"byoko.co.kr"; content:"Host"; http_header; classtype:attempted-recon; sid:200000904; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"byygw.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000905; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bzqnlhz.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200000906; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bzrider.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000907; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"c-om.be"; content:"Host"; http_header; classtype:attempted-recon; sid:200000908; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"c-om.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200000909; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"c00.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200000910; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"c1christine.tjelmeland2e.cso.gov.tt"; content:"Host"; http_header; classtype:attempted-recon; sid:200000911; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"c5lws.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000912; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"c6ebl792.caspio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000913; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"c6ebv708.caspio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000914; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"c985-endesa-vente-en-ligne.wbc-prod.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000915; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cache.nebula.phx3.secureserver.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000916; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cadacosaalseulloc.cresidusvo.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200000917; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cadastrosportal.epizy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000918; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"caf-mobile.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000919; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cakebox.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200000920; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cakesbyannemotha.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000921; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"calzadosiris.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000922; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"camaieufr.commander1.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000923; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"camerasulphur.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000924; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cancels-payee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000925; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"canlisohbetlerde.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000926; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cannellandcoflooring.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200000927; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cannes-encheres.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000928; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cantarinobrasileiro.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000929; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"capernaitical-cuckoomaid.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000930; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"capholeful1978.blogspot.be"; content:"Host"; http_header; classtype:attempted-recon; sid:200000931; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"capservice.online"; content:"Host"; http_header; classtype:attempted-recon; sid:200000932; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cararticle0033.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000933; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cardano-wallet.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000934; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"carestar-doccc.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200000935; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"careycapital.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000936; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"carrefour.googie.casa"; content:"Host"; http_header; classtype:attempted-recon; sid:200000937; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"carrfour-org.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200000938; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"carsten.boennen.continentalwingates.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000939; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"carte.impotsfrancesecurite.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200000940; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"carwash.tv"; content:"Host"; http_header; classtype:attempted-recon; sid:200000941; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"casamezquita.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200000942; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"casaverdeatelie.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000943; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"caserly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000944; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"caseyarchitecturallighting.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000945; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cashflowfxonline.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000946; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"casosapple.com-verificacionapple.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000947; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"castennisacademy.be"; content:"Host"; http_header; classtype:attempted-recon; sid:200000948; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cateroo.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200000949; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"causechimney.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000950; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"caycos.beispielseite-wmka.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200000951; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cbgerritsen.nl"; content:"Host"; http_header; classtype:attempted-recon; sid:200000952; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cbjets.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000953; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cce4dc4609ad.ngrok.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000954; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ccjrlaw.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000955; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cdek-pay.ru.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000956; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cdvlab.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000957; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ce442ac57e3849333.temporary.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000958; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cebuphonly.jrzoutsourcingservices.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000959; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cecieee.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200000960; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cedarcp.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200000961; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cefwebchat.chatbsservices.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000962; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cel.resgmultiplus.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000963; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"celebrations-cew.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000964; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"celesteohrganica.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000965; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cellidplus.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000966; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cema-fossano.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200000967; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"centec-am.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000968; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"center-verificationw.wapka.website"; content:"Host"; http_header; classtype:attempted-recon; sid:200000969; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"centerai.vot.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200000970; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"centericmailinwebs.wapka.website"; content:"Host"; http_header; classtype:attempted-recon; sid:200000971; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"centerprotectuser-argentina.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000972; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"centralconsulta.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200000973; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"centraleconsulta.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000974; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"centre1.bubbleapps.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000975; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"centriccenteradmin.wapka.website"; content:"Host"; http_header; classtype:attempted-recon; sid:200000976; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"centricorreoweb.wapka.website"; content:"Host"; http_header; classtype:attempted-recon; sid:200000977; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"centroassistenzaptapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000978; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"centroocular.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200000979; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"centruldepiele.ro"; content:"Host"; http_header; classtype:attempted-recon; sid:200000980; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"certicobanque.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200000981; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"certifica-appweb.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000982; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"certifica-montepaschii.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000983; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"certifica-sicurezza.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000984; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"certifiedearthlinke-mail.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000985; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"certifiedsalty.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000986; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cew.safewallet.replayattack.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200000987; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cf50l.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200000988; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cg-oe.snprobbx.pbz.r.de.a2ip.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000989; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cg00737-wordpress-2.tw1.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000990; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cg58234.tmweb.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000991; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cg6.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200000992; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cg94870.tmweb.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000993; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ch.marketing-gentleman.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200000994; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ch.net2care.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000995; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ch.prunauneau.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200000996; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ch.tcorner.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200000997; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ch10977.tmweb.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200000998; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"change-policies-41234.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200000999; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"charalabosdiamandis-plus.cloudaccess.host"; content:"Host"; http_header; classtype:attempted-recon; sid:200001000; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"charl.americommerce.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001001; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"charly-design.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200001002; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"charperimagedesign.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001003; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chase-payeesecure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001004; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chase.th.patricepurnell.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001005; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chat-whatasapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001006; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chat-whatsapp.click"; content:"Host"; http_header; classtype:attempted-recon; sid:200001007; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chat-whatsapp.doctorhaddadpediatriayflores.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001008; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chat-whatsapp.live18now.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001009; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chat-whatsapp.vizvaz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001010; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chat-whatsapp8jhvztulp7ajofk9jua3jfij4.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001011; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chat-whatsapp8jhvztulp7ajofk9jua3jfloi2.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001012; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chat-whatsapp8jhvztulp7ajofk9jua3jfloi5.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001013; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chat-whatsappgrupjoinbokepweb.zzux.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001014; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chatgrup.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001015; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chaturbate-videos-free.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001016; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chatwhatsapp.diamonffgratiss.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200001017; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chatwhatsappgroups11.otzo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001018; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chatwhatsappgrupbokep.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001019; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chaussuredrmartenss.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200001020; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"check-newpayee-halfax.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001021; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"check.amazon-sbver.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200001022; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"checking-my-account.mixh.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200001023; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"checkvk.hop.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001024; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chellean-entrapment.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001025; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chevreriepierrealaya.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200001026; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chfrichmond-orrgg.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200001027; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chiarabernardi.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200001028; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chileanylgroup.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001029; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chilejubila.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001030; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chirpme.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001031; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chirurgie-estetica.md"; content:"Host"; http_header; classtype:attempted-recon; sid:200001032; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chitterlings.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001033; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"choicefranchiseadvisors.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001034; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chregetioper.flywheelsites.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001035; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"christianpay.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001036; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chrisyapi.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001037; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chungcuvinhomessmartcity.com.vn"; content:"Host"; http_header; classtype:attempted-recon; sid:200001038; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"chuyennghiep.vn"; content:"Host"; http_header; classtype:attempted-recon; sid:200001039; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cibalvo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001040; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ciet-itac.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200001041; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cimeriletisimmerkez.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200001042; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cincinnatl-test.ebpages.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001043; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cingular-oac.qpass.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001044; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"citaenlineacr.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200001045; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"city-of-jazz.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200001046; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"citycouncil-refund.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001047; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cityoflondonchauffeurdrive.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001048; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"civilengineerssydney.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200001049; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"civilthesis.ir"; content:"Host"; http_header; classtype:attempted-recon; sid:200001050; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ckmadae.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001051; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cla2020gov.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001052; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"claim-irs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001053; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"claimeventpubgmobile.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001054; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"claimskin.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001055; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"clarkdd-clarkdd.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200001056; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"clarkdd.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001057; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"claro-controle-downloader.m4u.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001058; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"claus.bz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001059; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cleanupcongresspac.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001060; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"clearstageconsulting.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001061; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"clearviewpartners.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001062; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"clevercarrepairs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001063; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"click-radar.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001064; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"click.dealmode.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200001065; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"click.em32dat.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200001066; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"click.enignite.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200001067; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"clickloginpage.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001068; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"clients.devtux.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001069; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"clientweb03.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001070; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"climiyers.cloudaccess.host"; content:"Host"; http_header; classtype:attempted-recon; sid:200001071; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"clinicasaudearo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001072; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cliniqtec.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001073; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cloud-one-drive.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001074; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cloud1.directnutrisciences.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001075; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cloud102.hostgator.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001076; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"clouddoc-authorize.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001077; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"clt1234529.bmetrack.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001078; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"clubeamigosdopedrosegundo.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001079; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cmies.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200001080; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cn28538.tmweb.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001081; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cnl.snprobbx.pbz.r.de.a2ip.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001082; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"coalcoman.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001083; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cocovip.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001084; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"codashop-ph2020.ezua.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001085; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"codashop99.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001086; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"codeblue.ch.net2care.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001087; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"coinly.cz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001088; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"col-maten.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200001089; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"colloidalsilverone.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001090; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"colorfastinv.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001091; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"colorworxonline.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001092; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"columbus.shortest-route.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001093; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"com.ghasalah.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001094; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"comboniane.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001095; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"comcast-upgrade-com.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001096; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"comfimin.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200001097; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"comigocombr.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001098; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"community.shrm.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001099; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"comp-wood.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001100; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"companys-19916456897312565230053.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001101; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"companys-19916456897312565230055.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001102; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"complaint-vk.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001103; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"completedki.com.healthinsurez.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001104; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"compliance-central.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001105; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"composito.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001106; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"comprensivomarrosso.edu.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200001107; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"compte-orange10.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001108; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"comunicazioniarubait.tumblr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001109; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"con-firma.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001110; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confidentspiritequestrian.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001111; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"configuration-infos.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001112; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confirm-facebook-6534185723.maak.org.mk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001113; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confirm-my-devices.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001114; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confirm-my-newpayments.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001115; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confirm-mynew-payments.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001116; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confirm-mynew-tranfers.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001117; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confirm-mynew-transactions.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001118; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confirm-newpayments.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001119; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confirm-your-new-payee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001120; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confirmati.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001121; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confirmation-paiement-paypal1.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001122; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confirmauthentication.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001123; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confirmclpostingdetails.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200001124; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confirmdados.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001125; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confirming-page-detect-recover.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200001126; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"confmation-pages.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200001127; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"congeprosas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001128; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"congresosba.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200001129; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"constructoravallereal.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001130; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"construtoraeas.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001131; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"consultbasirah.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001132; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"consulthip.biz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001133; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"consulting-gvg.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001134; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"consultorias.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001135; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"contact-ebay.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001136; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"contapessoal.digital"; content:"Host"; http_header; classtype:attempted-recon; sid:200001137; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"contarv.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001138; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"content43532522.texservis.su"; content:"Host"; http_header; classtype:attempted-recon; sid:200001139; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"contents-229672293.keegan21.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001140; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"contestmariaoriflame1.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001141; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"contractcomplianceservices.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001142; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"contractordoc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001143; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"contraprova.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001144; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"control.pw"; content:"Host"; http_header; classtype:attempted-recon; sid:200001145; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"conviteparaacessaralbumcompartilhadogdrive.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001146; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"convocatoriasactualizadas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001147; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cookeandkelvey.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001148; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"coopfinancierapromerica.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001149; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"coprightmediaform.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200001150; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"copyrightmanagerinfo.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200001151; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"coralplum.diwanuk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001152; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"core2020.itigo.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200001153; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"corecapital.online"; content:"Host"; http_header; classtype:attempted-recon; sid:200001154; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"corinnakegel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001155; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cornholeledgends.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001156; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"coronationcleaning.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001157; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"corporacionplaneta.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001158; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"corr003.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001159; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cortijolatapia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001160; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cottonsailors.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001161; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"couchpop.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001162; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"counselingtraining.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001163; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"countestrds.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001164; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"courseworkwritingsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001165; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"covaricambi.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200001166; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"coverlatino.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001167; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"covid-19challengecoin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001168; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"covidmask24.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001169; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cowpaddies.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001170; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cox0.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001171; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"coxupdate1.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001172; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cp45362.tmweb.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001173; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cpanel.telephone-sfr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001174; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cpanel.thepsychedelics.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001175; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cpanel10wh.bkk1.cloud.z.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001176; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cpanelgsmdemgsoperateurlocal.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001177; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cpanelpourcontinuerhqnfghjkackmailercom.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001178; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cpc.cx"; content:"Host"; http_header; classtype:attempted-recon; sid:200001179; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cpjpainting.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001180; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cpu30691.mfs.gg"; content:"Host"; http_header; classtype:attempted-recon; sid:200001181; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr-mufg.1558008.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001182; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr-mufg.7566258.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001183; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr-mufg.7566321.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001184; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr-mufg.7566963.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001185; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr.mufg.jp.djxowfw.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200001186; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr.mufg.jp.joimhmu.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200001187; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr.mufg.jp.jqqbnxy.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200001188; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr.mufg.jp.jxamtpg.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200001189; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr.mufg.jp.skhayashi1.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200001190; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr.mufg.jp.skhayashi2.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200001191; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr.mufg.jp.ttakasua.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200001192; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr.mufg.jp.ttakasua1.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200001193; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr.mufg.jp.ttakasua2.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200001194; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr.mufg.ttakasua4.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200001195; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cr99797.tmweb.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001196; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"crackaworld.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001197; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"craftner.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001198; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cranetech.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001199; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"creation-creationact-215192311.atwebpages.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001200; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"creative-console.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001201; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"credagric8.temp.swtest.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001202; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"credicorpfiduciariasa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001203; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"credifinanciera.didacsis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001204; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"credilatam.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001205; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"creditiperhabbogratissicuro100.blogspot.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200001206; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cripto.imobtech.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001207; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"crm.manageudaserver.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001208; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"crmdocentes.xochicalco.edu.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200001209; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"csemergencylock.typeform.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001210; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"csgoequal.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001211; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"csknow.clicknkids.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001212; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"csnhc-in-or.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200001213; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"css.co1.qualtrics.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001214; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"csss.co.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200001215; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ctkparish.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200001216; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cu89987.tmweb.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001217; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cu94276.tmweb.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001218; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cuddl.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200001219; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cunjin.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200001220; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cup0p.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200001221; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"currentlyfromattverificationupdate1.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001222; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"currentlyfromupdateserviceyahoo.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001223; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cursomemokids.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001224; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cursosmaquiagem.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001225; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cusercrist.surveysparrow.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001226; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"customer-ebay.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001227; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"customer-remove-payeelloyds.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001228; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"customer-service-client.gcommindia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001229; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"customer.paypal.restored.cemaco.vn"; content:"Host"; http_header; classtype:attempted-recon; sid:200001230; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"customer.swisspost.ch.parcel.trusted.partner.billing07554290.info.com.u1344566.cp.regruhosting.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001231; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"customerrs-sercive.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001232; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"customers.d3b57uo3tsaxy1.amplifyapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001233; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cvkry.snprobbx.pbz.r.de.a2ip.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001234; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cvkry.snprobbx.pbz.r.uk.a2ip.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001235; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cw09073.tmweb.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001236; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cxmx2020atualizacao.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001237; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cy.tc"; content:"Host"; http_header; classtype:attempted-recon; sid:200001238; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cya.nz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001239; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cybersolution.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200001240; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cydaindia.org.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001241; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cyphersale.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001242; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cz0centrum.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001243; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cz84.webeden.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001244; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"d0fus.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200001245; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"d10-amazon.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200001246; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"d18gc1ytkdv37u.cloudfront.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001247; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"d1yjjnpx0p53s8.cloudfront.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001248; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"d521e3ba-0de3-4eae-a9a8-bafefca61eda.htmlcomponentservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001249; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"d5wxk.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200001250; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"da822325-313f-4f85-b334-d9b00a2d64da.htmlcomponentservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001251; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"daffodilmultimedia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001252; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dag-mot-lan.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001253; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dahlen.ax"; content:"Host"; http_header; classtype:attempted-recon; sid:200001254; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dailyexclusiveoffer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001255; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dailyloginrewards.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001256; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dainellistudio.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200001257; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"daniel-treufeld.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200001258; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"danielescivoli.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200001259; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"danielwritingportfolio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001260; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"danitraseoexperts.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001261; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dansami-001-site1.htempurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001262; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"daogetter.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001263; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"daqjwamhsb.cfolks.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001264; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"darah.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001265; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dardenneimmo.be"; content:"Host"; http_header; classtype:attempted-recon; sid:200001266; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"daressalaamtextilemills.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001267; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dashboard.openbankstone.secstone.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200001268; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dataforce.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001269; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dataupdaterequired.site44.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001270; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"datelsolutions.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001271; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"datenerweiterungsprozesslauf2222.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001272; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"datjfhwntt.cfolks.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001273; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"davitherbal.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001274; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"davivienda.ingresopersonal.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001275; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"daviviienda.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001276; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dazul.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200001277; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dba-dk.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200001278; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dbs-votes-friend.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001279; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dbs.rewardgateway.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001280; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dcq.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200001281; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ddestudent.kuk.ac.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001282; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"de-register-device-lloyds-online-banking.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001283; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"de-register-mobile-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001284; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"de.gethuman.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001285; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"de70980.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001286; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"de9632.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001287; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dealerzone.greatnortherncabinetry.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001288; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dealtix.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001289; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dealunderwriter.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200001290; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"decaturilbgc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001291; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"declicgestion.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200001292; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ded5104.inmotionhosting.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001293; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deficitdeatencionperu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001294; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"defneaydin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001295; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deginr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001296; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dekoro.es"; content:"Host"; http_header; classtype:attempted-recon; sid:200001297; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dekusar.com.ua"; content:"Host"; http_header; classtype:attempted-recon; sid:200001298; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"delezhen.mashalezhen.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001299; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"delightontour.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001300; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"delivery-billing.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001301; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"delivery-secure-details0.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001302; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"delivery.fieldgeo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001303; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deliverysec.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001304; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deluxeinternationalschool.co.zw"; content:"Host"; http_header; classtype:attempted-recon; sid:200001305; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"demiregalos.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200001306; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo.samretpechfinance.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001307; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"demo.trandinhnam.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001308; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"denartcc.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001309; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"denuihuongson.com.vn"; content:"Host"; http_header; classtype:attempted-recon; sid:200001310; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deny-application-access.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001311; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deoqsph.seratoptik.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001312; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dercasblog.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001313; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deregister-device-halifax.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001314; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deregister-device-securedlloyd.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001315; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deregister-lbpayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001316; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deregister-lloyd-unauthorisedaccess.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001317; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deregister-online-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001318; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deregister-unauthoriseddevice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001319; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deregister-unverified-seclloyd.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001320; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deregisteranunauthorised-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001321; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"desdeelamor.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001322; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"desert-assurances.be"; content:"Host"; http_header; classtype:attempted-recon; sid:200001323; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"design-lbd.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001324; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"designerforuiq.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001325; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"designerforuiy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001326; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"designerlakehouse.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001327; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deskeservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001328; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"desli-arch.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001329; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"destinationarcticcircle.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001330; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"detatch-this-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001331; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"detect-new-payee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001332; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"detected-payee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001333; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"detogroups.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001334; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deucing-phyteus.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001335; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev-alibaba-marketsquare.pantheonsite.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200001336; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev-market2square.pantheonsite.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200001337; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev-orange-remboursement.pantheonsite.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200001338; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dev.klinikmatanusantara.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001339; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"developerng.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001340; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"device-deregisteration.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001341; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"device-secureauth.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200001342; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"device-security.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200001343; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"device-verify.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200001344; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"device.secure-amendment.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200001345; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deviceaccess-lloydbanking.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001346; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"devicesupport.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200001347; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"devilish-sectors.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001348; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dewlingers.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001349; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dexlerholdings.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001350; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dffrhjrfnredbde.de.tl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001351; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfo.com.my"; content:"Host"; http_header; classtype:attempted-recon; sid:200001352; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfsgh.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001353; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dg54asdg15g1.agilecrm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001354; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dh0937.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200001355; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dhhe.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001356; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dhi.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200001357; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dhl.recruitmentplatform.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001358; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dhl.schedule-new-delivery.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001359; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dhlgpi.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001360; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dhlonboarding.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001361; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"diarionomada.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001362; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dicksonsmultitrade.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001363; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"die-post-swiss-id-19782635812.psd2any.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001364; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"diepost-id-17623512-parcel-redirect.prepaidify.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001365; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"digid-vorderingen.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200001366; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"digitalmps-it.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001367; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"digitaltaxmatters.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001368; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dimolo.activehosted.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001369; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dineroalinstante-viabcp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001370; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dipinstitute.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001371; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"directs-bank-mufg-co-jp.baoguoli.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200001372; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"directs-bank-mufg-co-jp.cnzhb.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200001373; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"discordaccountcp.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001374; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"discouragepeel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001375; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dishub.landakkab.go.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200001376; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"distrial.ec"; content:"Host"; http_header; classtype:attempted-recon; sid:200001377; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"diversepropertysolutions.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001378; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dixdomains.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001379; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"diylisty.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001380; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dkb-info.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001381; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dkb1231ag.site44.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001382; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dkbscure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001383; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dmgratis.freefire-eventff.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001384; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dmrcoop.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001385; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dmtechnologies.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001386; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dncselection.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001387; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dns-ssl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001388; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"doapositioning.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001389; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"doc-transfer.email"; content:"Host"; http_header; classtype:attempted-recon; sid:200001390; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"doclab-console-auth.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001391; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"docomocco.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001392; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"docomonio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001393; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"docomoonc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001394; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"docs.revv.so"; content:"Host"; http_header; classtype:attempted-recon; sid:200001395; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"docsharex-authorize.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001396; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"doctorsfederalcreditunion.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001397; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dofps.gov.bt"; content:"Host"; http_header; classtype:attempted-recon; sid:200001398; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dofus-actus.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200001399; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dofus-service.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001400; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dofus-veteran.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200001401; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dokanyshop.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001402; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"domainfornames.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001403; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"domainlockfacebookapps.owwnjv2dro-e9249ek1k6kr.p.runcloud.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200001404; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"domainsothersee.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001405; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"domalio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001406; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dominioits.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001407; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dominiqueleoville.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001408; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"domuterra.ch"; content:"Host"; http_header; classtype:attempted-recon; sid:200001409; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dongsuh.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001410; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"donieyuhuu05.getenjoyment.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001411; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dopeydog.co.nz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001412; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dortchandassociates.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001413; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dostawa-safe.su"; content:"Host"; http_header; classtype:attempted-recon; sid:200001414; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dostawaolx.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001415; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dota-hook.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001416; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dota2ez.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200001417; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dota2og.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200001418; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dotdre.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001419; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dotilo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001420; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"douuodwoman.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001421; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dowwr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001422; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"doz.tode.cz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001423; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dpay-paxful.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001424; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dpd-billingerror.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001425; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dpd-fee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001426; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dpd-parcel-attempt-reschedule.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001427; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dpd-shipping-fees.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001428; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dpd-unpaid.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001429; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dprotect.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001430; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dprotection.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001431; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dranathaliamatos.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001432; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"drebervalgadelha.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001433; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"drginc.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001434; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"drivetransfer.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200001435; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"drmartensbrando.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001436; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"drmartensoutlethu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001437; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"drmartensoutletmexico.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001438; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"drmartenssale.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200001439; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"drmgews.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001440; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"drsamuelzorrilaslives.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001441; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"drumairabubakar.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001442; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ds7.main.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200001443; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsastars.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001444; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsgcbeonline.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001445; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dsgrehrehreh.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001446; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"duchessequestrian.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001447; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dudhkundaadventuretreks.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001448; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"duemiglia.evoluzioneufficio.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001449; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"duffelbagadventures.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001450; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dukhovnist.in.ua"; content:"Host"; http_header; classtype:attempted-recon; sid:200001451; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"durafast.shoplo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001452; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dvla.myvehicle-rebate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001453; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dvla.support-schemeuk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001454; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dvlatax-return.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200001455; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dvlataxreturn.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200001456; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dydy2.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200001457; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dynastyclinic.ae"; content:"Host"; http_header; classtype:attempted-recon; sid:200001458; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dzd.rksmb.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001459; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-bay-freelistings-offers-today-2991832.saccgpi.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001460; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-devlet-kapisi.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001461; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-leclerc.fr-epicerie.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200001462; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-receipts.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200001463; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-registration.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001464; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-service.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001465; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-serviceparts.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200001466; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"e-www-roblox.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001467; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eaecl.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001468; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eamashoppigbill.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001469; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"earlylearningindiana.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200001470; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"easternts.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001471; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"easycheapshopping.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001472; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"easyquotes4you.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001473; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"easyurl.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200001474; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eb-info-verify.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001475; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eba0200d0c.nxcli.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001476; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebay-com-vehicles-29971842.1203910.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001477; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebay.co.uk.2912168371646.bid"; content:"Host"; http_header; classtype:attempted-recon; sid:200001478; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebay.co.uk.itm.sale"; content:"Host"; http_header; classtype:attempted-recon; sid:200001479; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebay.com-brand-gwen-food-trailer-37353927.3567102.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001480; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebay.com-itm-keystone-outback-25fb-290047.4367249.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001481; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebay.com-itm.apple-iphone.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200001482; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebay.com1.i.11itm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001483; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebay.itm.com.il1.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200001484; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebay.payment-issues-help.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001485; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebayitm.com.buyitnowpage.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001486; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebikestoreverona.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200001487; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebl-forum.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001488; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ebuddynews.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001489; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ec2-3-129-10-45.us-east-2.compute.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001490; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ecisd-sch.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200001491; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ecisd-us-docx.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001492; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ecoachievers.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001493; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ecolinklogistics.co.ke"; content:"Host"; http_header; classtype:attempted-recon; sid:200001494; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ecomcrew.staging.wpengine.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001495; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ecopeandson.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001496; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ecotaskforce.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001497; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ecoute-sms-vocal.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001498; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"edcfun.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001499; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"edje.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001500; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"edocusign.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001501; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"edoism.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001502; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"edtech.mybusybee.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001503; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eduardomendescanal.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001504; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"educadoracanina.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001505; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ee-accountsecureuk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001506; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ee-alert-bill.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001507; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ee-bill-pay-uk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001508; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ee-billing-updateinformation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001509; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ee-billinginfo-uk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001510; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ee-billingsecure-login.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001511; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ee-servicehub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001512; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ee-verify-billing-secure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001513; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eehelp.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001514; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eeonline-alerts.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001515; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eepayments.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001516; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eeservice-securerebate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001517; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"efashion.world"; content:"Host"; http_header; classtype:attempted-recon; sid:200001518; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"effect-print.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001519; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"egacal.edu.pe"; content:"Host"; http_header; classtype:attempted-recon; sid:200001520; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eggnogs-ferocious.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001521; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"egyptmovingfurniture.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001522; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eh5ko.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200001523; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ehan.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001524; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eharmonyservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001525; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ehealthmax.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001526; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eislueqr.livedrive.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001527; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ekologika.co.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200001528; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ekopups.com.ua"; content:"Host"; http_header; classtype:attempted-recon; sid:200001529; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ekotienda.com.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200001530; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ekvarika.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001531; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eladios.com.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200001532; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"elagus.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200001533; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"electrocoolhvacr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001534; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"electronicanehuen.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001535; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eledsupply.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001536; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"elenajae.biz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001537; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eletronicarwm.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001538; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"elettrovisiongroup.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001539; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"elinastorebd.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001540; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eliturbrasil.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001541; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ellenronaldskeene.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001542; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"elomo.ro"; content:"Host"; http_header; classtype:attempted-recon; sid:200001543; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"email.2020cycling.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200001544; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"email.royal-eng.ps"; content:"Host"; http_header; classtype:attempted-recon; sid:200001545; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"email.veromailer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001546; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"email302.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001547; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"emailfilter-update.sitebeat.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200001548; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"emailonlineavailable.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001549; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"emailsettings.webflow.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200001550; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"emailsignin.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001551; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"embarqueja.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001552; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"embdestech.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001553; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"emebfsasampaio.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001554; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"emeraldtextiles.pk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001555; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"emergencyelectricianfulham.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001556; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"emigratingtothesun.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001557; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"emotesfree-fire-garena1user.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001558; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"empirejewelers.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200001559; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"employee-portal.buildingandearth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001560; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"empoweredskills.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001561; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"empresas-lnterlbnlk-pe.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001562; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"empresas.netinterbank.interbol-portal.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001563; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"emsi-lobo.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001564; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"enbolivia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001565; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"encryptdrive.booogle.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001566; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"endpointsportal.au-bbva-bancomerappnomina.cloud.goog"; content:"Host"; http_header; classtype:attempted-recon; sid:200001567; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eneconpanama.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001568; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"energygain.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001569; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"energynsolucoes.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001570; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"enevis-investors.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001571; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"enext.mn"; content:"Host"; http_header; classtype:attempted-recon; sid:200001572; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eng.tni.ac.th"; content:"Host"; http_header; classtype:attempted-recon; sid:200001573; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"engcamp.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001574; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"engenhariasolutions.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001575; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"englishstudio.ir"; content:"Host"; http_header; classtype:attempted-recon; sid:200001576; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"enmeixing.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001577; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"enorma.is"; content:"Host"; http_header; classtype:attempted-recon; sid:200001578; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"enrollmoreclientsbootcamp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001579; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ensemblearsmundi.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001580; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"entry11.bkmoefg.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001581; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"entry11.bkmusfg.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001582; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eonsdme.nsndjeialfoanema.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200001583; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ephcoplaza.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200001584; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"epos-card.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001585; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"epos-card.vip"; content:"Host"; http_header; classtype:attempted-recon; sid:200001586; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"equalchances.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001587; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"equipeinteracao.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001588; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"equitydwellings.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001589; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eracargrup.com.tr"; content:"Host"; http_header; classtype:attempted-recon; sid:200001590; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eracvv.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200001591; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"erahomelistagent-realestate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001592; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"erere.parhlobeta.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001593; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eroom.stylemixthemes.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001594; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"error-mobile-concern.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001595; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ersal.wuamerigo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001596; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ertu.streamlink.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200001597; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"esgcommercialbrokers.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001598; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eslickcreative.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001599; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"espace-client.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200001600; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"espace-client21.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001601; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"essaidefiabiltebc.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001602; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"essence.co.th"; content:"Host"; http_header; classtype:attempted-recon; sid:200001603; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"estensione-web-clienti.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001604; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"estetika2z.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001605; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"estudiomaskin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001606; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"etails.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200001607; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"etkinsiteyonetimi.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001608; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"etoro-invest.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001609; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"etrack05.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001610; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eu.nuvuneu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001611; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eugnerally-wixsite-com.filesusr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001612; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eunefreeskinsrp.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001613; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"europemax.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001614; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eusa-lombo.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001615; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eve292929.dothome.co.kr"; content:"Host"; http_header; classtype:attempted-recon; sid:200001616; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"event-new-freefire-2021.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001617; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"event-neww01.xevent94.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200001618; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eventfreeskin-freefire4.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001619; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eventlogin18.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001620; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eventsisters.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001621; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"evidaac.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001622; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"evntmlbb-vip22.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001623; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"evolution-postepay.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001624; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"evotechss.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001625; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"exchange4free.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001626; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"exchangedictionary.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001627; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"executiveled.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001628; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"exodus-staking.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200001629; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"exosomes.sale"; content:"Host"; http_header; classtype:attempted-recon; sid:200001630; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"expeditions-of-e.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001631; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"expire-o2-billingupdate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001632; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"expire-o2-planupdate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001633; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"exploitrefund.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001634; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"explorer.usweepstakes.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001635; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"extracash-interlbankonline.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001636; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"extravasatingmetalworker.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001637; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ey8jl.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200001638; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eye-lucir.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001639; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ezapostille.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001640; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ezblox.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200001641; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"f-pembatalan.forumz.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200001642; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"f0522189.xsph.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001643; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"f6fr7.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200001644; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"f80e476c-4329-4a82-ae2b-40a9bc5e96df.htmlcomponentservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001645; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"f9w1lned0ruqblxi6jahwotak.filesusr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001646; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fa7436a7c93859878.temporary.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200001647; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fabiano.lima.continentalwingates.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001648; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fabricateelapse.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001649; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facabook.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001650; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facadetesting.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001651; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facagall.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001652; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facbk.atspace.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001653; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facealert.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200001654; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook-appsp.webnode.es"; content:"Host"; http_header; classtype:attempted-recon; sid:200001655; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook-giris.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001656; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook-login-customer-security-support-ticket-number-19485643.gmi.com.ng"; content:"Host"; http_header; classtype:attempted-recon; sid:200001657; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook-login.tbit.vn"; content:"Host"; http_header; classtype:attempted-recon; sid:200001658; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook-marketpleace1itm85551.sfcabinetexperts.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001659; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook-rentals.alaounalarabia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001660; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook-security.owwnjv2dro-e9249ek1k6kr.p.runcloud.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200001661; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook.com-marketplace-93839.mediaryte.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200001662; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook.com.e.ajt.hp.transer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001663; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook.com.marketplace-item18361-mobile.ppdautos.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200001664; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook.com.ttcysuttlart1999.aylandirow.tmf.org.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001665; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook.discreteform.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200001666; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook.eventspinff.wtf"; content:"Host"; http_header; classtype:attempted-recon; sid:200001667; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook.hrbureaugh.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001668; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook.marketplace-item-93248.scheff.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001669; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facebook.sekuasha.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001670; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"faceedr.jimdofree.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001671; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"facemyoriflame1.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001672; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fafireead.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001673; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fai-nyc.lt.acemlnb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001674; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"failure-o2billing-via.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001675; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fairauditors.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001676; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"faktypolska7.b-cdn.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001677; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"faleupas.kissr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001678; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fanfaronquays.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001679; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fanssoibahhh.vipcom1-xyz.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200001680; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fanxtv.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200001681; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fasdfasdfasdfas345wetasdf.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001682; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fashionphotographycourse.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001683; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fastpantech.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001684; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fastrehabs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001685; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"faturadigital.serveftp.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001686; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"faturaonlinecredicar.tempsite.ws"; content:"Host"; http_header; classtype:attempted-recon; sid:200001687; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fax.gruppobiesse.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200001688; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"faxitalia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001689; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb-marketplace-831767.calculatesite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001690; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb-pageconfirmation.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001691; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb-privacy-1000000024875112562451117-tw.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001692; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb-privacy-1000000024875112562451118-tw.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001693; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb-privacy-1000000024875112562451119-tw.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001694; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb-privacy-1000000024875112562451120-tw.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001695; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb-privacy-10000000248751199542387655901-hk.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001696; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb-privacy-10000000248751199542387655906-hk.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001697; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb-privacy-10000000248751199542387655908-hk.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001698; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb.expressturkeyi.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001699; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb.probox.lk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001700; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb18984-page38785-real-estate-item223674.house"; content:"Host"; http_header; classtype:attempted-recon; sid:200001701; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb29856-page89456-real-estate-item33785.house"; content:"Host"; http_header; classtype:attempted-recon; sid:200001702; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb72354-real-estate-item89456-page25346.house"; content:"Host"; http_header; classtype:attempted-recon; sid:200001703; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb84956-real-estate-item32895-page66783.house"; content:"Host"; http_header; classtype:attempted-recon; sid:200001704; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fb89324-page97845-real-estate-item67893.house"; content:"Host"; http_header; classtype:attempted-recon; sid:200001705; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fbmarketplace-homelisitng.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001706; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fbookoo.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001707; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fbpage-rules-5812937.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001708; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fbpages-claim-center.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200001709; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fbrent.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001710; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fcbk.brooklynjewish.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001711; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fd2821b14d3828306.temporary.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200001712; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fdx.co.th"; content:"Host"; http_header; classtype:attempted-recon; sid:200001713; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fdyf5.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200001714; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fedexvoyager.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001715; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fedner.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001716; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fedservco.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001717; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fee-postalservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001718; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fee-required.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001719; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"feedilicious.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001720; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"feitoparavoce-digital.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001721; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fene-modi.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001722; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ferienhof-gempel.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200001723; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ferinrterd.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001724; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"festina.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200001725; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"festivo.fi"; content:"Host"; http_header; classtype:attempted-recon; sid:200001726; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fetish-ketek.2waky.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001727; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ff-oberoetzdorf.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200001728; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fftmtt.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001729; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fgbbtyjuhgjhmgf.fra1.digitaloceanspaces.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001730; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fhhw1u.webwave.dev"; content:"Host"; http_header; classtype:attempted-recon; sid:200001731; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fiafunupe.flywheelsites.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001732; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fibre-broadband.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001733; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fiestanube.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200001734; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"financiallifecoaching.builderallwp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001735; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"financialone.com.hk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001736; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"financieracredicorpltda.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001737; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"finansuotojas.lt#noc@ruhr-uni-bochum.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200001738; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"findurway.tech"; content:"Host"; http_header; classtype:attempted-recon; sid:200001739; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fitbygg.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001740; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fitlineintegratorialimentari.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001741; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fixe-messagerie0.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001742; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fixe-vocale.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001743; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fixitestore.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001744; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"flingeldingel.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001745; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"flixpassed.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001746; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"floorsdirectltd.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001747; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"floristru.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001748; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"flowtork.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001749; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"flur7k.webwave.dev"; content:"Host"; http_header; classtype:attempted-recon; sid:200001750; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"flywed.turbo.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200001751; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fm.registrobarretos.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001752; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fmqseczoms.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200001753; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fndsdaytings.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001754; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"foamnflow.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001755; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"focusphotography.co.vu"; content:"Host"; http_header; classtype:attempted-recon; sid:200001756; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"foliar.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001757; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"foma-ura-lote.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001758; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"foresta-mod.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001759; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"forgesmithvr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001760; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"formbuddy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001761; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"formtools.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001762; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fortrader.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001763; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"forumasik.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001764; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"forums.rstools.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200001765; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"founders-center-1994545233616657575.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001766; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"founders-center-1994545233616657576.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001767; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"founders-center-1994545233616657579.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001768; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fpmaam.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001769; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fr-europe564598-com.filesusr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001770; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fr.chromeproxy.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001771; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fr.fireprox.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001772; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fr.freevideoproxy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001773; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fr.imsly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001774; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fr.proxy.al"; content:"Host"; http_header; classtype:attempted-recon; sid:200001775; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fr.unblockyoutube.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200001776; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"free-gifts-pubgs.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200001777; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"free-mlbb8.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001778; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"free-pubgmobile.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200001779; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"freemainuwebing.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001780; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"freeproductkey.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001781; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"freepubgs.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200001782; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"freevbuckx.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001783; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"frenchamani.s3-us-west-2.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001784; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"frensner.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001785; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"frerfire-gaming.mrbonus.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001786; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"froid-guyader.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200001787; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fromattyahoomailnetfay.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001788; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fructidor.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001789; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fruernes.dk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001790; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fskpagas.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001791; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ftp.lesterandco.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001792; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ftp.warfacebonus.hop.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001793; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fugas.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001794; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fulgurant-mistakes.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001795; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fundacioires.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001796; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fundacionpares.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001797; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"furkancinar.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001798; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"futboles.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200001799; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"futureofagencies.engagewithadobe.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001800; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"futuretroveschool.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001801; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fxt27.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200001802; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fzbfhn.webwave.dev"; content:"Host"; http_header; classtype:attempted-recon; sid:200001803; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"g-mtcc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001804; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gabona-ca.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001805; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gabungg-gruppwhattsapp18.ftp1.biz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001806; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gabungg-whatsappterbaru-dewasa18.hollz79.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001807; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gabunggroupdewasa.vizvaz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001808; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gabunggruphot.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001809; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gaerhaerh.kaixuanmencryp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001810; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"galbob.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200001811; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"galiciausuario3.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001812; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"galvanotehnik.rs"; content:"Host"; http_header; classtype:attempted-recon; sid:200001813; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gamecenterxpubgm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001814; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gamefex.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001815; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gamesonlinerewards.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001816; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gammanu1947.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001817; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gas9623wgb.fastpluscheap.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001818; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gau-lighting.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001819; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gawvs.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001820; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gayatriprojects.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001821; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gb-saw1him.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200001822; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gb-saw9him.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200001823; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gbsahur.gklk.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001824; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gdschoolbijorawas.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001825; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ge-ge.snprobbx.pbz.r.de.a2ip.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001826; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"genie-alba.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001827; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"geometry-yamal.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001828; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gerentecf.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200001829; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gerentenbo.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200001830; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gesticulatory-profi.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001831; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gestoriadecredito.com.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200001832; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"getactive365.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001833; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"getatless.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001834; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"getco-genetics.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001835; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"getdeals.lk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001836; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"getk9training.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001837; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"getlikesfree.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001838; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"getnatoun.am"; content:"Host"; http_header; classtype:attempted-recon; sid:200001839; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"getnowaddidas1.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001840; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfdhygfdhgfj.easy.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200001841; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfvn2.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200001842; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfxx.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001843; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghghgghghdfybv.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001844; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghjlmljgh.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001845; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghorana.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001846; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ghuswave.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001847; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"giacomonegro.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001848; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"giantintlagencyph.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001849; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"giftsospecial.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001850; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"giris-papara.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001851; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gite-lafage.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001852; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"giveaway-online.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001853; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"giveawayroyale16.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001854; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gjhanekamp.nl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001855; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gkigqoz1u3mxphqsckqkxr8k3mbnmuk-com.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200001856; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gkjx168.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001857; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gkpw-59.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001858; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"glamatixs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001859; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"glance-mishit.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001860; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"globailpage-prodwebex.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001861; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"globalpage-prodwebex.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001862; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"globalskillspark.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001863; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"glogo.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001864; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"glowtrk7.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001865; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"glsword.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001866; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gm-login.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001867; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmail-auth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001868; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmaillgve.ebpages.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001869; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gngssadhaz.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001870; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gns.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200001871; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"go.steamid.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200001872; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"goal.com.pe"; content:"Host"; http_header; classtype:attempted-recon; sid:200001873; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"godaddypage.cloudns.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001874; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"godeaug.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001875; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"godsmanmedics.godmanmedicals.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001876; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gofreegovernmentmoney.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001877; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldcoastrhinoplasty.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200001878; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldengypsyshop.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001879; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"goldenstarkos.gr"; content:"Host"; http_header; classtype:attempted-recon; sid:200001880; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"golfballsonline.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001881; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gonogenesis-outjinxes.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001882; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"google.projectseries.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001883; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"goravia.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200001884; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gornjimilanovac.rs"; content:"Host"; http_header; classtype:attempted-recon; sid:200001885; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gouv-impot.cemerbas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001886; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gov.uk-dvla.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001887; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gpsecurity-store.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001888; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grab.zenstream.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001889; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grabyourcode.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001890; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grandfathermigration.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001891; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grandmarketltd.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001892; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gravitfy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001893; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"greatmusica.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001894; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"greenmattresscleaning.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001895; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gregmounsey.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001896; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grenfellclub.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001897; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"greteldeblock.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001898; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grievance.gpshyampur.org.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001899; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grintechindia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001900; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grms.cit.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001901; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grocery-store.4pillarglobal.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001902; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grosshandel-mevida.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200001903; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grottedisaledesenzano.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001904; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"group-18-sans.wikaba.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001905; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"group-chat-vtmesport.dynamic-dns.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001906; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"group9815jcl.fastpluscheap.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001907; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"groupvirall2021-net.www1.biz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001908; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"groupwhatsappsex.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200001909; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"groupwhattsap.jkub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001910; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"growasiacapital.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200001911; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"groworldinternational.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001912; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grp02.id.rakutan-co-jpd.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200001913; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grps-bnnp.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001914; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grub-whatsaap.dtdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001915; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grubbokep22.mrbonus.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001916; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grubtantenadiah.crotteros.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200001917; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grubwa.mrbasic.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001918; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grubwhatsapp-indonesiaviral2021sexgrub.se.ke"; content:"Host"; http_header; classtype:attempted-recon; sid:200001919; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grup-notnot.fouzen.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200001920; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grup-tante.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001921; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grup-wa-bokep18.wikaba.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001922; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grup-wa-notnot-realll12.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001923; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grup-wahtsapp1888.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001924; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grup-whatsappsexy.xxuz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001925; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupdewasa17.otzo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001926; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupnotnot21.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001927; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupo-xtreme.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001928; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupoabi.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001929; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gruposcherman.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200001930; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupsexmyvip.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001931; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupwa-crottte.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001932; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupwa18-tys.wikaba.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001933; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupwavidioviral.1evnt-net.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200001934; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupwhatsaap-viral18.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001935; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupwhatsapp-biz.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001936; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupwhatsapp2021.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200001937; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupwhatsappyoutuber.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001938; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grupwhatsapviral.grupxxx-new.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200001939; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gs-facebook-91369352.azamov.uz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001940; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gsierohv4zgayjanmrputhzlvy-adwhj77lcyoafdy-www-paypal-com.translate.goog"; content:"Host"; http_header; classtype:attempted-recon; sid:200001941; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gt.trabajo.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001942; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"guccounterlrr.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001943; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gudanggamismuslimah.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001944; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"guillermo.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001945; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gulfsynergy.ram-fsip.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001946; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gulshangeneral.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001947; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gunind.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001948; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gunnebo.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200001949; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"guoshenlongjing.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001950; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gustavodiazmarin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001951; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gwenet.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001952; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gwisalltrack.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001953; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gxsb8.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200001954; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"h5brzd.webwave.dev"; content:"Host"; http_header; classtype:attempted-recon; sid:200001955; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"habitatsiliconvalley.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001956; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hagit-simantov.co.il"; content:"Host"; http_header; classtype:attempted-recon; sid:200001957; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hahdaeupdate.es.tl"; content:"Host"; http_header; classtype:attempted-recon; sid:200001958; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"haiifax.co.uk-mydevice.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200001959; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hailingmailserverbeat.godaddysites.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001960; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"halaisabudhabi.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001961; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hali-securepayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001962; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hali-securesuite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001963; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"halifax-checkthispayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001964; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"halifax-online-bank.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001965; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"halifax-securelink.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001966; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"halifax-security-de-register-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001967; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"halifax.co.uk-secure-online.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001968; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"halifax.device-authentication-login.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001969; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"halifaxid.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200001970; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"halifxpayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001971; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"halionlinebankingsystem.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001972; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"haliuk-secure-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001973; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"halved-perpetual-mule.glitch.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200001974; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hamc.org.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200001975; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"handipadel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001976; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"handmadebyamber.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200001977; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"handmhealth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001978; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hannetjiefaurie1.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200001979; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"haogege.52yjh.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200001980; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"haroldhazard1-wixsite-com.filesusr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001981; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hasancingiz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001982; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hasmob.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001983; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hasppa.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200001984; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hasseanhannitybeenwaterboarded.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001985; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hauntedbullockhotel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001986; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hbomaxfreetrial.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001987; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hbtengxun.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001988; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hcsp-in-comnm.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200001989; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hdmediahub.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200001990; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"healthepredictions.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001991; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"healthnetcct-a.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200001992; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"healthnetcct-com.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200001993; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"healthymantra.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200001994; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"heaterintwintersz.ams3.digitaloceanspaces.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001995; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"heavenlymatches.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001996; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hebronlions.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200001997; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hectorsantana.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200001998; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hedaodesign.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200001999; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"heipinstagram.byethost5.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002000; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"helloparis.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002001; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"help-dbs.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002002; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"help-deny-mypayees.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002003; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"help-deny-newpayees.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002004; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"helpdesk-tech.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002005; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"henry-in-org.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200002006; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"henryford.edu.np"; content:"Host"; http_header; classtype:attempted-recon; sid:200002007; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hentiesbaygolfestate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002008; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"heppler.ch.net2care.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002009; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"herdtissue.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002010; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hermes-my-package.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002011; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"herz-law.co.il"; content:"Host"; http_header; classtype:attempted-recon; sid:200002012; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hetershaven.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002013; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hfjgjgtgj.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002014; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hgn2t.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200002015; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hhaasg.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200002016; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hide-windows.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002017; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hidroconsultoria.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002018; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hidrorede.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002019; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"highnmightytv.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002020; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hilite.com.pk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002021; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hindaleryani.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002022; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hindva.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002023; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hipercardfatura.biz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002024; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hithustlers.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002025; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitman71hd-wixsite-com.filesusr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002026; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hitsem.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002027; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hjertevennlig.no"; content:"Host"; http_header; classtype:attempted-recon; sid:200002028; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hjfdjkkij.debalounefois.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002029; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hk.mikecrm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002030; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hm-revenue-costums.ciclosew.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002031; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hm.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002032; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hmlkl.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200002033; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hmp.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200002034; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoantrungdanang.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002035; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoberqueen.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002036; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hoholdenis.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002037; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"holatoronto.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002038; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"holdmembershipntfx.aulaseidec.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002039; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"holidayinnboston.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002040; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"home.myfairpoint.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002041; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"homelike.tiantianchecheng.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200002042; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"homesinlogin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002043; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"homologacao.madrugadaolanches.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002044; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"homs.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200002045; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"homs.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002046; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"honda4fun.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002047; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"honeyhyper.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002048; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"honorlifecollective.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002049; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hosting2021623.online.pro"; content:"Host"; http_header; classtype:attempted-recon; sid:200002050; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hosting2024700.online.pro"; content:"Host"; http_header; classtype:attempted-recon; sid:200002051; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hosting2042037.online.pro"; content:"Host"; http_header; classtype:attempted-recon; sid:200002052; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hosting2070987.online.pro"; content:"Host"; http_header; classtype:attempted-recon; sid:200002053; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hosting2086464.online.pro"; content:"Host"; http_header; classtype:attempted-recon; sid:200002054; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostnix.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002055; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostpoint-admin-panel52358.web65.s177.goserver.host"; content:"Host"; http_header; classtype:attempted-recon; sid:200002056; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostpoint.ch.1200028f.net2care.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002057; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostpoint.ch.121c0291.net2care.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002058; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostpoint.ch.17a902ef.tcorner.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200002059; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostpoint.ch.gbp-events.com.prunauneau.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200002060; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostpoint.ch.hebetec.ch.p2aexpertise.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002061; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hot-mailitaccedi.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002062; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hotel-pontos.gr"; content:"Host"; http_header; classtype:attempted-recon; sid:200002063; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hotgrub.mlbb732.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200002064; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hotmail-mailupdate.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002065; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"house18.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200002066; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"houstonisd-org.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200002067; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"howrse.5v.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200002068; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"howtostopforeclosurequick.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002069; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hp-ne.com.healthinsurez.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002070; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hp-or.surge.sh"; content:"Host"; http_header; classtype:attempted-recon; sid:200002071; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hrmdemo.zewiagroup.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002072; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hrs-game.main.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200002073; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hrzkpj.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002074; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hs-bankingservices.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002075; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hs-giveaways.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200002076; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hs-payeeauthentication.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002077; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hs-security-auth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002078; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hs-verify-payeeadded.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002079; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbc.cancel-online-payments.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002080; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbc.cancel-unauthorised-payments.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002081; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbc.deny-new-paym.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002082; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbc.deny-paym-auth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002083; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbc.payee-deny.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002084; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbc.payee-web-personal.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002085; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbc.raftarafta.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002086; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbc.remove-new-paym.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002087; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbc.remove-payee-secure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002088; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbc.stop-online-payments.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002089; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbc.stop-payments-online.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002090; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbc.web-payee-personal.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002091; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbc.web-paym-cancel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002092; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbcinfo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002093; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsgbndaloma.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002094; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ht6s.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002095; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"htiitrevcm.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002096; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"httpsloginorangefr80.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002097; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"httpsloginorangefr85.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002098; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"httpsloginorangefr86.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002099; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"httpsloginorangefrpro0.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002100; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"httpsloginorangefrpro1.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002101; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"httpsservices.runescape.com-cn.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002102; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hualish01.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002103; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"huanluyenchocaocap.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002104; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hubupgrade.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002105; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"humani.biz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002106; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hunnidmallc.azurefd.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002107; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"huntingreward.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002108; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"huntingtononline.ddns.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200002109; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"huschhus.ch"; content:"Host"; http_header; classtype:attempted-recon; sid:200002110; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hutoknepper.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200002111; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hwfsweden.se"; content:"Host"; http_header; classtype:attempted-recon; sid:200002112; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hyasozozadr5hdg.ygto.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002113; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hydrocorallia-mangabev.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002114; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"i-kiwi.com.ua"; content:"Host"; http_header; classtype:attempted-recon; sid:200002115; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"i-like-amtrak.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002116; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"iacoi-law.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200002117; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"iamin.events"; content:"Host"; http_header; classtype:attempted-recon; sid:200002118; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"iamkevinfay.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002119; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ib2wacesso.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002120; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ibank.my-benchmark.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002121; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ibank.qnbfinansbkonline.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002122; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ibpm.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002123; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"icapoetry.mabar-freefireinvit-wa17x.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200002124; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"icecosenergyltd.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002125; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"icloudproblemconn.servequake.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002126; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"id-ee-securecustomer-online-passwordreset.s3.eu-gb.cloud-object-storage.appdomain.cloud"; content:"Host"; http_header; classtype:attempted-recon; sid:200002127; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"id.ee.update.bill.secure.info.gorank.online"; content:"Host"; http_header; classtype:attempted-recon; sid:200002128; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"id.sls.g.u.1yerqfxfm.mastery.edu.sa"; content:"Host"; http_header; classtype:attempted-recon; sid:200002129; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"id.sls.g.u.lvyam1qt.renesaschool.edu.bd"; content:"Host"; http_header; classtype:attempted-recon; sid:200002130; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"idcarmenia.am"; content:"Host"; http_header; classtype:attempted-recon; sid:200002131; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"identification-portail.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002132; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"identifiez-vous-avec-votre-compte.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002133; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"idiomas247.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002134; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"idorange8.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002135; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"idsvls57.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002136; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ifatechniques.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002137; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ifb.dz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002138; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ig3emailmarketing.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002139; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"igazszabolcs.hu"; content:"Host"; http_header; classtype:attempted-recon; sid:200002140; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"igeog.uerj.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002141; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"igricekonzole.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002142; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"iiaosdffff.easy.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200002143; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"iims.onlineapplication.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200002144; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"iipvit.by"; content:"Host"; http_header; classtype:attempted-recon; sid:200002145; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ijobs.vn"; content:"Host"; http_header; classtype:attempted-recon; sid:200002146; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"iksanthesharp.postown.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002147; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ikuhzdswpx.pfirmann-bau.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200002148; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ilovemymess.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002149; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"imatter.rocks"; content:"Host"; http_header; classtype:attempted-recon; sid:200002150; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"img.maplejournal.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200002151; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"imheadquarters.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002152; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"imi.org.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200002153; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"implantecapilar.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200002154; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"impot-gouv.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200002155; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"impotspublicservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002156; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"impsa.com.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200002157; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"imsva91-ctp.trendmicro.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002158; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"imusica.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200002159; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"in.cim-identity.online"; content:"Host"; http_header; classtype:attempted-recon; sid:200002160; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"inaceinox.pt"; content:"Host"; http_header; classtype:attempted-recon; sid:200002161; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"incatraildeals.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002162; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"incometaxchandigarh.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002163; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"indevafd.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002164; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"index.kroppsfunktion.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002165; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"india-cosme-shop.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002166; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"indiankitchenfood.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002167; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"indiasamaachaar.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002168; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"indybytes.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002169; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"info-839a80.ingress-bonde.easywp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002170; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"info-amaoul.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002171; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"info-full18.2waky.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002172; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"info.ipromoteuoffers.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002173; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"info.lionnets.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002174; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"infobank.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200002175; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"infobcp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002176; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"infocenter.udonpao.go.th"; content:"Host"; http_header; classtype:attempted-recon; sid:200002177; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"infodati020.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002178; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"infonotifica.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002179; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"informacoes-diarias.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002180; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"informadadositau.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002181; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"informwebmail.eastus2.cloudapp.azure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002182; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"infosecurityid.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002183; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"infosecurityposte.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002184; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"infosprologinmatrisemomols.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002185; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ing-esdirecting.pro"; content:"Host"; http_header; classtype:attempted-recon; sid:200002186; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ingaveiculos.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002187; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ingegneriaingonlin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002188; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ingreso-solidario.nsytwa.cyou"; content:"Host"; http_header; classtype:attempted-recon; sid:200002189; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ingresozonasegura.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002190; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"inlnk.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002191; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"innoaura.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002192; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"inonwoven.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002193; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"inpost-dostawa.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200002194; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"inpost.pl-sale.surf"; content:"Host"; http_header; classtype:attempted-recon; sid:200002195; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"inscreditos.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002196; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"insta-gram.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200002197; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"instafollowers.azurewebsites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002198; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"instagraar-001-site1.etempurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002199; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"instagram-copyright-924653891958.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002200; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"instagram-copyright-support568995447896.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200002201; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"instagram.vintweb.ir"; content:"Host"; http_header; classtype:attempted-recon; sid:200002202; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"instagramhelpp.agency"; content:"Host"; http_header; classtype:attempted-recon; sid:200002203; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"instgrarm.herokuapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002204; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"institutoaxioma.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200002205; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"intellectechinc.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002206; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"interbankfinances.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002207; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"interestingfurniture.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002208; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"intermaticoline.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002209; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"intern.unibas-com.ch"; content:"Host"; http_header; classtype:attempted-recon; sid:200002210; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"internationaleimmobilien.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002211; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"internetbankingatualiza.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002212; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"interniitm.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200002213; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"intranet.grupoplasencia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002214; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"intserviy.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200002215; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"invitation-page-policy-notification-2021.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002216; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"invitation-pages-advanced-notification-2021.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002217; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"invitgrub-dewasa18.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002218; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"invoice-records.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002219; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"invoice.vrizm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002220; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ip-107-180-73-47.ip.secureserver.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002221; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ip-184-168-166-154.ip.secureserver.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002222; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"iphonemedicalphotography.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002223; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ippa.or.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002224; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ipv4x-201-88-101-77.nl"; content:"Host"; http_header; classtype:attempted-recon; sid:200002225; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"irenterprises.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200002226; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"irequest-beneficiary-removal.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002227; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"irisdigi-labs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002228; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"irstds.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002229; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"isamayy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002230; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"isfirsatibul.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002231; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"isqlglobal.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002232; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"it-europe564598-com.filesusr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002233; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"it-friedli.ch"; content:"Host"; http_header; classtype:attempted-recon; sid:200002234; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"it-supportdesk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002235; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"it.melnikhotels.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002236; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"itac.edu.az"; content:"Host"; http_header; classtype:attempted-recon; sid:200002237; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"italia-mobili.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200002238; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"itastexnikomar.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002239; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"itau.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200002240; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"itau.riweb.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002241; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"itaubrcard.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002242; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"itaucardverificacao.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002243; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"itechcircle.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002244; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ithelpservicedesk.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002245; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"itilscob5.ams3.digitaloceanspaces.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002246; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"itisrighi.fg.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200002247; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ix.chauffagebois-hiver.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002248; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"izcalttia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002249; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jabezrealtyservices.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002250; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jaccs-jp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002251; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jaccs.co.jp.fssdh.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002252; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jaccs.co.jp.mtjlb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002253; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jaccs.co.jp.qecsk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002254; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jacobliston.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002255; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jagex.nu"; content:"Host"; http_header; classtype:attempted-recon; sid:200002256; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jaggaauto.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002257; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jalfre.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002258; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jam-023d.gitlab.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200002259; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamescamacho28.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002260; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jamescorretor.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002261; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jameshallybone.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002262; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"janerodrigues.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002263; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jasdahsfh.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200002264; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jaten-jaten.karanganyarkab.go.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002265; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"javaboybr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002266; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jaysuntravels.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002267; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jbgroup.com.py"; content:"Host"; http_header; classtype:attempted-recon; sid:200002268; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jcb-carb.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002269; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jcb-jp.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200002270; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jcbadminsee.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002271; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jcroederchipplug.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002272; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jdih.sambas.go.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002273; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jeffreybcam.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002274; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jenis9q.dx.am"; content:"Host"; http_header; classtype:attempted-recon; sid:200002275; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jeranglah-rendah.nusantara.net.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002276; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jetgw.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002277; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jetprinterrepairs.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002278; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jeuxhtml5-orangefr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002279; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jeuxnys.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002280; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jewellerystore.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200002281; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jflkp.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200002282; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jhanjartv.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002283; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jhkkyuy.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002284; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jibnubank.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002285; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jiji-js.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200002286; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jk3bt83s.r.eu-west-1.awstrack.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200002287; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jlaser.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002288; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jlogine.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002289; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jnovemmaone.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200002290; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jo4gl3a26qsqmbldlykfglmaka-adwhj77lcyoafdy-www-paypal-com.translate.goog"; content:"Host"; http_header; classtype:attempted-recon; sid:200002291; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jobsaraby.online"; content:"Host"; http_header; classtype:attempted-recon; sid:200002292; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joecamera.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002293; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joeypmemorialfoundation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002294; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joeytorres.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002295; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"johannessscinders.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200002296; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"john-ashley.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200002297; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"join-group1.whatsapp-invite518.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200002298; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"join-grubwhatsaapp.se.ke"; content:"Host"; http_header; classtype:attempted-recon; sid:200002299; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"join-grupwa.event76.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002300; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"join-grupwhatsapp18.forumz.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200002301; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"join-whatapp.otzo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002302; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"join-whatsapp-bokep.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002303; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"join-whatsappk8wh.xxuz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002304; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"join.grub-wa179.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200002305; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"join.grup-whatsapphott.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002306; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joindewasa.qpoe.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002307; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joingroup2.myz.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200002308; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joingrup-online.joingrupwhatsapp-2021new.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002309; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joingrup3466.selleb-29.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200002310; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joingrupbudi01gaming.toh.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200002311; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joingrupwa18.fill-ip.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002312; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joingrupwahtsapp759.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200002313; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joinngrubwa.itsaol.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002314; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joinscattwhatsapp99.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002315; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joinsgrubbokep.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200002316; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joinwa18newgnz.zzux.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002317; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joinwa8tgf.dynserv.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002318; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jokerspins18.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002319; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joki.hop.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002320; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jornadaonline.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200002321; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"josuejr.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002322; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joul.co.kr"; content:"Host"; http_header; classtype:attempted-recon; sid:200002323; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"journeyeng.ca.healthinsurez.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002324; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jp-amazon-check.a1t.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002325; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jp-amazon-check.c15.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002326; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jp-amazon.p6o.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002327; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jp110.amazoncojpaccountsafe.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200002328; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jpassociate.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200002329; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jsbyv.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200002330; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jsitor.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002331; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jstrieb.github.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200002332; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"juanthradio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002333; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"juclonocontest2.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002334; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"judithleoni.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002335; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"judysigner.cafe24.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002336; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jugosdelvalle.com.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200002337; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"junglefunandadventure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002338; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jurlebedev.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002339; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"justgot.gonevis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002340; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"justlookapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002341; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"justsayingbro.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002342; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"justshowerdoorsllc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002343; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jvd6.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002344; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jyotsacademy.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200002345; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"k2rr3qoxpc32fi5qsdgnjs65r4-adwhj77lcyoafdy-sites-google-com.translate.goog"; content:"Host"; http_header; classtype:attempted-recon; sid:200002346; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"k5p4-res.phsarrealestate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002347; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"k8923.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200002348; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kabbeshco.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002349; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kadinterry64y.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002350; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalea-poke.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200002351; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kalkalgroup.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002352; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kama.hop.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002353; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"karacacomunicacao.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002354; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"karavella12.hop.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002355; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"karim-gawad.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002356; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kartaltepespor.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002357; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kartarky-online.cz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002358; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"karunruk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002359; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kashmir-packages.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002360; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kayemcray.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002361; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kayhatch.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002362; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kb.growbydata.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002363; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kblessedmom.com.np"; content:"Host"; http_header; classtype:attempted-recon; sid:200002364; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kbstitchdesigns.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002365; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kdlscaffolding.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002366; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kdocs.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200002367; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kecmanijada.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002368; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"keepcurrents-sslcertify0-office.s3.us-west-000.backblazeb2.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002369; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kelpiesinc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002370; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ken.kulaklikdergisi.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002371; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kenchezhair.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002372; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kenyaembassyjuba.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002373; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"keramikadecor.com.ua"; content:"Host"; http_header; classtype:attempted-recon; sid:200002374; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ketodessertyum.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002375; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"keyboardtreasures.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002376; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kh3wfp6f.easy.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200002377; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"khabargharghoda.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002378; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kharidekalayeirani.ir"; content:"Host"; http_header; classtype:attempted-recon; sid:200002379; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"khayyamadeel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002380; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kingnetitsys.wapka.website"; content:"Host"; http_header; classtype:attempted-recon; sid:200002381; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kinstationery.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002382; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kinya.byethost7.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002383; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kit.mishkanhakavana.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002384; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kitapbursa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002385; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kivenstars.cloudaccess.host"; content:"Host"; http_header; classtype:attempted-recon; sid:200002386; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kjsa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002387; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kkachi.co.kr"; content:"Host"; http_header; classtype:attempted-recon; sid:200002388; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"klantenservicebelgies.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002389; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"klikbsi.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002390; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kloingforwardhfg.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002391; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"klothsq.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002392; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"klveiculosmontealto.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002393; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"km4o0.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200002394; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"knarle-neomenia.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002395; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kojd6.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200002396; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kokoalets.dx.am"; content:"Host"; http_header; classtype:attempted-recon; sid:200002397; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"konfirmasi-data-facebook8.webnode.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002398; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"konskij-vozbuditel.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002399; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kontoopdatering.appleld.dk.opdatering.dspbrand.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002400; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kontoservice008.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002401; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"koreiamotors.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002402; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"korespodencja-online.fun"; content:"Host"; http_header; classtype:attempted-recon; sid:200002403; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"korespodencja-online.host"; content:"Host"; http_header; classtype:attempted-recon; sid:200002404; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"korespodencja-platnosc.cyou"; content:"Host"; http_header; classtype:attempted-recon; sid:200002405; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"korespodencja-platnosc.website"; content:"Host"; http_header; classtype:attempted-recon; sid:200002406; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"koskas.activehosted.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002407; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kourabiika.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200002408; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kovolem.cz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002409; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kozlaw-validate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002410; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kozlaw-validates.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002411; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kozlaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002412; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"krabi.go.th"; content:"Host"; http_header; classtype:attempted-recon; sid:200002413; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"krfzednl.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002414; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"krieagle.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002415; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kristallsolucoes.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002416; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kshconsultingllc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002417; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ksmcixosee.ddns.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002418; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ktpn.kalisz.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200002419; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kualazone.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002420; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kubud.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200002421; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kuchkuchnights.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002422; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kuriyama1.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200002423; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kurortnoye.com.ua"; content:"Host"; http_header; classtype:attempted-recon; sid:200002424; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kusoe.edu.np"; content:"Host"; http_header; classtype:attempted-recon; sid:200002425; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kutschergwoelb.at"; content:"Host"; http_header; classtype:attempted-recon; sid:200002426; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"l.royal-eng.ps"; content:"Host"; http_header; classtype:attempted-recon; sid:200002427; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"l1zuo.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200002428; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lacie_killin.gitlab.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200002429; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"laelitestudio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002430; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"laibia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002431; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lakp.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200002432; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lamoorespizza.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002433; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lamvb.czweb.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002434; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lanubegeek.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002435; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lanuevavitrina.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200002436; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lapedgodang.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200002437; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lareference.ac.ma"; content:"Host"; http_header; classtype:attempted-recon; sid:200002438; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"larrybarronmusic.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002439; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lasersnab.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002440; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lasertec-mi.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002441; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"latinotravel.cz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002442; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"latmasoud.persiangig.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002443; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lausd-ignni.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200002444; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lausd-ignni.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200002445; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lausd-purduee.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200002446; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lausd-purduee.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002447; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lbcoinvirementfonds.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002448; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lbcpzonasegurabeta.rf.gd"; content:"Host"; http_header; classtype:attempted-recon; sid:200002449; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lboindustrial.com.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200002450; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lctafrica.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002451; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ldsplanettt.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002452; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"le-diablotin-rouen.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002453; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"learning.validate.santander.digital"; content:"Host"; http_header; classtype:attempted-recon; sid:200002454; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"leboncoin01authserver.kiev.ua"; content:"Host"; http_header; classtype:attempted-recon; sid:200002455; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lecord.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002456; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lectiocolombia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002457; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"legendtitleagency.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002458; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"legitshop.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200002459; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"leiaaesthetic.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002460; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"leitersadvogados.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002461; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lekkimuslimschools.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002462; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lenagruessdich.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002463; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lender.sandbox.natwest.poweredbydivido.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002464; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lesbenwelt.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200002465; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"letolab.nl"; content:"Host"; http_header; classtype:attempted-recon; sid:200002466; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lexnotes.com.ng"; content:"Host"; http_header; classtype:attempted-recon; sid:200002467; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lfelelei.agilecrm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002468; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lgbtstlouis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002469; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lgt-plc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002470; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"libertyypmedia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002471; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"library.foraqsa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002472; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"licensekeysfree.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002473; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"licogi18.com.vn"; content:"Host"; http_header; classtype:attempted-recon; sid:200002474; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lifecard.co.jp.hongzewh.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002475; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lifeccrd.co.jp.bet36000.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002476; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"liftershower.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002477; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lightlink.com.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200002478; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lihi3.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200002479; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lik-prom.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002480; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"likolaw.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002481; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"likss-updat-schb.demopage.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200002482; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"limpiezadeobras.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200002483; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lindalpilcher.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002484; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"linesoe.github.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200002485; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"link.upnyk.ac.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002486; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"linklist.bio"; content:"Host"; http_header; classtype:attempted-recon; sid:200002487; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"linkware.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002488; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lion.main.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200002489; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"liquidateam.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200002490; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"listingfun.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002491; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"literasi.widuri.ac.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002492; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"liters-prefeast.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002493; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"littleelmapartments.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002494; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"littlefoots.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002495; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"live-site.hopto.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200002496; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"liveloginoffice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002497; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"livingemeraldjayne.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002498; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"livraisonexpress.customervalidationprotocol.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002499; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lizzweightwatchers.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002500; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloyd-advicepage.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002501; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloyd-reviewdata.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002502; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloyd.bank-verifydevice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002503; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydbank-accountbreach.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002504; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydbank-connect-payee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002505; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydbank-device-help.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002506; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydbank-devicehelp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002507; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydbank-online-secures.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002508; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydbank-secure-customers.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002509; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydbank-securebanking.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002510; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydbank-secures-online.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002511; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydbank-support-team.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002512; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydbanking-connection.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002513; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydbanking-onlineaccess.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002514; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydbanking-payeehelp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002515; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydbanking-securelogin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002516; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydplc-verify.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002517; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloyds-bank-help-page.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002518; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloyds-deregister-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002519; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloyds-payee-uk-alert-verify.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002520; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloyds-payeecancellations.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002521; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloyds-uk-bank.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002522; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.authenticate-cancellation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002523; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.cancellation-payee-secure-auth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002524; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.deregister-cancellation-payee-secure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002525; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.deregister-payee-secure-auth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002526; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.deregister-payee-security-auth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002527; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.login-personal-devices.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002528; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.online-auth-verify-secure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002529; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.online-security-auth-verify.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002530; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.online-visit-secure-auth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002531; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.personal-devices-login.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002532; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.personal-login-secure-payee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002533; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.register-security-online.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002534; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.secure-device-protect.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002535; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.secure-online-deregister.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002536; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.secure-personal-device-login.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002537; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbankplc.secure-personal-device-login.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002538; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsplc-authorisation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002539; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsplc-authorise.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002540; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloyduk-newdevice-authorised-online.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002541; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloyduk-newdevice-registered-online.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002542; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloyduk-newpayee-approved-online.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002543; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloyduk-online.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002544; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloysecauth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002545; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloytsdsecure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002546; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lltlkp.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200002547; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmlenzitrasporti.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002548; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lms.ozyegin.edu.tr"; content:"Host"; http_header; classtype:attempted-recon; sid:200002549; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lnk.pmlti-etai-2.ovh"; content:"Host"; http_header; classtype:attempted-recon; sid:200002550; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lnsformediasupport.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200002551; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"localbusinesscitationbuilding.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002552; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"localservicejob.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002553; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"locked-recover.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200002554; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lofon-add.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002555; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"logbromw.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002556; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"logex.com.tr"; content:"Host"; http_header; classtype:attempted-recon; sid:200002557; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login-authentication.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002558; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login-bancoestado-web.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200002559; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login-bank.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002560; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login-cancellation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002561; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login-liteacebook.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002562; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login-live.com-s02.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200002563; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login-live.com-s02.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002564; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login-manage-payeeteam.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002565; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login-orange-fr-mail.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002566; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login-secure-three.uk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002567; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login-securepass.serveftp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002568; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login-webregistrobr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002569; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.live.dns-ssl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002570; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.microsoftonline.workinghuman.careers"; content:"Host"; http_header; classtype:attempted-recon; sid:200002571; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.office-server.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200002572; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.officeservers.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002573; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.vdohnovenie.org.ua"; content:"Host"; http_header; classtype:attempted-recon; sid:200002574; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.wipro.design"; content:"Host"; http_header; classtype:attempted-recon; sid:200002575; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"login.xn--blockchan-7sb.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002576; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"logintomybtaccount.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002577; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"logintomybtbusiness.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002578; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"loireorland.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002579; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"loja.brasilliker.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002580; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lombard11.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200002581; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lookdigital.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200002582; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"loparskorse.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002583; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lorvencomputers.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002584; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"loterianacionalplus.es"; content:"Host"; http_header; classtype:attempted-recon; sid:200002585; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"loudweb.czweb.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002586; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"loving-mirzakhani-a1d582.netlify.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200002587; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"loyaltyportion.win"; content:"Host"; http_header; classtype:attempted-recon; sid:200002588; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"loydsbank.co.uk-device-gb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002589; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"loydsbank.co.uk-mydevices.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002590; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lp2m.umsu.ac.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002591; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lqg8u8.webwave.dev"; content:"Host"; http_header; classtype:attempted-recon; sid:200002592; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lsrekn4zfgaoagus3egm5atr24-jj2cvlaia66be-online-mbank-pl.translate.goog"; content:"Host"; http_header; classtype:attempted-recon; sid:200002593; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"luckow.adv.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002594; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lucky-new-spin182.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200002595; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"luckyspinseason18.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002596; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lucy-walker.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002597; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ludiequip.es"; content:"Host"; http_header; classtype:attempted-recon; sid:200002598; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lus-netflix.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002599; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"luxsho.com.tw"; content:"Host"; http_header; classtype:attempted-recon; sid:200002600; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lvk.hop.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002601; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lwd.org.kh"; content:"Host"; http_header; classtype:attempted-recon; sid:200002602; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lynkos.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002603; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lyrevie.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200002604; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lyyhty.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200002605; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"m-facebook.mypi.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200002606; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"m-faceboook.mypi.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200002607; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"m-nordea-fi.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002608; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.4everproxy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002609; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.emd9856.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002610; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.faceebok.com-listing.id45346765852.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002611; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.g22m.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002612; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.hf2666.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002613; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.hf736.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002614; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"m.monteverdi.continentalwingates.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002615; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"m42club.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002616; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"m54af8.webwave.dev"; content:"Host"; http_header; classtype:attempted-recon; sid:200002617; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"machinta.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002618; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"maciel.med.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002619; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"macjakarta.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002620; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"macle.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200002621; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"madkap.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200002622; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"madrugadaolanches.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002623; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"magnetarbpo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002624; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mahdistock.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002625; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail-deliver.support"; content:"Host"; http_header; classtype:attempted-recon; sid:200002626; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail-delivery-info.support"; content:"Host"; http_header; classtype:attempted-recon; sid:200002627; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail-generali.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002628; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail-orange23.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002629; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail-royal-update.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002630; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.02alertbilling.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002631; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.arigo.ng"; content:"Host"; http_header; classtype:attempted-recon; sid:200002632; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.armata-neagra.ro"; content:"Host"; http_header; classtype:attempted-recon; sid:200002633; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.bacritkita.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002634; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.bancoitaucard.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002635; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.charperimagedesign.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002636; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.cmuhawaii.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002637; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.enrollmoreclientsbootcamp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002638; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.fbpage-rules-5812937.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002639; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.fbpoliciesrec.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002640; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.harmonmedical.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002641; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.helprasuwanepal.org.np"; content:"Host"; http_header; classtype:attempted-recon; sid:200002642; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.hsuk-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002643; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.inatel.pt"; content:"Host"; http_header; classtype:attempted-recon; sid:200002644; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.information-page-disclaimer-2021.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002645; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.ingegneriaingonlin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002646; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.jimdavidsoncolumn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002647; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.klikbsi.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002648; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.liveloginoffice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002649; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.lloysecauth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002650; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.login-liteacebook.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002651; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.molcancd.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002652; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.mymp3remix.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200002653; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.netflix.billing-australia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002654; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.netflixpartycanada.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002655; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.o2-confirm-billing-info.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002656; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.o2-failure-billing-update.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002657; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.securing-hostlink.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002658; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.tencentus.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200002659; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.thelovegarden.com.ph"; content:"Host"; http_header; classtype:attempted-recon; sid:200002660; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail.wheel1factory.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002661; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mail2.mclink.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200002662; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mailorange1254.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002663; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mailtraffic.dnsresolution.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002664; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mailupgrade2info.site44.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002665; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mailus.ovh"; content:"Host"; http_header; classtype:attempted-recon; sid:200002666; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"main.d1f6h6dpfudolh.amplifyapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002667; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"main.d1o5w2cgv976pr.amplifyapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002668; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"main.d25p8q0uyge9hf.amplifyapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002669; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"main.d297c2yt8lktld.amplifyapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002670; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"main.d2nnayeg58bm3i.amplifyapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002671; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"main.d3pjf238j3b9xy.amplifyapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002672; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"main.d3v486co0ptwb7.amplifyapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002673; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mainehomeconnection.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002674; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"maisonneuve-menuiserie-pornic.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200002675; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"maj-dofus.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200002676; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"majorwirebankssynray.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002677; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"makrjing.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002678; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"maksi.feb.unib.ac.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002679; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mala-riba.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002680; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"malaysialiveaboards.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002681; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"man1bantul.sch.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002682; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"manage-cancelpayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002683; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"manage-device-authentication.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002684; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"manage.fanshuyou.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002685; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"managehosting.areaclienti.aruba.it.u1336879.cp.regruhosting.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002686; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"managepayee-mobile.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002687; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"managmentsservice.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200002688; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"manaplas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002689; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"manateetreeservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002690; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mandat24.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002691; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"manhattaneurope.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002692; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mapadamente.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002693; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mapleaiongroup.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002694; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"maquinasdecartaosemaluguel.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002695; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"marceluoribeiro.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002696; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"margarita.md"; content:"Host"; http_header; classtype:attempted-recon; sid:200002697; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"margin.today"; content:"Host"; http_header; classtype:attempted-recon; sid:200002698; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mariagiasena1001.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002699; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"marisaprieto.es"; content:"Host"; http_header; classtype:attempted-recon; sid:200002700; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"marjaharmon.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002701; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"marjonhomes.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002702; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketplace-65985214.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002703; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketplace-housing-listing32456.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002704; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"marketvit.by"; content:"Host"; http_header; classtype:attempted-recon; sid:200002705; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"massimobacchini.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002706; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"masterdrive.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002707; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"match.lookatmynewphotos.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002708; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"matematika.fkip.untirta.ac.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002709; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"materialspinpubgm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002710; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mationpagedisclmationpagedisclmationpagedisclmationpagediscl.informationpageclaim0003.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002711; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mavragatakianike.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002712; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"maximasport.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200002713; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"maximilianschnauzers.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002714; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxoxa4772.systeme.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200002715; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"maxsegurebn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002716; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mayclickbank.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002717; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbex.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002718; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mcafeecomactivates.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002719; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mccapfunds.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002720; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mccarthyelectrical.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002721; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mclainjonesproperties.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002722; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mclaren-arg.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200002723; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mclaren-mo.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200002724; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mclarren.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200002725; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mcns.co.za"; content:"Host"; http_header; classtype:attempted-recon; sid:200002726; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mcpss-dic.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002727; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mct04389.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002728; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mdurucan.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002729; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"me-helpdesk-fbclid8949837273742.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200002730; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"meat.uniandes.edu.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200002731; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mechanicalresource.com.healthinsurez.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002732; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"medacademy-a.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002733; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mediainstagram.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002734; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"medicalspaskincare.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002735; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mediclinicabudhabi.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002736; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mediclinicdubaimall.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002737; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"medievalfactory.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002738; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"meeting-23900123090123.bitbucket.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200002739; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"meetingteammicro.azurefd.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002740; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"megacredi.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002741; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"megasolar.lk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002742; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"megayourname.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002743; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mein-tan2go.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200002744; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mein.gebuhrenfrei.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002745; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"melodika.com.tr"; content:"Host"; http_header; classtype:attempted-recon; sid:200002746; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"members.theatrewomen.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002747; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"memorialpremiersleepcenter.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002748; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"memrise.online"; content:"Host"; http_header; classtype:attempted-recon; sid:200002749; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mentoring.beautyforashes.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002750; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"meritroyalbetgiris20.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002751; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"merveyilmazericmimarlik.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002752; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mesquecamping.es"; content:"Host"; http_header; classtype:attempted-recon; sid:200002753; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"messagerie-fixe18.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002754; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"messagerie-llebon-coins.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002755; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"messagerie-orange-pro-20212.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002756; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"messagerie-orange155.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002757; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"messagerie-vocale168.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002758; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"messagerie-vocale175.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002759; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"messagerie22.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002760; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"messagerieorange44.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002761; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"messelive.tv"; content:"Host"; http_header; classtype:attempted-recon; sid:200002762; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"messtours.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002763; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mester.info.hu"; content:"Host"; http_header; classtype:attempted-recon; sid:200002764; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"metaltubos.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002765; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"metamask-wallets.online"; content:"Host"; http_header; classtype:attempted-recon; sid:200002766; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"metamask.cloud"; content:"Host"; http_header; classtype:attempted-recon; sid:200002767; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"metamasknet.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200002768; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"metrocti.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002769; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"meuspontosbradesco.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002770; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"meyden.rw"; content:"Host"; http_header; classtype:attempted-recon; sid:200002771; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mfacebook.blogspot.rs"; content:"Host"; http_header; classtype:attempted-recon; sid:200002772; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mfacebook.blogspot.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002773; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mi-air-onedrive.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002774; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"micato.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002775; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"michelleberkey.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002776; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"microsoft-excel.kr.jaleco.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002777; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"microsoftoffice-365.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002778; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"microsoftserviceupgrade.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002779; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"microsoftwebserver.mfs.gg"; content:"Host"; http_header; classtype:attempted-recon; sid:200002780; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"microsofy.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002781; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"micup.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200002782; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"micvweb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002783; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"midadholdings.com.illusionsxpllc.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002784; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"midasbuyeventsnow.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002785; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"midasbuyofficial.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002786; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"midasglitter.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002787; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"midbuy.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002788; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"midnightluna1.typeform.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002789; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"midshopping.ro"; content:"Host"; http_header; classtype:attempted-recon; sid:200002790; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"midwayisd-auth-adobe.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200002791; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"midyatmimaritas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002792; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"miecompany.8b.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200002793; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mijn-authenticatie.digital"; content:"Host"; http_header; classtype:attempted-recon; sid:200002794; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mijnbuitenhuis.nl"; content:"Host"; http_header; classtype:attempted-recon; sid:200002795; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mijncontract-fortisbanking.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002796; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mijneasy-banking.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002797; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"milanobet0279.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002798; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"millenniumapp-pt.servepics.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002799; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"millenniumstaffing.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002800; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"milliondollarsproject.fxfdq.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002801; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"millionsoccer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002802; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"miloserdie-rzn.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002803; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mimecast.fmlms.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002804; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mimecast.swagonline.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002805; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"minsterabbeynuns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002806; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"miplab.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002807; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mipymescolombiana.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002808; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mirandaassociates.biz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002809; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"miss-peggy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002810; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"missed-delivery.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200002811; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"missionshashank.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002812; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mistimbas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002813; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mitrasolusiseragam.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002814; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mivtsystems.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002815; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mixi.guru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002816; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mjayme9jdg9izxixmjeydgg.filesusr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002817; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mjkkennel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002818; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mjphotozone.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002819; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mlgcapitals.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002820; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmfarms.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200002821; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmprsatx.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002822; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mms-orange17.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002823; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mms.tucsonhispanicchamber.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002824; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmsportable.kissr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002825; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmsvocale.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002826; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mnp-postscriptum.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002827; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mobile-alerts-o2.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002828; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mobile-cancelpayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002829; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mobile-cancelpayees.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002830; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mobile-portail.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200002831; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mobile-srftoken-benutzername.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200002832; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mobile.facebook.com.videos.facebook.lpt-abbepierre-bf.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002833; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mobilede-login.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200002834; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mobiledesuchen.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200002835; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mobipay-systems.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002836; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mockup.metradigitalmedia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002837; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mohangroups.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200002838; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mohid.scizers.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002839; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"moj.aktiv.rs"; content:"Host"; http_header; classtype:attempted-recon; sid:200002840; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"moneyviewfinance.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200002841; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"monirshouvo.github.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200002842; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"monitor254.co.ke"; content:"Host"; http_header; classtype:attempted-recon; sid:200002843; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"monomobileservice.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002844; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"monroy-proyectos.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002845; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"monstercarp.rn86.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200002846; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"monthly-o2-helpvia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002847; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"moodle.lms-su.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002848; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"moracantik.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002849; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"moreinterestworg.gb.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002850; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mouadarrivalco.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002851; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mrcstyle.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002852; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ms-365.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002853; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"msantander.es"; content:"Host"; http_header; classtype:attempted-recon; sid:200002854; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"msn-live2.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002855; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"msoffice506.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002856; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"msrsolutions.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200002857; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mstaxmultiservices.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002858; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mta-round-cube.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200002859; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mufg-co.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002860; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"multirbnacion.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002861; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"muscogee-conm.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200002862; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"musicisit.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200002863; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"musing-cori-ab8056.netlify.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200002864; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mutatio.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200002865; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"muxt.mi-me.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002866; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mx0.arqsys.srv.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002867; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mxrr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002868; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my-devices-halifax.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002869; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my-eeid.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002870; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my-jcb-co-jp-aa.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002871; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my-jcb-co-jp-aq.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002872; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my-jcb-co-jp-az.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002873; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my-jcb-co-jp-uz.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002874; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my-site219.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002875; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my-transactions-netflix.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002876; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my.famous.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200002877; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my.jcb.co.adminssilologin.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002878; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my.jcb.co.jp.adminsplayins.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002879; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my.jcb.co.jp.ahhxg.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002880; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my.jcb.co.jp.souaq.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002881; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my.nativeforms.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002882; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my02billing.dev"; content:"Host"; http_header; classtype:attempted-recon; sid:200002883; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my2ktop.company.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200002884; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my2ktop.ecwid.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002885; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"my3-update.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002886; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myauthorz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002887; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mybasementd0ctor.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002888; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mybigfatlistbuilder.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002889; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mybpos.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002890; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myburbankvacations.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002891; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mycoerver.es"; content:"Host"; http_header; classtype:attempted-recon; sid:200002892; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mydetails-mynetflix.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002893; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myee-billing-info.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002894; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myee-id.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002895; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myee-securedlogin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002896; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myeeyouree.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002897; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myetherwalletk.vip"; content:"Host"; http_header; classtype:attempted-recon; sid:200002898; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myetncrenwallper.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002899; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myhashtoken.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002900; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myhealthinsquotes.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002901; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myhomeecia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002902; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myjcb-card.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002903; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myjcb-vip.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002904; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myjcb.adminsoline.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002905; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myjcb.amazovpsee.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002906; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myjcb.cn.cheapforwebsite.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002907; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myjcb.cn.emailonlineavailable.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002908; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myjcb.jp.domainssecurity.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200002909; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myjcb.updateconpyjcb.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002910; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mykonos.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200002911; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mylovejar.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002912; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mymed.lk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002913; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mymelody.or.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200002914; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mymensinghbarta24.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002915; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mymentalhealthday.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002916; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mymonero.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200002917; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mymweb-owner.at.ua"; content:"Host"; http_header; classtype:attempted-recon; sid:200002918; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myo2-billing-error28.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002919; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myo2-billing-error83.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002920; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myownrecords.rocks"; content:"Host"; http_header; classtype:attempted-recon; sid:200002921; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myparcel-approval-fees.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002922; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myparcel-delivery-fees.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002923; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mypestcalls.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002924; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myprocurements.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002925; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myqatar.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002926; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mysnapschat.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002927; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mytheamsauthecent.wapgem.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002928; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myupdates-mynetflix.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002929; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myvodaphone-secure-update.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002930; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"n26-particuluar-n26-personal-own.boxofbusinessblogs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002931; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"n4r7u.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200002932; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"n9qyb.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200002933; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nabagejec1893.blogspot.sg"; content:"Host"; http_header; classtype:attempted-recon; sid:200002934; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nabaud.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002935; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nabtolonu1913.blogspot.kr"; content:"Host"; http_header; classtype:attempted-recon; sid:200002936; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nacionalservicos.net.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002937; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nagari.or.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002938; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nakamistrad.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002939; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nanohairtech.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002940; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"naranja-users.auth0.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002941; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"narant-uaice-amnoneonm.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200002942; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"narrativesummit.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002943; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nasih-network.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002944; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nat-online-reviewpayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002945; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nat-online-revokepayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002946; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nat-payee-review.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002947; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"natwest-authp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002948; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"natwest-removepayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002949; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"natwest.authenticate-personal-web.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002950; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"natwest.nwolb-device-login.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002951; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"natwest.nwolb-login-auth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002952; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"natwest.personal-login-online.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002953; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"natwest.secure-auth-personal-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002954; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"natwest.secure-devices-personal-login.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002955; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"natwest.secured-online-verify.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002956; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"natwest.secured-personal-verify.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002957; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nbpropiedades.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200002958; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ndotk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002959; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nebojsega.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002960; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nedbank.demdex.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002961; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nef.com.pk"; content:"Host"; http_header; classtype:attempted-recon; sid:200002962; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"neighborless-stand.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002963; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nelsonjustus.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200002964; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"neponsetfriends.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002965; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nequipay-paxful.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002966; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"netciti.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200002967; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"netevin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002968; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"netflix-appl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002969; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"netflix-com.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002970; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"netflix-verify-billinguk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002971; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"netflix.avsita-oil.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200002972; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"netflix.pl.soincoips.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002973; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"netflix.sourceaudio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002974; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"netflix.verifybillingdetail.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002975; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"netflixloginhelp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002976; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"netlana.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002977; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"netprogress.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200002978; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"netservice-upd.tumblr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002979; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"netstotian2apluscojp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002980; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"network.innovatedm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002981; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"neutrax2u.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002982; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"new-control-pamis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002983; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"new-devicehelp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002984; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"new-hs-payeeadded.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002985; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"new-payee-add.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002986; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"new-payee-lloyds.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002987; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"new-recipients.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002988; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"new.29studios.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002989; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"new.semcore.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200002990; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"new1-paypal.blogspot.sn"; content:"Host"; http_header; classtype:attempted-recon; sid:200002991; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"new2.froid-guyader.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200002992; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"newboi365onlineupdate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002993; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"neweventsmobilelegend.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002994; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"newlien.site44.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002995; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"newlifebiblechurch.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200002996; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"newlifeschooloftheology.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002997; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"newonline-payee-restricted.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002998; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"newonline-restrict-payee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200002999; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"newsbrigade.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003000; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"newsimdigital.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003001; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"newsonghannover.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200003002; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"newspubgs18.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003003; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"newton-us-ocom.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200003004; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nextdoor-ignii.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003005; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nextdoormke-purdue.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200003006; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ngx273.inmotionhosting.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003007; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nhsmgt-pp.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003008; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ni212065-1.web02.nitrado.hosting"; content:"Host"; http_header; classtype:attempted-recon; sid:200003009; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ni5641185-2.web04.nitrado.hosting"; content:"Host"; http_header; classtype:attempted-recon; sid:200003010; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"niedopla.fun"; content:"Host"; http_header; classtype:attempted-recon; sid:200003011; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nightvision.tech"; content:"Host"; http_header; classtype:attempted-recon; sid:200003012; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nikemedwrakia.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003013; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nikomac.main.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200003014; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nilay-new.glooh.nl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003015; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nine-box.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003016; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nineled.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003017; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nisvaliashop.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003018; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nisveceras.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003019; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"niuqi.euro-techno.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200003020; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nizotchauffage.bilty.be"; content:"Host"; http_header; classtype:attempted-recon; sid:200003021; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"njdiua-bsfsrz66.wpdevcloud.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003022; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"no6xb.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200003023; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-dfcrlajk.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003024; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-eqmzdzcl.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003025; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-giffgiso.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003026; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-gyuenowf.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003027; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-hupjklqj.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003028; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-hymyluyk.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003029; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-lrxmsqmv.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003030; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-mpvvvoqo.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003031; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-mullzsiy.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003032; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-nimuddpn.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003033; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-onsisljy.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003034; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-powsrozz.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003035; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-puwrkykl.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003036; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-qqhrshfg.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003037; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-rwowiwzp.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003038; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-rztwjtyn.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003039; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-tnxsqiil.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003040; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-tyvnrwno.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003041; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-uotnzsqm.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003042; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-uropvkux.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003043; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-vnqlnxry.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003044; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-vvvppxqo.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003045; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nocontent-xjsrpqym.velocityhub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003046; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nomadsland.kg"; content:"Host"; http_header; classtype:attempted-recon; sid:200003047; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"noncausative-systemproof.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003048; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nonstop-ks.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003049; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nordcity.by"; content:"Host"; http_header; classtype:attempted-recon; sid:200003050; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"noreply2redirect2.site44.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003051; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"noreplyattyahoomail.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003052; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"normativa-psd2web.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003053; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"northcountyluxuryrealestate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003054; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"northlakeroxx.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003055; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nota-online.host"; content:"Host"; http_header; classtype:attempted-recon; sid:200003056; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nota-online.tech"; content:"Host"; http_header; classtype:attempted-recon; sid:200003057; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"notags-facebook-08131630.azamov.uz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003058; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"notariagalvez.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003059; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"notendur.hi.is"; content:"Host"; http_header; classtype:attempted-recon; sid:200003060; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nothing-is-impossible-anything-can-happen-as-page.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003061; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"noticias.canal22.org.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200003062; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"notification-page-claim-restriction-004.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003063; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"notifypaymentsinfo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003064; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"notnot.cyzjsj.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200003065; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"noutbookofff.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003066; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nova-grafic.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003067; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"novacantu.pr.gov.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200003068; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"novinroyapolymer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003069; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nozed-uname.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003070; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nra.gov.np"; content:"Host"; http_header; classtype:attempted-recon; sid:200003071; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nrk.one"; content:"Host"; http_header; classtype:attempted-recon; sid:200003072; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ns3pssionntngoal.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200003073; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ntf-lang-ja-jp.kingking017.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003074; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuanciel.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003075; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuevalyon.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003076; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuovesicurezzeonline.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003077; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuovo-portale-isp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003078; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuru0147.website2.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200003079; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nutrifrezze.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003080; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nutrisilviaramos.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200003081; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuvuneu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003082; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nv.snprobbx.pbz.r.de.a2ip.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003083; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nvuitpra.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003084; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nw-securedfailure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003085; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nwolb.default.aspx.cookiecheck.refferiddent.aspx.online.cross-press.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003086; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nwolbderegisterdevice-access.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003087; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nwolbsecure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003088; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nwsecure-iproceed-icancel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003089; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nwsecure-newdevice-iproceed.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003090; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nwsecure-newpayee-cancel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003091; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nwsecurity-setdevice-icancel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003092; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nymccu.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200003093; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nzpost-returns.kapitirabbitcontrol.co.nz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003094; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-accountsecurity.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003095; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-authbill-secure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003096; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-bill-failure.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003097; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-billing-updatefailure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003098; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-billingplan.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003099; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-billsetup.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003100; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-failure-billing-update.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003101; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-processbilling-update.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003102; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-securebilling-update.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003103; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-ukresolutions.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003104; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-updatebill.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003105; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-updatebillingvia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003106; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-updatepayment.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200003107; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-via-updatebilling.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003108; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2.solution-verify.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003109; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2billingauth-update.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003110; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2billingdueupdate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003111; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2duebilling.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003112; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2monthlybilling-update.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003113; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2monthlybilling.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003114; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2updatedue-billing.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003115; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oandperformanc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003116; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oatiscozxmocxixc-forgiving-hartebeest-rp.eu-gb.cf.appdomain.cloud"; content:"Host"; http_header; classtype:attempted-recon; sid:200003117; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"objectstorage.me-dubai-1.oraclecloud.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003118; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"observation-point-ck355879462187964369849508-bg.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003119; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"observatoriodeourofino.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200003120; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"obslive.oss-eu-west-1.aliyuncs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003121; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"obzory-online-casino.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003122; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ocaque-domen.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003123; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oceantires.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003124; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"odbieraj-nagrody.com.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003125; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oferta-payment.tech"; content:"Host"; http_header; classtype:attempted-recon; sid:200003126; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ofertas--magazineluiza.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003127; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"offal.odoo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003128; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"office365.eu.vadesecure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003129; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"officeee.bubbleapps.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200003130; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"officence.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003131; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"officences.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003132; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"officentry.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003133; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"officested.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003134; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"officialevent.way.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200003135; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"officialismsschwartze.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003136; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"offrekrysnetflix.servehttp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003137; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ogz6d.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200003138; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oimazon.56vif719ndqwo.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200003139; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oivac.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003140; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ojnw.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200003141; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ojs.budimulia.ac.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003142; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"okeyciyiz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003143; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"okisdtograpgyuijnh675ttfr.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003144; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"old.chipfc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003145; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oldnfc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003146; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oldschool-runescape-bondrewards.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003147; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olesya-petrova.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003148; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olidooo.waca.tw"; content:"Host"; http_header; classtype:attempted-recon; sid:200003149; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olufe21.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003150; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx-banking.bid"; content:"Host"; http_header; classtype:attempted-recon; sid:200003151; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx-bezpieczne.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003152; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx-hold.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003153; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx-informacja.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003154; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx-myordin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003155; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx-ordin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003156; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx-paystill.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003157; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx-pl-konto-ref.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003158; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx-purchase.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003159; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx-rent.id23814.su"; content:"Host"; http_header; classtype:attempted-recon; sid:200003160; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx-seller.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003161; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx-send.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003162; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx-uzbekistan.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003163; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx-uzyskiwanie.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003164; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.bolxgift.online"; content:"Host"; http_header; classtype:attempted-recon; sid:200003165; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.deal-id.pw"; content:"Host"; http_header; classtype:attempted-recon; sid:200003166; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.deiivery.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003167; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.epaymasters.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003168; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.payd-info.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200003169; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.payment-checking.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003170; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-autoryzacja.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003171; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-buy.surf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003172; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-getpayment.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003173; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-makedeal.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003174; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-payed.surf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003175; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-posts.surf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003176; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-safes.surf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003177; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-safes.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003178; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-safes.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003179; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-safeway.icu"; content:"Host"; http_header; classtype:attempted-recon; sid:200003180; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-sale.store"; content:"Host"; http_header; classtype:attempted-recon; sid:200003181; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-sale.surf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003182; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-saleorder.casa"; content:"Host"; http_header; classtype:attempted-recon; sid:200003183; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-saleorder.icu"; content:"Host"; http_header; classtype:attempted-recon; sid:200003184; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-saleorder.store"; content:"Host"; http_header; classtype:attempted-recon; sid:200003185; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-saleorder.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003186; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-saleorders.casa"; content:"Host"; http_header; classtype:attempted-recon; sid:200003187; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-saleorders.cyou"; content:"Host"; http_header; classtype:attempted-recon; sid:200003188; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-saleorders.icu"; content:"Host"; http_header; classtype:attempted-recon; sid:200003189; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-saleorders.store"; content:"Host"; http_header; classtype:attempted-recon; sid:200003190; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-saleorders.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003191; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-saleorders.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003192; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-sales.casa"; content:"Host"; http_header; classtype:attempted-recon; sid:200003193; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-sales.icu"; content:"Host"; http_header; classtype:attempted-recon; sid:200003194; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-sales.store"; content:"Host"; http_header; classtype:attempted-recon; sid:200003195; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-sales.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003196; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-sales.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003197; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-saves.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200003198; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-smsinfo.surf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003199; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-upowaznienie.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200003200; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl-upowaznienie.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003201; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl.3d-secure.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003202; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl.oferta-payment.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003203; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl.oferta-payment.surf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003204; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.pl.safe.payments-id.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200003205; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.polska-oferdo.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200003206; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.polska-oterfa.cyou"; content:"Host"; http_header; classtype:attempted-recon; sid:200003207; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.polska-oterfa.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200003208; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.polska-oterfa.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003209; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olx.rwpay.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003210; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olxpl.id-173056.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003211; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olxpl.id23814.su"; content:"Host"; http_header; classtype:attempted-recon; sid:200003212; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olxpl.pay-secure.icu"; content:"Host"; http_header; classtype:attempted-recon; sid:200003213; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olxpraca.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003214; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olxro-curier.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003215; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"omesqiwines.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200003216; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ommsd.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003217; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"omnimarketingsolutions.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003218; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"omrixml.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003219; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"omsaicollege.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003220; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"omssd.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003221; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"on-me-ro.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003222; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onailsupply.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003223; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oncopharma-ae.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003224; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"one-3w6kjxwn4.vercel.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200003225; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oneaim.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200003226; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oneattonline.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003227; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onecreator.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200003228; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onetoomanydesign.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200003229; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlbc2.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003230; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"online-alertprotection.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003231; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"online-banking-personal-login.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003232; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"online-devicesecurity.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200003233; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"online-services-ee.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200003234; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"online.cheapstore2021.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003235; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"online.natwest-personal.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003236; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"online.natwest-supportcentre.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003237; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"online.natwest-welfare.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003238; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlineaccounts-bancodeoro.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003239; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinebanking-mtb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003240; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinebanking-payeerevoke.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003241; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlineboncoinviro.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003242; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinebusservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003243; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinepayee-restricted-service.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003244; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinepractice.cillbd.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003245; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlineroisupportupdate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003246; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinesharepoint.typeform.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003247; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinesohbet55.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003248; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinesohbet74.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003249; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinesohbet99.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003250; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlineugyvitel.hu"; content:"Host"; http_header; classtype:attempted-recon; sid:200003251; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinezeel.optimal.mn"; content:"Host"; http_header; classtype:attempted-recon; sid:200003252; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ooxvocalor.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003253; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"op-xi-nine.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200003254; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"openoffice.com.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003255; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"openstreetmap.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003256; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"operacionmultired1bn-web.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003257; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"operator-24.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003258; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"operator-platnosci.click"; content:"Host"; http_header; classtype:attempted-recon; sid:200003259; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"opfgmdm.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003260; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"opjkk.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003261; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"opretretopoptk.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003262; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"optiklin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003263; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oqhwhj.whatsapp-join-2.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200003264; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"or-ca.love"; content:"Host"; http_header; classtype:attempted-recon; sid:200003265; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ora-n.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003266; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orange-bvd.cosavostra.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003267; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orange-dcr.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200003268; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orange-loginfr0.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003269; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orange-mobile34.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003270; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orange-offre.mobile-forfait.client.travelforever.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003271; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orange-security.cloud.coreoz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003272; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orange.iobeya.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003273; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orange2506.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003274; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orange602.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003275; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orange624.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003276; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orangeci.answers.dimelo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003277; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orangeetmoi.fr-fonds.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200003278; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orangefr67.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003279; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orangemail12.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003280; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orangemail14.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003281; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orangemessagerie.icon.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200003282; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orangemobile446.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003283; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orangesms12.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003284; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orangewebmail0.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003285; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orcapm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003286; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ordo-maz.ir"; content:"Host"; http_header; classtype:attempted-recon; sid:200003287; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"org-nr.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003288; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"organicoslim.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003289; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"origanopintercla.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003290; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orionsbelttech.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003291; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orlandoareavacations.orlandoareavacation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003292; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orzech.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200003293; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"osa-amazon.date"; content:"Host"; http_header; classtype:attempted-recon; sid:200003294; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"osh11.labour.go.th"; content:"Host"; http_header; classtype:attempted-recon; sid:200003295; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"osh2.labour.go.th"; content:"Host"; http_header; classtype:attempted-recon; sid:200003296; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oslonorkaji.cloudaccess.host"; content:"Host"; http_header; classtype:attempted-recon; sid:200003297; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"osmaslo.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003298; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"osun.cz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003299; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"otomati-srl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003300; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"otomoto-h229.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003301; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"otomoto-konto54875424.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200003302; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"otomoto3452.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003303; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ourevolution.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003304; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ourlovmess.wordpress.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003305; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ourtimecom4.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003306; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ourwebprojects.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003307; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"outl00kupgrading.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003308; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"outlook-mailer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003309; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"outlook12861.activehosted.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003310; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"outlook1541489.webcindario.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003311; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"outlookhelpdesk.activehosted.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003312; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"outravantagem.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003313; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"overseasmexico.com.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200003314; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"owambewww.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003315; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"owaupgradeservice3.myfreesites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003316; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oximedica.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003317; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"p.wpage.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003318; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"p84ig.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200003319; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paavos.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200003320; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"package-fees.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003321; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"package-redelivery-mail.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003322; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"packssrl.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200003323; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"packstation-221.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003324; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"packstation-226.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003325; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"packstation-304.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003326; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paczkowodpd4you.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003327; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"page-contact-center02574.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003328; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"page-dashboard-option-2021.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003329; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"page-dashboard-option.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003330; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"page-termsverify267234.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003331; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"page7821552198fb.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200003332; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pages-and-community-standards.insting-berandal.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003333; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pageshome.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003334; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pagina2.news"; content:"Host"; http_header; classtype:attempted-recon; sid:200003335; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pagincolm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003336; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paiement-securise-leboncoin.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003337; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paiementdirect.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003338; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pailbailxom.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200003339; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"painelnovoacesso.servecounterstrike.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003340; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pakkepostnord.online"; content:"Host"; http_header; classtype:attempted-recon; sid:200003341; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"palmgardenn.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003342; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"panamericano-financial-institution.negocio.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200003343; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"panelweb-4cae2.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200003344; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paperboatmedia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003345; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"parcel-delivery-fees.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003346; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"parcel-deliveryreturn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003347; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"parcel-fees.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003348; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"parcel-id-updates.support"; content:"Host"; http_header; classtype:attempted-recon; sid:200003349; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"parcel-r0yalmai1-fee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003350; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"parcelfees-customs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003351; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paris-dgfip.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200003352; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"partelier.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003353; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"particulares-ban-k-ia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003354; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"passionfruit4576261.brizy.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200003355; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"patch-plume-pullover.glitch.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200003356; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pateltutorials.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003357; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pathayescon.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003358; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pathikareps.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003359; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"patricepurnell.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003360; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paulhishom.cloudaccess.host"; content:"Host"; http_header; classtype:attempted-recon; sid:200003361; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paulmitchellforcongress.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003362; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pawfection.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200003363; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pax4l.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003364; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paxful.com.ua"; content:"Host"; http_header; classtype:attempted-recon; sid:200003365; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paxluf.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003366; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pay-parcel-billing.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003367; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pay-sera.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200003368; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pay-today.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003369; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pay.moban.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003370; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pay.olx.pl.link-id784815.net.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003371; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pay16-olx.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003372; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pay22-olx.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003373; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pay41-olx.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003374; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paychekout.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003375; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"payee-authorise-login.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003376; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"payee-confirmationid.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003377; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"payee-my-hali.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003378; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"payee-notifydetected.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003379; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"payee-portal-halifax.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003380; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"payee-security-restrictions.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003381; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"payee-securityerror.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003382; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"payee.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003383; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"payeenew-hali.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003384; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"payeeurgentnotices.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003385; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"payeeverify-login.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003386; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paymentattemptinfo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003387; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paymentprotectiondatamode.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003388; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypa1verification.goldensealstudio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003389; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal-checkout-app.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003390; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal-me-alessandra-martini.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003391; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal-merchantloyalty.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003392; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal-opladen.be"; content:"Host"; http_header; classtype:attempted-recon; sid:200003393; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal-password-reset.pardis-mobile.ir"; content:"Host"; http_header; classtype:attempted-recon; sid:200003394; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal-test.projektumfeld.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200003395; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal-uk-webcmd-login.done-login-access-krf41asdsge4h6g354sa3sdwej5yxncv54er.sentient.asia"; content:"Host"; http_header; classtype:attempted-recon; sid:200003396; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal-updating-me.azurewebsites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003397; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal.ca.purchasekindle.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003398; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal.co.uk.session23406304fd15e72e65304c141af8898f117.33s3.smoz.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200003399; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal.co.uk.useriazi6bqgssb.settingsppup.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003400; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal.com.0.security-confirmation.d72b69c8e37aec662e13e39d929d6e3d.as2.2u.se"; content:"Host"; http_header; classtype:attempted-recon; sid:200003401; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal.com.05925924b730bb369f87ad369fde0ffbf74a3c2.33s3.smoz.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200003402; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal.com.service.id999.sorttheweb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003403; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal.com.update.service.verify.freeget.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003404; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal.me.holdpaystatic.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200003405; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypal.verylegit.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200003406; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypalforex.co.ke"; content:"Host"; http_header; classtype:attempted-recon; sid:200003407; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypalil.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200003408; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypalupdate.osamaalshareef.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003409; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypalverification.allgamescheaper.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003410; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypalweb.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003411; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paypial-us.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003412; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"payu.okta-emea.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003413; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pbi.unsam.ac.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003414; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pbmjx.youroffer.company"; content:"Host"; http_header; classtype:attempted-recon; sid:200003415; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pch.sweetstakes.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003416; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pearlfilms.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003417; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pedrorei.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003418; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"peds-ortho.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003419; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"peer.yourluv.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200003420; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pembatalan-pemblelokiran.webnode.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003421; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pembatalanpemblokiran08.webnode.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003422; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pending-deliveryfee-helpdesk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003423; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"peoplegamer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003424; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"perfectliker.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003425; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"perinasas.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200003426; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"peringatan-pemblokiran516.webnode.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003427; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"perkpolder.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003428; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"permajacktulsa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003429; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"peronaci.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200003430; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"persistencepays.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003431; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"perso.menara.ma"; content:"Host"; http_header; classtype:attempted-recon; sid:200003432; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"personastcverifc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003433; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"peru.payulatam.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003434; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"peruzonazonasegvra-bnweb29.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003435; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pgevmp.getenjoyment.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003436; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pgmm.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200003437; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pgrimard.magix.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003438; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pgroupefinancesprofilacccountencaissement.justns.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003439; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ph.zanqap.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003440; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pharmaglobiz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003441; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"phdchiropractic.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003442; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"phil.berry.continentalwingates.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003443; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"philipsisitme.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003444; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"phillipmill176545.clickfunnels.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003445; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"phimhaymoingay5.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200003446; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"photo.mie.vn"; content:"Host"; http_header; classtype:attempted-recon; sid:200003447; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"photographybyallen.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003448; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"phreshphoto.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003449; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"phx.chromeproxy.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003450; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"physics.uctm.edu"; content:"Host"; http_header; classtype:attempted-recon; sid:200003451; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"piandizano.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200003452; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pichincha.fast-page.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200003453; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"picnic.industries"; content:"Host"; http_header; classtype:attempted-recon; sid:200003454; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pics.lookatmynewphotos.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003455; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pilisklima.hu"; content:"Host"; http_header; classtype:attempted-recon; sid:200003456; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pinehills-school.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003457; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pinezaki.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003458; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pismo-online.space"; content:"Host"; http_header; classtype:attempted-recon; sid:200003459; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"piusicurezza.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003460; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pixelbenchmarks.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003461; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pixigifts.ae"; content:"Host"; http_header; classtype:attempted-recon; sid:200003462; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pizfirepizzacafe.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003463; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pkhnm.ac.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200003464; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pkk.depok.go.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003465; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pl-19.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003466; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pl-bankinvest.surge.sh"; content:"Host"; http_header; classtype:attempted-recon; sid:200003467; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pl-dhl.store"; content:"Host"; http_header; classtype:attempted-recon; sid:200003468; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pl-wdrazanie.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003469; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pl-weryfikacja.world"; content:"Host"; http_header; classtype:attempted-recon; sid:200003470; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pl-wprowadz.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200003471; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pl.inpost-oferta.su"; content:"Host"; http_header; classtype:attempted-recon; sid:200003472; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pl.olxdelivery.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003473; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"placowka-pocztowa.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200003474; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"plain583.mipropia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003475; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"plak-subring.s3.us-east-2.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003476; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"plan-o2-monthlypayments.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003477; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"planeta12.minobr63.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003478; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"plasticaindia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003479; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"plataformaeducativa.se.jalisco.gob.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200003480; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"platnosc-online24.fun"; content:"Host"; http_header; classtype:attempted-recon; sid:200003481; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"platotech.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200003482; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"plc-support.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200003483; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"plcsupportsystem.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003484; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pljnsnmdmqiw.jetos.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003485; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"plog.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200003486; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"plutosmto.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003487; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pmbonline.unmuha.ac.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003488; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pnw-ins.com.healthinsurez.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003489; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"poczta.pl-buy.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200003490; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"poczta.pl-buy.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003491; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"poczta.pl-makepays.casa"; content:"Host"; http_header; classtype:attempted-recon; sid:200003492; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"poczta.pl-newdeal.casa"; content:"Host"; http_header; classtype:attempted-recon; sid:200003493; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"poczta.pl-payed.surf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003494; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"poczta.pl-payed.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003495; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"poczta.pl-sales.cyou"; content:"Host"; http_header; classtype:attempted-recon; sid:200003496; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"policieschange-4123.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003497; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"policy-fanpage.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200003498; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"poligrafiapias.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003499; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"polinaves.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003500; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pontofrio.webpremios.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200003501; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"popcornapp.360guide.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200003502; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"populartraders.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200003503; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pornseks.zyns.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003504; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"portal-bancoestado-personas-login.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200003505; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"portal-ingreso-bancoestado-cl.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200003506; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"portal.abraz.org.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200003507; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"portal.ativacaoapp.digital"; content:"Host"; http_header; classtype:attempted-recon; sid:200003508; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"portal.hardwarecheck.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003509; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"portal.prizegiveaway.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003510; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"portal.prizesforall.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003511; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"portalaereo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003512; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"portale-web-app.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003513; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"portale.web.mps.info.fpl.ma"; content:"Host"; http_header; classtype:attempted-recon; sid:200003514; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"posadalalucia.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200003515; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"postaleaccedi.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003516; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"postalservices.support"; content:"Host"; http_header; classtype:attempted-recon; sid:200003517; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"postch-dl.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200003518; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"postchtrackingorder.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003519; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"posten-pakke.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003520; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"posten-post.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200003521; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"postes-dhll.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003522; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"postfb-e1o7jzv4z.countme.bz.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200003523; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"posylka.icu"; content:"Host"; http_header; classtype:attempted-recon; sid:200003524; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"posylka.website"; content:"Host"; http_header; classtype:attempted-recon; sid:200003525; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pour-vous-identifier62.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003526; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pour-vous-identifier66.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003527; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pourcontinueridauthenserweuronlineworking.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003528; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"poverty.monespace.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003529; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"powercase.shoplineapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003530; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"powercontrol.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003531; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pp-secure.ddns.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003532; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ppds.anestesi.ulm.ac.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003533; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pphwm.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200003534; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ppi.mwavpn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003535; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pragmaticplayonline.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003536; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pramitmedicalstore.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003537; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pranavks.github.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200003538; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"prcl44.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003539; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"prepagata-postepay.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003540; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"preppingconfidence.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003541; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"preprod-support.cleanairzonevehiclecheck.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003542; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"presenting.vercel.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200003543; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"presidencia.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003544; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestige-nation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003545; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"prestonwmaa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003546; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"prettypugpuppies.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003547; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"preventsenior.com.br.cutercounter.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003548; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"prewarminor.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003549; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pridecare-auth.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200003550; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"prikany.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003551; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"prime-co-jp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003552; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"primeparkrealty.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003553; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"print-mara.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003554; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"printandprovisions.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003555; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"printtoner.com.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200003556; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"prismanet.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003557; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"privacy-notification-checkiing-page-recovery.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003558; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"prizeconsultancy.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200003559; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"prizewel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003560; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pro-ligne.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003561; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"processing-delivery.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003562; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"procurement.mcot.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003563; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"procurement.tevta.gop.pk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003564; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"produvicexpress.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003565; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"proe.cz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003566; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"professional-house-cleaning.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200003567; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"professionalindemnityinsurance.com.mt"; content:"Host"; http_header; classtype:attempted-recon; sid:200003568; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"professionalrealestate-homelistings.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003569; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"professorgizzi.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200003570; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"profile-4157237824.shoparena.pk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003571; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"profile-7rczpytb.hostkriolo.cv"; content:"Host"; http_header; classtype:attempted-recon; sid:200003572; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"profile-j4dstxrq2s9.hostkriolo.cv"; content:"Host"; http_header; classtype:attempted-recon; sid:200003573; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"profile-qhwtzqnb2kp.hostkriolo.cv"; content:"Host"; http_header; classtype:attempted-recon; sid:200003574; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"programmasviluppo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003575; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"projec.arq.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200003576; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"proluxlistinghome-realestate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003577; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"promcuscotravel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003578; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"promehedinti.ro"; content:"Host"; http_header; classtype:attempted-recon; sid:200003579; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"propspark.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003580; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"prosto-i-vkusno.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003581; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"protect-mylogindetails.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003582; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"protect.sabzgoltab.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003583; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"protect.theresortweddings.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003584; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"protection-newpayee-halifax.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003585; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"protelesis.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003586; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"proyectospalma.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003587; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pruprioritas.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003588; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"psmkreditsyari.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003589; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"psupport.apple.com.pple.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003590; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pte.lt"; content:"Host"; http_header; classtype:attempted-recon; sid:200003591; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pu6gmobile.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003592; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pubg.kopens.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003593; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pubgeventsseasons18.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003594; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pubgmbest15.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003595; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pubgmobile.com.xxucpubg.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003596; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pubgredee17ms.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200003597; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pubgrewards15.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003598; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pubgspin17.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003599; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pubgturnamens18.ygto.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003600; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pubgxeventnew.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003601; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"publicspeakingcoursesinsingapore.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003602; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"puffing.com.pk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003603; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pump.thats.im"; content:"Host"; http_header; classtype:attempted-recon; sid:200003604; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"punjabjewellers.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200003605; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"puntaarenas.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003606; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"puntobohemio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003607; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"puremerchantprocessing.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003608; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pview-fymupnsdbt.arcinovationz.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200003609; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pvix217-0027.icu"; content:"Host"; http_header; classtype:attempted-recon; sid:200003610; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pvix217-0027.online"; content:"Host"; http_header; classtype:attempted-recon; sid:200003611; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pvix2931-3310.net.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003612; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pvix2931-3329.net.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003613; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pvix2931-3355.net.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003614; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pwcgov-er.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200003615; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pwcs-co.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003616; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pwcs-co.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200003617; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pwcs-in-org.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003618; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pyjamoda.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003619; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pyroxenic-documenta.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003620; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pytlo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003621; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pzywdxg.bagsofbags.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200003622; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"q06huk.webwave.dev"; content:"Host"; http_header; classtype:attempted-recon; sid:200003623; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qare.nl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003624; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qastaffingagency.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003625; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qdevtools.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003626; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qnbfinzb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003627; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qsdqsx.ns12-wistee.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200003628; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"quad-as.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200003629; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"quadfabrik.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200003630; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qualistand.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003631; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qubectravel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003632; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"quinaroja.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003633; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"quintanaevents.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200003634; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"quota.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003635; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qw4g5w3sl31.typeform.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003636; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qwertymailboxericqpliuytrewqasdghjknbvcxzaxscdfvbghnmjkmloipowe.eu-gb.cf.appdomain.cloud"; content:"Host"; http_header; classtype:attempted-recon; sid:200003637; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"r.mail.flowii.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003638; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"r2l.com.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200003639; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"r3g34.fra1.digitaloceanspaces.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003640; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"r7vfe.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200003641; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rabofree.blogspot.li"; content:"Host"; http_header; classtype:attempted-recon; sid:200003642; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rabots.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200003643; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rackenfordlabs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003644; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raddelmotalaka.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003645; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"radforddoors.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003646; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raikuten.co-jp.4tdcsgjs.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003647; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raikuten.co-jp.73kbjnqz.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003648; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raikuten.co-jp.9ckbmtqs.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003649; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raikuten.co-jp.9f1r4nrc.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003650; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raikuten.co-jp.bk6mocqu.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003651; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raikuten.co-jp.bo8pdlt5.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003652; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raikuten.co-jp.dibk9iqf.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003653; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raikuten.co-jp.xn4qtfgs.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003654; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raikuten.co-jp.ydossmjn.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003655; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rajwebtechnology.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003656; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raketenm-9fly7.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003657; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raketenm-e5g00.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003658; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raketenm-fy3xb.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003659; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raketenm-ggbi1.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003660; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raketenm-h9gei.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003661; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raketenm-o7q4t.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003662; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raketenm-ri243.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003663; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raketenm-tk23ia.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003664; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raketenm-vcydv.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003665; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raketenm-zq5et.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003666; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakkuten.co.jp.ninemax2201.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200003667; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten-bank006.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003668; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten-bank027.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003669; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten-card.co.jp.silaideng.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003670; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.aa01.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003671; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.add55.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003672; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.ao01.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003673; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.co.jp.bbj4ymckczg0x89lkgwzw158.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200003674; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.co.jp.dmktifel8z8sn6lq5zm1ljav.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200003675; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.co.jp.hnax9jpel027keo7yuufx6cl.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200003676; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.co.jp.ipslc8thge3729slpgf1flk1.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200003677; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.co.jp.kimsdfpwxu.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200003678; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.co.jp.rakuteenvip.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003679; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.co.jp.rakutennjp.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003680; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.co.jp.rakutennvip.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003681; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.co.jp.rakutpu.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003682; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.co.jp.t26lohpsx89ppx3anqtsxlc9.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200003683; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.co.jp.x465nodmw9ijk8feac286v09.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200003684; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.co.jp.zep9i89hj9h5o2te8kqczsdl.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200003685; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.grp03-id.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003686; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.grp05-id.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003687; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.idbi.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003688; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.idd55.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003689; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.ld01.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003690; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.lo0ol.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003691; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.oo01.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003692; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten.qoiop.work"; content:"Host"; http_header; classtype:attempted-recon; sid:200003693; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakuten2sopper.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200003694; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakutonet.jp.rawqek.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003695; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rakutonet.roaliuq.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200003696; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ramgarhiamatrimonial.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200003697; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rayone.com.jo"; content:"Host"; http_header; classtype:attempted-recon; sid:200003698; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"razaaudiochannel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003699; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rbcmontgomery.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003700; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rblxapionline.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003701; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rcbc-phl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003702; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rd8um.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200003703; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rdeshapriya.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003704; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"re-add-new-payee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003705; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"re-direct-me.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003706; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"react-ba2roi.stackblitz.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200003707; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"read-newfbterms.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003708; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"read-policiesfb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003709; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"readsee.thedisneylover.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003710; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"real.de.seller.bookings.siharkaboy.boyolali.go.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003711; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"realclub.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200003712; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"realcodashopfreediamonds.freeddns.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003713; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"realestateservices-homelisitng.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003714; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"realestatewithsheneka.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003715; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"realesteatehomes-findjewelers.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003716; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"realmoneysend.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003717; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"realrenderstudio.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200003718; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"realtoragent-pagge38233.agency"; content:"Host"; http_header; classtype:attempted-recon; sid:200003719; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rearrange-mail.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200003720; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"reconfirmpost287846656.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200003721; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"recoverinst.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003722; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"recp.mkt91.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003723; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"recso.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200003724; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"redbysfrgroupebox.myfreesites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003725; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"reddotarms.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003726; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"redelivery-uk-rm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003727; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"redeliveryuk-rm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003728; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"redirect-ca578.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003729; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"redirect.voici-news.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200003730; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"redirectida.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003731; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"redirecting-55f01.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200003732; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"redirnicatio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003733; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"redlinegym.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003734; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"reduction-ligne.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200003735; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"reebe.snprobbx.pbz.r.de.a2ip.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003736; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"reegme.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003737; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"regiaocentrorsmg.websicredi.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200003738; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"regina.ninetendev.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003739; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"register-my-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003740; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"register-mynew-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003741; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"register-mynew-devices.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003742; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"register-page-certificated-000447.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003743; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"registerallwalmartmoneycards.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003744; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"registerinthispageliveid.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003745; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"regulacja-platnosci.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200003746; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"reinstate.netflix.ie.reinstateservice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003747; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rektuen.jp.get-r.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003748; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"releaseinboxheldmails.s3.us-east.cloud-object-storage.appdomain.cloud"; content:"Host"; http_header; classtype:attempted-recon; sid:200003749; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"relevant.systems"; content:"Host"; http_header; classtype:attempted-recon; sid:200003750; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"relieffund.freeinternetz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003751; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"relivable-choice.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003752; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"remaining-fee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003753; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"remicindustry.co.za"; content:"Host"; http_header; classtype:attempted-recon; sid:200003754; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"remittance369297292749.goshly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003755; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"remove-auth-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003756; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"remove-device.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200003757; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"remove-unauthorised-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003758; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rempitem.agilecrm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003759; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"remsy.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200003760; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rencon.ch.net2care.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003761; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"renew-billing-information.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003762; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"renew-suggus.v6.rocks"; content:"Host"; http_header; classtype:attempted-recon; sid:200003763; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"renovocap.com.healthinsurez.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003764; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rentyouracc.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003765; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"repartidoor.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003766; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"repl-mess.myfreesites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003767; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"replug.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200003768; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"request-payee-now.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003769; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"reregister-digitalaccess.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003770; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"reremice3706553002.blob.core.windows.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003771; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"reschedule-delivery-package.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003772; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"researchmedics.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003773; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"reset-billing-address.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003774; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"restorationofacct.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003775; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"restricted-newonline-payee.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003776; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"restricted-newpayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003777; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"resuscitated-occurr.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003778; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"retraiteenaction.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200003779; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rettogo.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200003780; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"retuken-xyz.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003781; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"retuken.retakuooqn.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200003782; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revenuetaxx.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003783; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"review-my-newtransaction.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003784; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"review-mynew-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003785; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"review-page-activation-2021.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003786; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"review.support.disabledads.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200003787; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revisionara.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003788; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revivetherapy.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003789; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revoke-newly-added-payee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003790; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revolution-admin-100002030038264578189.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003791; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revolution-admin-100002030038264578190.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003792; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revolution-admin-100002030038264578211.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003793; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revolution-admin-100002030038264578212.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003794; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revolution-admin-100002030038264578213.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003795; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revolution-admin-100002030038264578214.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003796; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revolution-admin-100002030038264578216.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003797; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revolution-admin-100002030038264578218.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003798; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revolution-admin-100002030038264578219.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003799; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revolutionacademy.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200003800; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"reward-mobile-legends.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003801; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rewards-trust-crypto-wallet.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003802; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rextraening.dk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003803; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"reygaming.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003804; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rf.moneywayappl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003805; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rffesf1-iuhjhgu-kygdfs.s3-eu-west-1.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003806; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rgcsolutions.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200003807; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ricavato.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003808; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"richiesta-dati-utente.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003809; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"riderjoyas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003810; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"riley-wilson.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003811; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rioverdepar.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200003812; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"risihlahpasti.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003813; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rizkyinterior.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003814; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rj1kx.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200003815; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkgreany-seg3-2.kk.sopqa.arg.r.de.a2ip.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003816; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-billing.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003817; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-delivery-uk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003818; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-delivery.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200003819; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-deliverycentre.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003820; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-fee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003821; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-package-help.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003822; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-packages.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003823; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-parcel-manage.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003824; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-parcel3871.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003825; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-parcel3873.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003826; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-parcel6299.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003827; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-parcel7389.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003828; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-parcel7814.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003829; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-parcel7816.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003830; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-parcel7936.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003831; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-parcel7965.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003832; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-parcel9548.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003833; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-parcel9817.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003834; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-parceltracking.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003835; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-redelivery-uk1.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003836; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-uk-delivery1.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003837; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rmsfcc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003838; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rnb51.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003839; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rockportportugal.pt"; content:"Host"; http_header; classtype:attempted-recon; sid:200003840; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rockysite.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003841; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rodinagermaniya.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003842; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rokutanm-ctmrrj.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003843; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rokutanm-rrbrb.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003844; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rolasellsrealestate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003845; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"romatermit.ro"; content:"Host"; http_header; classtype:attempted-recon; sid:200003846; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ronaldjamesgroup.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200003847; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rondelbarrilito.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003848; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rongbachkim.tv"; content:"Host"; http_header; classtype:attempted-recon; sid:200003849; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ronin47design.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003850; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rooyan.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200003851; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rosalinas-initial-project-30ac52.webflow.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200003852; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rosarioscarpato.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003853; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rosesattar.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003854; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rotarysnehaveedu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003855; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rotimi.pandaform.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003856; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rotseezunft.ch.tcorner.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200003857; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rouseau-manque.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200003858; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"roy-mail.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003859; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royailmail-pay-parcel-fee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003860; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royaimaii.co.uk.prcl44.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003861; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royal-billinghelp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003862; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royal-delivery-uk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003863; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royal-deliveryfee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003864; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royal-parcel-refund.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003865; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royal-redelivery-uk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003866; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royal-servicessupport.team"; content:"Host"; http_header; classtype:attempted-recon; sid:200003867; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royal.mail-receiving.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003868; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royal.mailhelp-gb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003869; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royal.mailredelivery.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200003870; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royal.mailredelivery.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003871; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royal.mails-delivery.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200003872; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royaletw.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003873; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royalmail-shipped.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003874; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royalmail.delivery-secure-details1.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003875; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royalmail.dispatch-details-confirmation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003876; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royalmail.login.delivery-secure-details1.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003877; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royalmail.parcelfees.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003878; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royalmail.pay-shipping.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003879; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royalmail.pay-tracking.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003880; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royalmail.payfee-online.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003881; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royalmail.payshipping-feeonline.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003882; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royalmail.secure-delivery1.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003883; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royalmail.shipping-due.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003884; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royalpostcards.be"; content:"Host"; http_header; classtype:attempted-recon; sid:200003885; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royalredeliveryupdate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003886; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rreeufffsaussaa3.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200003887; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rstools.club"; content:"Host"; http_header; classtype:attempted-recon; sid:200003888; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rubeeworks.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003889; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ruekrew.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003890; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rulesfb-5s5rgw7c2epbu.webport.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200003891; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rulesfbchange-4897062265.villarte.gr"; content:"Host"; http_header; classtype:attempted-recon; sid:200003892; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rulesfbchange-5375142767.villarte.gr"; content:"Host"; http_header; classtype:attempted-recon; sid:200003893; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"runescape.com-ec.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003894; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"runescape.com-wsvs.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200003895; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"runescapeapk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003896; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"runescapeservices.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003897; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"runion1337.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003898; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rureoreir.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003899; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ryokojuku.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003900; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"s-paypalinfo.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200003901; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.codetasty.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003902; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.free.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200003903; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"s.kekk.is"; content:"Host"; http_header; classtype:attempted-recon; sid:200003904; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"s18pubgm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003905; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"s7-airlines.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200003906; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"s7-airlines.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200003907; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"s7-airlines.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003908; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"s7airlines.art"; content:"Host"; http_header; classtype:attempted-recon; sid:200003909; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"saagksa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003910; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"saar05-leichtathletik.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200003911; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sacredjourneyguide.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003912; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sadervoyages.intnet.mu"; content:"Host"; http_header; classtype:attempted-recon; sid:200003913; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"safainternational.com.pk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003914; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"safe-offers.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003915; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"safelegalestate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003916; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"safety-delliveri.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003917; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"safety-delliveri.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200003918; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"safety1-pages-appconfrimss-35437837.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200003919; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"safetyconsultantehs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003920; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"saifglobalsports.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003921; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"saifmobile.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003922; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sainathhospital.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003923; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"salahkaarconsultants.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003924; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"salamyu89.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003925; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"saldospc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003926; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"salesjpstore.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003927; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"salesnksportsqn.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200003928; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"samducksports.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003929; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"samircanel20.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003930; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sanada-manu.co.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200003931; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sanasunty.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200003932; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sancotradebd.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003933; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sandbox.plantstny.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003934; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sandengineer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003935; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sanjheeventerprises.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003936; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sanjilkumar.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003937; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sanjing.amxhylc970.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200003938; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"santan-myverify.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003939; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"santander.currentacc-security.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003940; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"santoshwomencarehospital.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003941; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sarahstofel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003942; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sarbesar.ir"; content:"Host"; http_header; classtype:attempted-recon; sid:200003943; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"saritapariyar.com.np"; content:"Host"; http_header; classtype:attempted-recon; sid:200003944; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"satkom.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003945; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"saudi-seo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003946; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sbaomisndbf.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003947; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sbc-logins.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003948; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sbc.redirectme.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200003949; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sbcglobal-login.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200003950; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sbcglobal.guidetoknives.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003951; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sbcgloballoginn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003952; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sbi.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200003953; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sbloccareposte.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003954; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sbsinger.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003955; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"scalextricman.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003956; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"scentedsuperhero.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003957; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"scgrotto.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200003958; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"schaaf.ch.net2care.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003959; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"schedule-new-delivery.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003960; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"schizophrenia.today"; content:"Host"; http_header; classtype:attempted-recon; sid:200003961; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"schroffenstein.online.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200003962; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"schule-niederrohrdorf.ch"; content:"Host"; http_header; classtype:attempted-recon; sid:200003963; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sconsumer.e-pagos.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200003964; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"scotland.op.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200003965; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"scouts.org.sv"; content:"Host"; http_header; classtype:attempted-recon; sid:200003966; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"screniah.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003967; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"scstategives.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003968; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sctrlgin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003969; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"scupimelgadar.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003970; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sdjhdy.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200003971; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sdreyljeusm.ru.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003972; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sdvsdv.ad-hebenstreit.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200003973; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"seahoss.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003974; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sec02-bankofamerica.servehttp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003975; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secur-reconfrms-paqs-problms.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200003976; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secur-recovery-standardcommunity-identity.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200003977; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"securbjff.webcindario.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003978; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-02-billing.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003979; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-deviceauth.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200003980; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-halifax-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003981; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-myaccountdetails.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003982; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-mynew-devices.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003983; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-mytransfer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003984; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-onlinepayee.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200003985; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-payeeremoval.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003986; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-payeeremoval.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200003987; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-ssl-cdn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003988; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-unauthorised-activity.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003989; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-verify-loginhelp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003990; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.bankofamerica.com-login-sign-in-signonv2screen.go.suzukihaiphong.com.vn"; content:"Host"; http_header; classtype:attempted-recon; sid:200003991; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.captisa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003992; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.caykurrizespor.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200003993; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.device-return.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003994; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.deviceassistance.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200003995; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.facebook.com.de.a2ip.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003996; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.legalmetric.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003997; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.login.aliexpress.com.coin-balance.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200003998; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.oldschool.com-ez.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200003999; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.oldschool.com-ty.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004000; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.oldschool.com-xs.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004001; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.oldschool.com-zs.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004002; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.runescape.com-cn.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004003; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.runescape.com-oc.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004004; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.runescape.com-ro.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004005; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.runescape.com-tp.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004006; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.runescape.com-vc.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004007; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.runescape.com-vzla.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004008; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.tdfinanceweb.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004009; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure.verify-deviceinfo.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200004010; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure09-account07.myftp.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004011; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure1811.tmweb.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004012; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure273.inmotionhosting.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004013; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure279.inmotionhosting.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004014; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure285.inmotionhosting.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004015; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secureaccount.cloud"; content:"Host"; http_header; classtype:attempted-recon; sid:200004016; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secureclbc.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200004017; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secured-id328425.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200004018; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secured-mypayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004019; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secured-payee-cancellation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004020; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"securedcitizenslogin32.serveusers.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004021; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"securedhelp7-001-site1.itempurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004022; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secureemailsrrvr.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004023; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secureid-verify.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004024; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"securelloyd-help-app.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004025; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"securemy-logindetails.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004026; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"securemydevice.redirectme.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004027; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"securemypayee-assist-auth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004028; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"securepayement-authorisation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004029; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"securesiteapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004030; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"securesquared.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004031; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"security-devicesecured.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200004032; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"security-mappl-information-account.piiquarry.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004033; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"security-unapproved-payee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004034; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"security-unrecognised-payee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004035; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"security-unrecognised-payees.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004036; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"security.ccashqpp.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200004037; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"security.hs-authorize-online.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004038; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"securityposte.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004039; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"securityupdatereview-365online.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004040; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"seductionlearning.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004041; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"segurabetaviabcp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004042; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"seivino.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200004043; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"selectuslicor.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004044; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"self-secureauthorise-personal.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004045; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sella.banking.home.kintv.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200004046; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sellolx-ro.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004047; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"semimaratonulcraiovei.ro"; content:"Host"; http_header; classtype:attempted-recon; sid:200004048; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sen-manole.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004049; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sendo-meso.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004050; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"seo-one1.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004051; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"seousalc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004052; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serriceuptocie.azurewebsites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004053; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sertyxese.myfreesites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004054; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serv-secured-1.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004055; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"servernuovaintesa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004056; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serverupdate.getforge.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200004057; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serverupdates0-0.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004058; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serveur987452.flywheelsites.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004059; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"service-aktivierung.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004060; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"service-lkdn2020.gacconstrutora.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004061; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"service.login.ag.pay.adminis.aeffective.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200004062; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviceclient.site44.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004063; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemail0200inf.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004064; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicemailsfr527.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004065; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviceoutade.groutmastersatlanta.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004066; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"services-vodafone.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004067; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"services.runescape.com-cn.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004068; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"services.runescape.com-m.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200004069; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"services.runescape.com-mv.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004070; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"services.runescape.com-oc.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004071; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"services.runescape.com-ro.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004072; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"services.runescape.com-vc.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004073; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"services.runescape.com-vzla.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004074; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviceupdateconfirmation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004075; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviceusentity.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004076; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviciodigitacr.online"; content:"Host"; http_header; classtype:attempted-recon; sid:200004077; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"servindustriadelsur.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004078; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviziapponline.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004079; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"servlces.runescape.com-cn.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004080; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"servlces.runescape.com-mv.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004081; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"servlices.runescape.com-mv.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004082; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"servllces.runescape.com-mv.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004083; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"servmessagerieinternetclient.yahoosites.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004084; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"set.galerry63.nhely.hu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004085; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"setona.main.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200004086; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sevasangama.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004087; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sevilenlezzetler.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004088; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sevoudryserviciobomail.dudaone.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004089; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sfirstrepublic.coms.cso.gov.tt"; content:"Host"; http_header; classtype:attempted-recon; sid:200004090; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sfr.provad.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200004091; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sftp.usin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004092; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgcc.bm"; content:"Host"; http_header; classtype:attempted-recon; sid:200004093; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgmsugar.com.pk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004094; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgozq-alternate.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200004095; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sh199811.website.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200004096; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shalomtextiles.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004097; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shambika.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004098; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"share-relations.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004099; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"share.chamaileon.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200004100; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharefiles.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200004101; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shareholds.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004102; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharelink.sn.am"; content:"Host"; http_header; classtype:attempted-recon; sid:200004103; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharepointle.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004104; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharestion.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004105; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharing-files-com.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200004106; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sharlu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004107; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shib-idp.tufts.edu.campuspride.ro"; content:"Host"; http_header; classtype:attempted-recon; sid:200004108; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shifawll1.ae"; content:"Host"; http_header; classtype:attempted-recon; sid:200004109; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shimaarutechies.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004110; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shohidurrahman.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200004111; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shop.banhbasu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004112; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shopeextradron.wpdevcloud.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004113; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shopello.pk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004114; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shoppingpoints.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004115; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shortenlink.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200004116; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shortlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004117; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shrtm.nu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004118; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shtuchki.store"; content:"Host"; http_header; classtype:attempted-recon; sid:200004119; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shubhmoney.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200004120; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sicurezzainpiu.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004121; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sieck-kuehlsysteme.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004122; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sierratx.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004123; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"signaturebrandfactory.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004124; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"signifyteleprompt-expired.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004125; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"signin.ea-winter.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004126; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"signin.ebay.de.whyymedia.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200004127; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"signin.eday.co.uk.ws.ayisapi.dllsigninusingssl1puserid.kzbzd9n59c7tggswrvcvewuihebw7.menara-anugrah.co.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200004128; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"signin.eday.co.uk.ws.eayi.sapi.dllsignin.usingssl.9x9bdd880tj5elgyowg9r6qtn9idtl.artisste.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200004129; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"signin.eday.co.uk.ws.eayi.sapi.dllsignin.usingssl.fbckchcehuvk5qfp1oqwzvu8nf7vqk.meduzas.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004130; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"signin.eday.co.uk.ws.eayi.sapi.dllsignin.usingssl.p9fgtw9cxc5w7pli0bu3rw2i0nexz1.artisste.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004131; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"signin.eday.co.uk.ws.eayi.sapi.dllsignin.usingssl.xlrzhsyzcdimlzsz8usiwdz8mhh2ht.artisste.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200004132; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"signin01.kauf-eday.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004133; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"signinattcomdynamici.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004134; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"signintoupgradeattmailwebsite.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004135; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"signtocontinueupdateservicefromyahoo.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004136; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sihla.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004137; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"siigniiinattt.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004138; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sikikoparoles.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004139; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sikkertnabolag.dk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004140; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sillyabba.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004141; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"silverleafelectric.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004142; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"simaniopls8.constantcontactsites.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004143; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"simpletec.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200004144; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"simpletouchpos.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004145; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"simtechglobal.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004146; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"simulation.go.yj.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200004147; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sinababaei.ir"; content:"Host"; http_header; classtype:attempted-recon; sid:200004148; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindhbarcouncil.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004149; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sindicombustiveis.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004150; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sios.tech"; content:"Host"; http_header; classtype:attempted-recon; sid:200004151; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"siqnin-attt-net.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004152; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sirak.se"; content:"Host"; http_header; classtype:attempted-recon; sid:200004153; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sirdarnell.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004154; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sisteminformasipantaijepara.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004155; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"site-atomic.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004156; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"site-mvtnbfdr.websiteserver3.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004157; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"site9423623.92.webydo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004158; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"site9423773.92.webydo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004159; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"site9434107.92.webydo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004160; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"site9548676.92.webydo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004161; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"site9552191.92.webydo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004162; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"siteserversolutions.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004163; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sixfer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004164; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sixhub.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004165; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sjhsk.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200004166; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sjtuqpgbut.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200004167; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"skhayashi.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004168; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"skhayashi1.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004169; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"skhayashi2.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004170; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"skinmetroroyale.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004171; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"skribbl-io.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004172; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sleepmaskz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004173; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sloka.constantcontactsites.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004174; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"slotonline777.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200004175; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"slotsno.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004176; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"slvfshnjonce.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004177; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"slvhugrhjonce.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004178; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sm777.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200004179; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smartagrico.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004180; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smartautomation.co.th"; content:"Host"; http_header; classtype:attempted-recon; sid:200004181; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smarteconomy.rs"; content:"Host"; http_header; classtype:attempted-recon; sid:200004182; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smartmco.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004183; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smartprotech.rw"; content:"Host"; http_header; classtype:attempted-recon; sid:200004184; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smarttechmarketing.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004185; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smartusluga.xja.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200004186; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smash7289eui.fastpluscheap.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004187; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbc-card.com.j246u2.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004188; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbc-card.com.jpqwo98dhiqwq8.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004189; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbc-card.com.kuriyama1.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004190; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbc-card.com.skhayashi.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004191; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbc-card.com.skhayashi4.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004192; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbc-card.com.skhayashiz.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004193; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbc-card.skhayashi7.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004194; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbc-crab.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200004195; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbc-crad.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200004196; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbc-f.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004197; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbc-japan.works"; content:"Host"; http_header; classtype:attempted-recon; sid:200004198; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbc-jiapan.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004199; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbc-smbgm.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200004200; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbcbc.jp.amuzun.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200004201; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbcbc.jp.omozona.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200004202; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbcbc.jp.rawqek.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004203; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smbcwodeqingguoshoujicojp.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200004204; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smediaphotography.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004205; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smeo.org.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200004206; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smilenewyork.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004207; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smmdzen.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004208; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smmms01.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004209; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smmsvocal.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004210; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smsenligne.myfreesites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004211; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smsmf14.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004212; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smsorangesmsmessage.myfreesites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004213; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smss-mms.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004214; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smsverificationmms.myfreesites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004215; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"smwam.coms.cso.gov.tt"; content:"Host"; http_header; classtype:attempted-recon; sid:200004216; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"snakedoctorspirits.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004217; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sncb-card.zjmtzc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004218; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sniperdz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004219; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"snprobbx.pbz.r.uk.a2ip.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004220; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"snrsystem.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004221; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"soaresrefrigeracao.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004222; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"soaringskiesrentals.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004223; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"soccerequipmentbags.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004224; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"soci-molen.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200004225; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"socia54998.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200004226; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sofe-firma.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004227; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sofiacarreghalozano.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004228; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"solarwattafrica.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004229; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"solobuenasideas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004230; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"solyanayakomnata.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004231; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"somever.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200004232; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"soneyamks.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004233; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sonne-medoon.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004234; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sonofabridge.com.net2care.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004235; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sonuguptaclasses.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004236; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sorinandronic.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004237; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sorinuri.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004238; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"soshopee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004239; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"souaxwaoh.myfreesites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004240; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"soude-masi.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004241; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"soufliscience.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004242; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"soulhealthlife.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004243; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"southernpacker.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200004244; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"souvenirsplace.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004245; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"soydofokke.easy.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200004246; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"soysodimac.estudiarfacil.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004247; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"soytablaroquero.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004248; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sp477389.sitebeat.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200004249; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sp701876.sitebeat.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200004250; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"spaceandform.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004251; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sparkassbank-de.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004252; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sparkasse-directservice15.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004253; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sparkasse-directservice77.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004254; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sparkasse-giroverband4.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004255; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sparkasse-giroverband5.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004256; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sparkasse-konto.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004257; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sparkasse-musterstadt.if-einblick.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004258; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sparkasse-noreply4.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004259; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sparkasse.scert-team.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004260; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sparkassefinanz.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004261; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sparkassentan.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004262; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sparmikantoa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004263; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sparxinteriors.co.zw"; content:"Host"; http_header; classtype:attempted-recon; sid:200004264; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"specialwayy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004265; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"spectralwirejewelry.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004266; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"spectrumstorageaccess.yahoosites.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004267; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"spidertvapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004268; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"spinosacenter.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004269; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"spinskinseune.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004270; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"spiritotarsogno.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004271; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"spkfod.coms.cso.gov.tt"; content:"Host"; http_header; classtype:attempted-recon; sid:200004272; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"splitmart.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004273; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"spontan.ch.net2care.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004274; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sportcareers.ph"; content:"Host"; http_header; classtype:attempted-recon; sid:200004275; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sportmall.online"; content:"Host"; http_header; classtype:attempted-recon; sid:200004276; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sports.com-4daily.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004277; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sportsmedicsltd.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004278; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sportsskylark.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004279; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"spotify-home.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004280; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"spotify-updatebilling.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004281; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"spotify.update-billing.sctrlgin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004282; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"spropes-auntmillies-com.slite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004283; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"srfgzdsfh4ergdsfg.agilecrm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004284; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"srszamienie.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200004285; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sslprotocoloweb38272.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004286; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sslseguridad.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004287; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sswebmail-4w5twsr.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200004288; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ssxxl.nl"; content:"Host"; http_header; classtype:attempted-recon; sid:200004289; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stadtsparkasse-giroverband10.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004290; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stadtsparkasse-giroverband16.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004291; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stadtsparkasse-giroverband18.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004292; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stadtsparkasse-giroverband3.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004293; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stadtsparkasse6.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004294; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stafftrainingsolutions.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004295; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"starlangsb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004296; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"starlingbankplc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004297; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"starmak.com.tr"; content:"Host"; http_header; classtype:attempted-recon; sid:200004298; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"starme.hekko24.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200004299; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"starsoftheindustry.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004300; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"startseite-verden.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004301; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"starttsboxfile.myfreesites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004302; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stateagencybe.tumblr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004303; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"statenewsharyana.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004304; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"static-ak-fbcdn.atspace.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004305; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"steadyhost.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200004306; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"steam.communyty.worldhosts.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004307; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"steamcommunity-traderoffer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004308; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"steamcomuunity.ru.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004309; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"steampowered.freeskins.ru.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004310; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"steamproxy.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004311; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"steeamcommunity.ru.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004312; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"steven-coldwellbth9965.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200004313; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stevencrews.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004314; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stevenhoffmancreative.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004315; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stillgraphics.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004316; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stimulus-claim.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004317; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stingsecureposte.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004318; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stitch-statichosting-prod.s3.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004319; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stlienconunlty-xyztradeofernewpartnhr11122139271.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004320; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stolizaparketa.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004321; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stollgroup.coms.cso.gov.tt"; content:"Host"; http_header; classtype:attempted-recon; sid:200004322; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stomkinscommercial.com.aus.cso.gov.tt"; content:"Host"; http_header; classtype:attempted-recon; sid:200004323; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"store-tada0drdyw.mybigcommerce.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004324; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"storibookphotography.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004325; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"streamcommumity.ru.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004326; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"strivebe.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004327; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"structureui.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004328; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"studiogiardasrls.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200004329; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stylesbyaranda.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004330; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"stylifehomedecors.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004331; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"suapromocaodejunho.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004332; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"subpav.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004333; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"successgroup.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004334; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sucursal-virtualpersonas.shinjiru-landings.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004335; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sucursalveriftcpersonas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004336; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sucursapersonastransacionebancolombiaccomn.small-business-solutions.biz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004337; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sucuvirtcolba.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004338; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"suelunn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004339; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sugarcoupling.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004340; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"suissrava.cloudaccess.host"; content:"Host"; http_header; classtype:attempted-recon; sid:200004341; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"summer7559srz.fastpluscheap.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004342; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunbeltmembers.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004343; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunbrightaquatics.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004344; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"suncoastcreditunion.balancepro.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004345; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunge-ode.firebaseapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004346; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sunglobeshipping.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004347; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"supermilhas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004348; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"suportecxacesso2020.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004349; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"suporteempresas-guardiao.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200004350; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"suports-identiity-notification-secur-recovery.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200004351; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"suports-identity-notiification-secur-recovery.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200004352; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"suportts-notification-idntity-secur-recover.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200004353; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-confirm-newdevice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004354; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-connexion.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004355; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-kundenformular.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004356; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-registerpayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004357; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-verify-my-newpayments.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004358; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-verify-mydevice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004359; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-verify-mydevices.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004360; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"support.apsfl.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200004361; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"support.telproserv.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004362; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"supportmail.webservis.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004363; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"supportpaymentincser.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004364; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"supportpichicha.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004365; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"supremeanimation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004366; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"surjyadas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004367; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"surpriseplanner.com.bd"; content:"Host"; http_header; classtype:attempted-recon; sid:200004368; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"surveyol.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004369; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"susanlynnepeters.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004370; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"suspfacebookcom-14796405.nightaway.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200004371; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"suspfacebookcom-19897473.nightaway.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200004372; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"suspfacebookcom-41315206.nightaway.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200004373; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"suspfacebookcom-66071638.nightaway.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200004374; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sv.mikecrm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004375; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"svca.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200004376; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"svelte-kdy6dk.stackblitz.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200004377; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"svmms.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004378; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"swamcorrecter.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004379; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"swamitradingcompany.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200004380; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"swaziplastics.ofmmarylandusa.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004381; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"swiftamericanbank.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004382; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"swisscom.myfreesites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004383; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"swissorderpaketstore.report"; content:"Host"; http_header; classtype:attempted-recon; sid:200004384; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"switzerland-ubsc.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004385; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"swuisme.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004386; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sxglobalinds.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004387; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"symphonynetwork-rp.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200004388; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"symphonypan-do.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200004389; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"synoxpigments.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004390; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"syriagaleri.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004391; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"system-accountonline.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004392; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"szcxz.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004393; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"szonasegurabetabcp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004394; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"t-online-de.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004395; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"t-online.de.rongouniversitychaplaincy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004396; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"t.mktla.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004397; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"taalim.ma"; content:"Host"; http_header; classtype:attempted-recon; sid:200004398; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tabac-lemarcus.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200004399; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tadriib.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004400; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"taengball.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200004401; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"taijishentie.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004402; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"taimitaivas.fi"; content:"Host"; http_header; classtype:attempted-recon; sid:200004403; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"takingnote.learningmatters.tv"; content:"Host"; http_header; classtype:attempted-recon; sid:200004404; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"taksi-econom.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004405; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"talkingdogsmobile.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004406; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tambolin.adv.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004407; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tamol.gearhostpreview.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004408; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tamrudagmawidejene.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004409; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tanbo.main.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200004410; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tancentgamegroup.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004411; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tanerneuern.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004412; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tanias-accounting.co.za"; content:"Host"; http_header; classtype:attempted-recon; sid:200004413; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tante.joinguup-nett.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200004414; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tarrchitects.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004415; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tattoodragon.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004416; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"taumiq.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004417; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tawreedss.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004418; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"taxrebate-hmr-customs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004419; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tb915hdh89.mfs.gg"; content:"Host"; http_header; classtype:attempted-recon; sid:200004420; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"techdirectbh.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004421; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"techfela.win"; content:"Host"; http_header; classtype:attempted-recon; sid:200004422; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"techpcapps.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004423; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"telalmakkah.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004424; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"telecreditobco.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004425; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"templat65sldh.myfreesites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004426; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"temporalvin.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004427; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"temporaryserver13.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004428; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"temprazin.mydoctorfinder.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004429; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tempzter.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004430; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tenisclubemc.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004431; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"termerosapepe.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200004432; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"terri2.gitlab.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200004433; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.arintek.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004434; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.bayoucitybadges.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004435; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.dxbproductions.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004436; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.oqtech.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004437; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"test.webclient4.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004438; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"testdmn.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004439; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"testfirebase001-cf40b.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200004440; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"testingfortt-aj.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004441; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tetprep.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004442; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"texafd.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004443; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"texasfreedomrun.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004444; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"texstyleintlinc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004445; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tffgbarbados.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004446; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tforrester.continentalwingates.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004447; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tgbhbk.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004448; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"the-best-view-comes-after-the-hardest-climb.my.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200004449; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"theaceofspaeder.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004450; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"theannapoorna.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200004451; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"theavon.co.zw"; content:"Host"; http_header; classtype:attempted-recon; sid:200004452; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"theaxalta.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004453; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thebarnesgrp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004454; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thebeachleague.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004455; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thebrownbutterblog.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004456; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thechillipicklecanteen.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004457; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecomeupceo1.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004458; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thecrossmidia.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004459; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"theduecfoinv.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004460; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thefocaltherapyfoundation.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004461; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thefoodbox.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004462; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"theironinnparlour.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004463; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thelyonsfamilyden.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004464; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"themkdiaries.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004465; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thenine9.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004466; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thepantyhosequeen.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004467; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thepaperdesign.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004468; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"theprdiva.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200004469; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"therapeutnijmegen.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004470; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"therockacc.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004471; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thescrapescape.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004472; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"theumashow.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004473; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"theylike.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004474; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thousandscolors.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004475; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"three-account.digital"; content:"Host"; http_header; classtype:attempted-recon; sid:200004476; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"three-bill-uk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004477; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"three-retail-live.devicetradein.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004478; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"threebillverify.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004479; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"thxfootball.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004480; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ticxosw.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004481; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tiendaunikas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004482; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tighi.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004483; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tiktok.com.video.9283402984729347928471946967548713123.amadike.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004484; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"timeopinion.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004485; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"timetravel.mementoweb.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004486; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tinavegaphotography.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004487; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tinyl.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004488; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tipicsa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004489; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"titelinedrillingintl.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004490; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tivoli.nu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004491; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tkx29.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200004492; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tmphysio.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004493; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"to-ken.biz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004494; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"toancaupumps.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004495; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"toanhoc247.edu.vn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004496; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"toddler-town.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004497; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"todoengeneradores.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200004498; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"todosprodutos.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004499; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"togive.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004500; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tokendigital.1bn-zonaseguraperu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004501; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tokendigital.bn-zonamultired.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004502; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tokendigital.bnsegurazona1.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004503; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tokendigital.segurazona-1bn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004504; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tokendigital.segurazona1-bn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004505; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tokullarmobilya.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004506; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"toloaviation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004507; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tomerkoron.co.il"; content:"Host"; http_header; classtype:attempted-recon; sid:200004508; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"top20bonus.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004509; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"topamamaomansomsn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004510; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"topmarketingnetwork.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004511; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"topselectedtours.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004512; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"topspinllc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004513; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"toquedsol.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004514; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"torrinwine.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004515; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tourismfair.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200004516; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tow1.photoclub-ebroicien.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200004517; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpq74.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200004518; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpv63.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004519; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tracie.tjagv.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004520; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"track-your-item.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004521; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"track.drerries.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004522; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tracylalla.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004523; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"trademaxboilerproducts.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004524; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tradetricks.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200004525; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"trail.tmr.asia"; content:"Host"; http_header; classtype:attempted-recon; sid:200004526; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"traildino.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004527; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"train6.netwisedev6.co.za"; content:"Host"; http_header; classtype:attempted-recon; sid:200004528; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"trams.mot.go.th"; content:"Host"; http_header; classtype:attempted-recon; sid:200004529; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"transferpricing.firs.gov.ng"; content:"Host"; http_header; classtype:attempted-recon; sid:200004530; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"transforma.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200004531; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"transit-e.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004532; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"transportesrajju.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004533; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"treasury-gov.email"; content:"Host"; http_header; classtype:attempted-recon; sid:200004534; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"trelock.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004535; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tremblaypoint.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004536; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"treqin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004537; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"trilife.space"; content:"Host"; http_header; classtype:attempted-recon; sid:200004538; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"trilles157.typeform.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004539; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"truckcalling.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004540; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"true-fish.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004541; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"truerespite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004542; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tse6l.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200004543; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsecure-paxful.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004544; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsetsuuh.mn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004545; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsk-idrija.si"; content:"Host"; http_header; classtype:attempted-recon; sid:200004546; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsuzuki.co.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200004547; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ttakasua.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004548; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ttakasua1.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004549; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ttakasua2.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004550; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tubepchiunuoc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004551; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tudosobretudo.blog.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004552; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tuetrad.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004553; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tumbleweedsboutiques.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004554; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"turboflightpros.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004555; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"turingmain.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004556; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"turkuazkirtasiye.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004557; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"turningpointyogawithjacki.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004558; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tweakdoor.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004559; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"twowheelcool.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004560; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"twtr.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200004561; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tyanrmak.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004562; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tyrecentre.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004563; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tyzwox.webwave.dev"; content:"Host"; http_header; classtype:attempted-recon; sid:200004564; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tzamereth.co.il"; content:"Host"; http_header; classtype:attempted-recon; sid:200004565; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u08qv44zu5h.typeform.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004566; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u1066445vjm.ha004.t.justns.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004567; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u1068535w9u.ha004.t.justns.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004568; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u1070635wuo.ha004.t.justns.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004569; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u1071665z8s.ha004.t.justns.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004570; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u1075085zyg.ha004.t.justns.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004571; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u1316796.cp.regruhosting.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004572; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u1319981.cp.regruhosting.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004573; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u1326751.cp.regruhosting.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004574; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u1329605.cp.regruhosting.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004575; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u1335059.cp.regruhosting.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004576; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u1335637.cp.regruhosting.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004577; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u1344051.cp.regruhosting.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004578; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u15838okb.ha002.t.justns.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004579; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u18820701.ct.sendgrid.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004580; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u1928111.ct.sendgrid.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004581; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u1s6.22web.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004582; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u20906245.ct.sendgrid.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004583; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u28ww4gcquzfkzfok1gp9a-on.drv.tw"; content:"Host"; http_header; classtype:attempted-recon; sid:200004584; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u3699884.ct.sendgrid.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004585; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"u3703558.ct.sendgrid.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004586; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uapdate.amezona.buzz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004587; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uat-internetloanapplication.cudl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004588; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ubee.co.kr"; content:"Host"; http_header; classtype:attempted-recon; sid:200004589; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ubsbank-online.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004590; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uchecks-isuptportes-fbssss-83243klll.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200004591; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ucpubgtops.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004592; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ucsh.rect.bg.ac.rs"; content:"Host"; http_header; classtype:attempted-recon; sid:200004593; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ujs612.activehosted.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004594; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uk-mailservices.support"; content:"Host"; http_header; classtype:attempted-recon; sid:200004595; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uk-o2-resolutions.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004596; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uk-three-bill.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004597; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uk-uytdom.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004598; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uk0qx.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200004599; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ukash-wallet.biz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004600; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ukcare.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200004601; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ukokkei-ramen-ron.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004602; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ulster.ulsterban.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004603; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ultimatemotors.co.ke"; content:"Host"; http_header; classtype:attempted-recon; sid:200004604; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"umbrellaclubla.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004605; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"umzap.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004606; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unam.myfreesites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004607; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unauthorised-login-attempt872.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004608; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unauthorised-loginhelp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004609; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unauthorised-payeerequested.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004610; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unauthoriserecentdevice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004611; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uncc-us.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004612; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unimaisfm.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004613; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unimelb.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200004614; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"union-b.ankph-stagingapi.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200004615; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unionheightsresidental.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004616; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unisito.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200004617; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unisonsouthayr.org.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004618; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uniswap-v2.tokenpocket.pro"; content:"Host"; http_header; classtype:attempted-recon; sid:200004619; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uniswap.vn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004620; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uniswaptwitter.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004621; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unitedvoicesforeducation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004622; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unitus.mk.ua"; content:"Host"; http_header; classtype:attempted-recon; sid:200004623; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"universalcenterofspirituality.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004624; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unknown-payee-decative.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004625; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unkrunchdesabor.com.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200004626; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unlock-account.dynamic-dns.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004627; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unlock-suspension.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004628; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unpaid-deliveries.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004629; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unprocessed-package-info.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004630; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unrecognisedrequestedpayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004631; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unregister-device-seclloyd.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004632; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"unregpayee-lb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004633; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"up.rev.ref.rbzqvn.ahis.com.bd"; content:"Host"; http_header; classtype:attempted-recon; sid:200004634; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"update-cl-acc.colorteam.rs"; content:"Host"; http_header; classtype:attempted-recon; sid:200004635; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"update-netflixacout.serveirc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004636; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"update-sqreup.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004637; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"update.amazoon.prime-co-jp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004638; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"update365online-secure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004639; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"updatealldomainash.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200004640; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"updatealldomainash.web.app#tietopalvelu@utu.fi"; content:"Host"; http_header; classtype:attempted-recon; sid:200004641; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"updatebilling-information-ee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004642; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"updatefile.s3.us-east.cloud-object-storage.appdomain.cloud"; content:"Host"; http_header; classtype:attempted-recon; sid:200004643; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"updatemysantan.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004644; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"updateproblemamazon.servehalflife.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004645; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"updted-access.demopage.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200004646; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"updtowa.xf.cz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004647; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uralairlines.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200004648; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uralalrlines.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200004649; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"urbenorte.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004650; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uregulowanie-naleznosci.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200004651; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"urgent-halifaxlogin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004652; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"urineaward.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004653; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"url5532.raadz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004654; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"urls.gorean.biz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004655; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"urlth.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200004656; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"us-clbc.ebanking-services.com.ibitipocachales.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004657; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uscrateclub.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004658; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uscrissey.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200004659; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"usedcopiersaustin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004660; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"user-id032i1.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004661; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"user-restore.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004662; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"users.tpg.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200004663; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"usosolowebperso1.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004664; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"utilizzamps.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004665; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"utrackafrica.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004666; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uy02.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200004667; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uz9zoiz9vqbutkpvdyp0tg-on.drv.tw"; content:"Host"; http_header; classtype:attempted-recon; sid:200004668; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"v160-251-72-160.cuvq.static.cnode.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200004669; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"v2lproblemsamazon.servequake.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004670; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"v9.vc"; content:"Host"; http_header; classtype:attempted-recon; sid:200004671; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vaikis.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004672; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"val-gardena.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004673; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"valenteplay.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004674; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"valeshoptv.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004675; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"valida2021.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200004676; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"validarusuario.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004677; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"validate-onlinesecurity.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004678; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"validation-newpayee.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004679; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"validationsystem.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004680; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"valuescaucus.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004681; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"valurant.gq"; content:"Host"; http_header; classtype:attempted-recon; sid:200004682; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"valurant.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200004683; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vanvleetfamilyfarm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004684; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"variazione-pin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004685; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vassallo.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200004686; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vasudhacrafts.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004687; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vbalskfkahsf.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200004688; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vcpstaff.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004689; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vcv-custom.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200004690; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vedantinterior.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200004691; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vegas-x.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004692; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"veiligthuis.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004693; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"veloce-outlines.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004694; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"veltz3d.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004695; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"venex-ca.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004696; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"venixotechnologies.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004697; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ventcreation.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004698; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"venueinindia.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200004699; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"veracitedusitebc.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004700; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vereins.at"; content:"Host"; http_header; classtype:attempted-recon; sid:200004701; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verfiz.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200004702; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verfyme.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004703; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verificacaocardbancoitau.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004704; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verificalogin.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200004705; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verificationdate.sytes.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004706; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verificationmessage.blob.core.windows.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004707; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verifikasi-blockeds8.forumz.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200004708; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verifikasi-facebook-akun.webnode.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004709; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verifikasiblokir.kokovid.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004710; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verify-mobile-deviceteam.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004711; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verify-nckel.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004712; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verify-redirect.instagram.com.anonqs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004713; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verify.chase.billing.info.igualdad.cl"; content:"Host"; http_header; classtype:attempted-recon; sid:200004714; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verify.paypal-verifysms.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004715; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verify.paypalsmsverify.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004716; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verifyadded-device.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004717; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verifyand.authorizedevice.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200004718; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verifymytransfer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004719; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verzeichnisse.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004720; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vf6w.byethost6.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004721; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vhs.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200004722; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"viabccp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004723; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"viabcpzoniasegurabeta.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200004724; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"viandjo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004725; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vices.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004726; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"videobigo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004727; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"videocabledolores.com.ar"; content:"Host"; http_header; classtype:attempted-recon; sid:200004728; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"videos0025a.de.tl"; content:"Host"; http_header; classtype:attempted-recon; sid:200004729; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"viewcatd.co.jp.toanji.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004730; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"viewfileverzekering.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004731; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vikingwear.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004732; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vilanovacenter.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004733; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"villasalento.puglia.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200004734; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vinceduchene.cnbcreative.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004735; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vinshiwellness.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004736; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vinssaimpex.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004737; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"viotarster.flywheelsites.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004738; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vip-tournament.itsaol.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004739; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vipfbtools.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004740; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vipuldalal11221-wixsite-com.filesusr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004741; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vir.yunen.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200004742; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"virginmobile-uk-verify.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004743; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"virtual1dattss.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004744; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"visadpsgiftcard.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004745; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"visione.co.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200004746; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vitcomm.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004747; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vivaanadventure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004748; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vivekanandcbse.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200004749; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vixas.atwebpages.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004750; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vjdisplay.com.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004751; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vk0ntakto3.webservis.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004752; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vkaktivations23.bos.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004753; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vkalathur.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200004754; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vkvotes.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004755; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vkvzlomid.viptop.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004756; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vmi330298.contaboserver.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004757; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vmi392080.contaboserver.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004758; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vmi454420.contaboserver.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004759; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vmi542007.contaboserver.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004760; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vnhh.hyperphp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004761; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vocalcoachingbysloane.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004762; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vocale-fixe-orange.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200004763; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vod.reliableiptv.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004764; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vodafone-platform.nl"; content:"Host"; http_header; classtype:attempted-recon; sid:200004765; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vodafone.bill-failure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004766; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vodafone.bill-referral.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004767; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vodafone.bills-referral.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004768; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vodafone.payment-retry.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004769; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vodafone.referred-bills.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004770; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vodafone.referred-payments.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004771; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vodafonenotice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004772; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vogotelecom.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004773; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"voipoid.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004774; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"volarevic.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004775; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"volgaday.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004776; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"volksfinance.pe"; content:"Host"; http_header; classtype:attempted-recon; sid:200004777; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"volocarspre1950s.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004778; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"votre-espace.cp89021.tmweb.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004779; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"votre-fixe-orange52.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004780; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"votre-fixe2.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004781; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"votre-fixe5.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004782; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vpapara.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004783; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vps69286.inmotionhosting.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004784; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vq21.1mb.site"; content:"Host"; http_header; classtype:attempted-recon; sid:200004785; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vrpayment.live.itonicsit.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004786; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vt3pa0.webwave.dev"; content:"Host"; http_header; classtype:attempted-recon; sid:200004787; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vtennis.vn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004788; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vtxmail2018.myfreesites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004789; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vukovarski-spomenar.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004790; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vulkanland-bio-safran.at"; content:"Host"; http_header; classtype:attempted-recon; sid:200004791; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vvipidm.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004792; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vvsmsmms.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004793; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vvsw.fast-page.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004794; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vwbank.inforia.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004795; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vwparts.pro"; content:"Host"; http_header; classtype:attempted-recon; sid:200004796; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vzrew.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004797; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"w4tywekfhj.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200004798; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"w5czf.csb.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200004799; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"w6634s.webwave.dev"; content:"Host"; http_header; classtype:attempted-recon; sid:200004800; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"waasaa.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004801; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"walmartgiftscard.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200004802; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wanehow.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004803; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"warrantjustice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004804; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"warringtonh0meservices.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004805; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"warzombs.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200004806; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wbnn.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200004807; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wbstormer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004808; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wearabletechtogo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004809; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wearenaughty.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004810; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"weaveessentialgoodness.cloud"; content:"Host"; http_header; classtype:attempted-recon; sid:200004811; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web-armas.royale-freefire1garena-bonus.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004812; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web-bf598475.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004813; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web-com-br.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004814; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web-helptiktok.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200004815; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web-orange-mail.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004816; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web-proxy.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200004817; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web-rechungbetrag-domain.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004818; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web-whatsapp.checkyourprofile.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004819; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.bredbanque.trans.sylog.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200004820; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web.royale-freefire1garena-bonus.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004821; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web1-cpn.biz.net.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200004822; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web1577.webbox444.server-home.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004823; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web4980.web07.bero-webspace.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004824; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web5040.web07.bero-webspace.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004825; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web5041.web07.bero-webspace.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004826; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"web7894.cweb02.gamingweb.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004827; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webbbb.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004828; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webcase.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200004829; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webcentricmenu.wapka.website"; content:"Host"; http_header; classtype:attempted-recon; sid:200004830; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webdatamltrainingdiag842.blob.core.windows.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004831; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webdemoapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004832; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webemailactivation.wapkiz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004833; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webexcels.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004834; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webfamily.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200004835; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webfiddle.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004836; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webindextesting.pro"; content:"Host"; http_header; classtype:attempted-recon; sid:200004837; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webinsel.at"; content:"Host"; http_header; classtype:attempted-recon; sid:200004838; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmail-sso8uyg.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200004839; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmail.accenter.answerivecovid19.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004840; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmail.bakari.com.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200004841; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmail.credit-suisse-capital.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004842; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmail.njea.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004843; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmail.telephone-sfr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004844; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmailadmin0.myfreesites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004845; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmailgobcom.creatorlink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004846; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmallin.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200004847; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmart.tw"; content:"Host"; http_header; classtype:attempted-recon; sid:200004848; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webmial.calcplane.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200004849; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"weboutlookstorageaccess.activehosted.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004850; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webservicocef.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004851; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webstories.eu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004852; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webuyitback.co.za"; content:"Host"; http_header; classtype:attempted-recon; sid:200004853; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webventelbcoin.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004854; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wecluihfrf-76tygh.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200004855; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wejgj234jg234.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004856; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"well-made-iron.surge.sh"; content:"Host"; http_header; classtype:attempted-recon; sid:200004857; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wellboreng.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004858; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wellsasn.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004859; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wellsfargos.aicsolutions.co.za"; content:"Host"; http_header; classtype:attempted-recon; sid:200004860; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wengler-group.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004861; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"werhawslink.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004862; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"westexstones.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004863; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"westportvillagegallery.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004864; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"westsfamily.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004865; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wetransferee.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004866; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wetransferir.s3.us-west-000.backblazeb2.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004867; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wg1385932.virtualuser.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004868; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whare.100webspace.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004869; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whateverpizza.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004870; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whatsap-vxcp.hotsexxmyclient.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200004871; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whatsapp-18.ikwb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004872; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whatsapp-grubsx1.zzux.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004873; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whatsapp.blazagency.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004874; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whatsapp.join-grupbokep2021.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004875; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whatsapp18girl.4pu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004876; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whatsappchat.zyns.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004877; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whatsappgroup.grub-wastapp-2021.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200004878; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whatsappgrubb.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004879; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whatsappgrup.jantungjujam.kozow.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004880; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whatsappgrupviral-bokep.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004881; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whatsapps.instanthq.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004882; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whatsapps.mrslove.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004883; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whatsapptantetante8.duckdns.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004884; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whattsapp2020.qpoe.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004885; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whattsapps.misecure.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004886; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wheel1factory.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004887; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whisoiuresowhrywarryalk.icu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004888; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"whoisnooey.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004889; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wifi.retinad.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004890; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wificomputers.ca"; content:"Host"; http_header; classtype:attempted-recon; sid:200004891; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wikiarch.cz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004892; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wild-reels.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004893; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildcard.vancouvershipping.ae"; content:"Host"; http_header; classtype:attempted-recon; sid:200004894; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildcard.villarte.gr"; content:"Host"; http_header; classtype:attempted-recon; sid:200004895; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wildcard.zjlions.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004896; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"willmartowing.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004897; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"willtoaccssnowand.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200004898; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"windocyte.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004899; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"windowcleaningny.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200004900; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"windowshost404902.s3-ap-southeast-1.amazonaws.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004901; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"windowsupdateerror.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004902; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"winescriber.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004903; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wingoo.com.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004904; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"winnice.com.tr"; content:"Host"; http_header; classtype:attempted-recon; sid:200004905; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wires-business-starter.webflow.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200004906; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wirtschaft.baesweiler.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200004907; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wisconsin-dmv-mv3001.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004908; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wkzhgs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004909; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wlake-aa.ml"; content:"Host"; http_header; classtype:attempted-recon; sid:200004910; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wonderful.gr"; content:"Host"; http_header; classtype:attempted-recon; sid:200004911; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"woodcountyd-a.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200004912; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"woodworkpalace.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004913; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wordpress-fresnes94.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004914; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"workprotocoles-com.webs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004915; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"worldlabcu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004916; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"worldwidepbx.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004917; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wp-login.azurewebsites.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004918; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wp1.j1115229.m9r2m.spectrum.myjino.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004919; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wp1.serviceorange912.pkzyp.spectrum.myjino.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004920; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wpslots.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004921; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wrap.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200004922; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wriot-alternate.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200004923; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wsxwaaaa.web.app"; content:"Host"; http_header; classtype:attempted-recon; sid:200004924; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wu7q5.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200004925; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wvwkwqk.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004926; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wvwv.xn--zonsegurasbn1cmp-hmb1nth.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004927; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ww1.bancopichincha.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004928; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ww17.casas-cb-compras.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004929; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ww2.activartusoperacionesenlinea.zonasegurabeta.com.pe.vegam.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200004930; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ww25.secure.runescape.com-k.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200004931; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ww25.services.runescape.com-j.ws"; content:"Host"; http_header; classtype:attempted-recon; sid:200004932; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wwbcpezonassegurabetas-viabcpe0o.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004933; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www-commbank.id8.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200004934; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www-cumhurbaskanligiiadesonuclari.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004935; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www-cursosdigitalesmx-com.filesusr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004936; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www-degelyehuda-org-il.filesusr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004937; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www-europe564598-com.filesusr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004938; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www-europessign-com.filesusr.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004939; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www-office-com.office365.qacust1.fpcasbdev.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004940; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www-paypal-com-login.menlosec.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004941; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www.runescape.com-tp.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200004942; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www1.xn--bmobnking-376d.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004943; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www2.cr.mufg.ajluyhr.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004944; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www2.cr.mufg.jp.adftg.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200004945; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www2.cr.mufg.jp.bzqnlhz.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004946; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www2.cr.mufg.jp.joimhmu.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004947; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www2.cr.mufg.jp.jxamtpg.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004948; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www2.cr.mufg.jp.lftihdw.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200004949; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www2.cr.mufg.jp.skhayashi1.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004950; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www2.cr.mufg.jp.skhayashi2.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004951; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www2.cr.mufg.jp.ttakasua.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004952; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www2.cr.mufg.jp.ttakasua1.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004953; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www2.cr.mufg.jp.ttakasua2.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004954; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www2.cr.mufg.jp.ttakasua3.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004955; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www2.cr.mufg.jp.ttakasua4.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004956; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"www2.cr.mufg.jp.ttakasua5.tokyo"; content:"Host"; http_header; classtype:attempted-recon; sid:200004957; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wwwinfo89564.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004958; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wypadki24.e-kei.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200004959; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wzplh.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200004960; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"x.yakinindaki-kizlar42.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200004961; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"x2mqj8a.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200004962; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xaydungtamhoanganh.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004963; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xdfgvdfxdthg.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004964; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xdjtzdyatllr4bj.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004965; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xfinifyservicesonline11.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004966; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xfinityhtml.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004967; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xgyul.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200004968; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xh13v.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004969; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xh140.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004970; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xh14n.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004971; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xh156.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004972; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xh1ou.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004973; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xh1pl.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004974; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xh1u4.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004975; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xhlgt.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004976; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xhlhs.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004977; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xhlr4.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004978; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xhlvl.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004979; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xhmnq.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004980; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xhmnu.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004981; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xhmnv.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004982; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xhmql.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004983; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xhmqu.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004984; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xhmr1.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004985; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xhs02.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004986; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xhsl1.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004987; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xianzns.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200004988; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xifx.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200004989; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xj333.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004990; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xj33s.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004991; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xj33w.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004992; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xj3pr.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004993; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xj45g.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004994; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xj45o.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004995; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xj4og.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004996; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xjm7s.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004997; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xjmr7.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004998; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xju3s.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200004999; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xjup3.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200005000; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xjup8.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200005001; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xjupq.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200005002; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xjupr.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200005003; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xjupu.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200005004; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xmley.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200005005; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--42cah8clrbc6a3bj5fsedc1eta89a.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005006; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--80aaa0a0avl4b6b.xn--p1ai"; content:"Host"; http_header; classtype:attempted-recon; sid:200005007; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--bankofmerca-3ij68171c.vg"; content:"Host"; http_header; classtype:attempted-recon; sid:200005008; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--bay-5la.com.3676239199.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005009; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--bnkofmerc-qcbee85c.vg"; content:"Host"; http_header; classtype:attempted-recon; sid:200005010; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--gmal-sya.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005011; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--pacincia-xl-qbb.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005012; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--pxful-v11b.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005013; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--ugbd1cbxo23egh.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005014; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--www-bmobnking-pf2g.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005015; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--www1-bmobnk-zt9e.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005016; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--www1-bmobnking-3p8g.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005017; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--www1bmobnking-pf2g.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005018; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--wwwbmobnk-676d.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005019; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xn--wwwbmobnking-b45f.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005020; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xoune016.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005021; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xpixl.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200005022; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xqhq4.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200005023; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xqr3i.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200005024; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xqr3n.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200005025; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xqr3u.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200005026; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xroom.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200005027; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xrx6r.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200005028; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xrxh1.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200005029; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xrxh2.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200005030; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xrxhl.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200005031; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xthac-free.ga"; content:"Host"; http_header; classtype:attempted-recon; sid:200005032; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xtreemcreative.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005033; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xtw42.mjt.lu"; content:"Host"; http_header; classtype:attempted-recon; sid:200005034; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xyproject.xtensio.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005035; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"y3s2ye.webwave.dev"; content:"Host"; http_header; classtype:attempted-recon; sid:200005036; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yaaupdnowsbcat.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005037; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yah707.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005038; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yahoolinksinfo.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005039; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yahoomailupdateservicemail.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005040; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yahooyearmail-onlineaccesslogin.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005041; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yajrouxma.cloudaccess.host"; content:"Host"; http_header; classtype:attempted-recon; sid:200005042; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yakinindaki-kizlar42.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200005043; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yakutcement.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200005044; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yalena.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200005045; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yamazon.iurvwnu.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200005046; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yanrdash.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005047; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yaqoobi.org"; content:"Host"; http_header; classtype:attempted-recon; sid:200005048; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yattsbcma.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005049; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ybs.51haoyayi.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200005050; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ydrdkbcff.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005051; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yertredrevx.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005052; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yetpack.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005053; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yeugeniy.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005054; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yht404.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005055; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yidobrkutmcwqr.corp.gulab.com.tr"; content:"Host"; http_header; classtype:attempted-recon; sid:200005056; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yifiny.ltd"; content:"Host"; http_header; classtype:attempted-recon; sid:200005057; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ympme.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005058; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yo-he.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005059; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yokbisey.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005060; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"youngil.co.kr"; content:"Host"; http_header; classtype:attempted-recon; sid:200005061; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yshau.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005062; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ytco.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200005063; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yttattupdya.weebly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005064; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yufeng.shop"; content:"Host"; http_header; classtype:attempted-recon; sid:200005065; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yuklihattontondanmasuk.claim-all77.tk"; content:"Host"; http_header; classtype:attempted-recon; sid:200005066; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yuuu6.codesandbox.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200005067; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"z-pay.biz"; content:"Host"; http_header; classtype:attempted-recon; sid:200005068; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"z54a8gj8.yolasite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005069; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zap715160-1.plesk10.zap-webspace.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005070; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zap716649-1.plesk11.zap-webspace.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005071; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zarobitoknadomu.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200005072; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zaza.neto.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200005073; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zdpgliwice.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200005074; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zeebracross.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005075; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zekkafreitas-vando-magazine.cheetah.builderall.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005076; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zemraxmie.cloudaccess.host"; content:"Host"; http_header; classtype:attempted-recon; sid:200005077; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zepfcenter-re.cf"; content:"Host"; http_header; classtype:attempted-recon; sid:200005078; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zfhub.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200005079; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zgjcsh.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200005080; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zi-3-gporange1.free.builderall.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005081; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zjgsyds.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200005082; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zlcltc01havv.wixsite.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005083; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zlmfeia.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200005084; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zohagdyj27bga1znahjjwa-on.drv.tw"; content:"Host"; http_header; classtype:attempted-recon; sid:200005085; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zon.co.jp.saasdsasda.xyz"; content:"Host"; http_header; classtype:attempted-recon; sid:200005086; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zonasegura-creditos-interbank.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005087; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zonasegurabeta.viabcp.transferencia.bcp.one21.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200005088; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zonasegurabetabcp.live"; content:"Host"; http_header; classtype:attempted-recon; sid:200005089; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zonasegurabn9-bnperu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005090; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zonaseguradbancaporinternet-interlbank.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005091; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zonaseguradvialbeta-viabcp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005092; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zonasegurainisaenwebreactivemosjuntoselperu.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005093; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zoniisha.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005094; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zoolinutricaoanimal.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200005095; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zvuqh.app.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200005096; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"154.30.211.130.bc.googleusercontent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005097; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"15cd797765fa599290e8b119ff5a1ed9-dot-solidstar-improts.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005098; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"180betper.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005099; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"188elexusbet.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005100; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"1artemisbet.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005101; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"1sultanbet.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005102; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"385693349567216-dot-sign-50268-vry.oa.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005103; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"3sekabet.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005104; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"4sekabet.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005105; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"5334456yh543dd8305d3b0d52a2616-dot-verdant-petal-307316.df.r.appspot.com#groupbilling@legalshieldcorp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005106; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"5334456yh543dd8305d3b0d52a2616-dot-verdant-petal-307316.df.r.appspot.com#solutionselite@legalshieldcorp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005107; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"7e88da4e7d84265c4906c0433ffce170-dot-solidstar-improts.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005108; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"800emailsupport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005109; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"8635345her524h5k4dd8305d3b0d52a2616-dot-rising-study-290821.df.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005110; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aagiineqxbcmnkdnceowacqnpi-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005111; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"abfqjfcarleiboruzvsyfiraxh-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005112; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"abvncdlfpfxbsxfohvagcgbjox-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005113; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"acampsrqnvicyctjutoznqjawv-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005114; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accounts.sanpchat.com.ghasalah.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005115; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"accountsecuritygoogle.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005116; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"actcfwknexhykindluesavspam-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005117; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ads-google-think.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005118; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"adscouponsbusinessaccount.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005119; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aeedb4f1e27ddb58a27d22256f00ac29-dot-solidstar-improts.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005120; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aexyzaktybsqxhsuhrxagoebry-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005121; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"agcsajpqcezxrcsmofafycsoki-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005122; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ahghamnaauwgjtqgckgifnqbql-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005123; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"allfundsbank-com-securedportal-dot-solidstar-improts.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005124; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alservic-tirmiles.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005125; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"alvizfqmgqwdtgzakwlaatodlf-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005126; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.l8u.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200005127; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amazon-check-co-jp.s4u.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200005128; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amqvuznlprhutjgmjhdvbijytr-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005129; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"amzaon.phovolt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005130; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"annftcpqerpqnyabwgjlnblilu-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005131; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"anxwqlubaabcsnylaofqhkqcfd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005132; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"app44666604777.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005133; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"app66560000.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005134; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"apple.com.services-and-support.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005135; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"appleverificationalert.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005136; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"appleverificationalert.com:443"; content:"Host"; http_header; classtype:attempted-recon; sid:200005137; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"areyourobotornot.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005138; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"artemisbetguncel.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005139; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"artemissbet.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005140; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aruba-iv.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005141; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"asadg43sdsa.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005142; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"asyabahisgiris1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005143; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"att-loginz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005144; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aubqtzrgutxkcyjxultowjskri-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005145; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"aujghwnbsqauqheywfzrldwakl-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005146; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"autolikesfree.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200005147; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"awifomfukwsrfmipfqvfmfkgya-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005148; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"axgaxrxxeqxepbouytrwkasdmi-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005149; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"azfbwtkkirslczauurcizdsaru-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005150; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bacafsxptliiqmycgekfdsugci-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005151; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"balcolfilmisx.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005152; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bancfililmilsxd.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005153; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bancolifilmisxd.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005154; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bancolmfilmilsxd.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005155; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"banfilmilsxdd.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005156; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"banteriuoaa.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005157; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bauyxseuvabdghjhhmnwhvbutu-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005158; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bcvpqkfwzgbsquxbfdclbdafvs-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005159; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bdzwuyvvgszcmjbcqgdriyeipr-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005160; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"benrefamdksi.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005161; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus-giir.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005162; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus020.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005163; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus021.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005164; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus09.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005165; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus111.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005166; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus111.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005167; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus17.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005168; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus199.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005169; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus20.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005170; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus2020.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005171; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus2021.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005172; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus20211.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005173; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus20213.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005174; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus21.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005175; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus21.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005176; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus223.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005177; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus224.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005178; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus23.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005179; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus25.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005180; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus26.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005181; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus30.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005182; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus31.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005183; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus311.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005184; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus312.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005185; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus312.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005186; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus33.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005187; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus331.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005188; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus332.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005189; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus57.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005190; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasus777.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005191; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasuscom.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005192; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgiir.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005193; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgirdi.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005194; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgiri.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005195; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgiris11.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005196; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgirisadresi.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005197; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgirisadresimiz.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005198; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgirisburasi.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005199; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgirisburasi3.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005200; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgirisburasi4.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005201; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgirisimiz1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005202; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgirisimiz1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005203; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgirmek.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005204; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgirmek.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005205; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgirmek1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005206; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgirmekicin.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005207; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusgirsenesende.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005208; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusguncelgirisimiz4.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005209; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasuslink1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005210; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasuslinkgir.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005211; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasuslinkgiris.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005212; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusorjinal1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005213; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusorjinals.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005214; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasussgir.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005215; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasussgiris.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005216; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusss.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005217; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusturkeygiris.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005218; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusturkiye.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005219; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusturkiyee.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005220; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasusum1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005221; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betasuus1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005222; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betcupgiris1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005223; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betcupgiris2.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005224; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betcupgirisadresimiz.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005225; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betcupgirisadresimiz1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005226; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betcupgiriss1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005227; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betcupum.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005228; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betebet122.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005229; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betebetgirisim.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005230; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betebetgirisimiz.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005231; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betpergir4.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005232; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betpergiris3.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005233; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"betpergirisadresimiz.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005234; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"beupkziebukuiaxnpkasazfvwe-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005235; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bezqyrdvnqoogaonymakmhclbv-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005236; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bhxpqzmnkqjpnihwfqtmerkbho-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005237; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bicyzggnaqwluajgghspiertfv-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005238; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bitferronort.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005239; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bklpbgbbwhpvlfsxztmkajbepppyhbxs-dot-onk89909.wn.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005240; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bkpcgvxbtlkyajebiepozrlrlj-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005241; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blesswokdlifemls.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005242; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"blmblifmilsxd.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005243; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bphuvbnzhxuwxdoielchuusrxy-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005244; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bqubixgnfhhkrhtkfcmvmojrlx-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005245; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brassunnysolar.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005246; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brcgorhrnnqshfdfcnovtwqflg-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005247; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"breqohqdfrmspybqykgopqcwuz-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005248; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"brodcast6002.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005249; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bsjizjdcxjkmelcdcnfpzymqgd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005250; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bsnzzefnjdnjudbjtrctjbyway-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005251; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bvridnaenqucnotzhuovhpfgea-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005252; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bycakxbglgyvkfpcpxndwbdogd-dot-gle34354569099988.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005253; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"bycakxbglgyvkfpcpxndwbdogd-dot-gle34354569099988.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005254; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cajbptwswtplhilwbbzuknicib-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005255; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"canvasist.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005256; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"caracasmateriais.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005257; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"caxtquydnkwwiyinpsmtzwclua-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005258; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"celtabet2.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005259; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"celtabet88.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005260; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"celtabets.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005261; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"celtabets2020.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005262; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cfdxskrizyqkdplzxxkldzncmj-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005263; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cgsedzcsnecvvaopfbozxeolap-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005264; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cisfyanqthrdibkcjoejonltef-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005265; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cjwknrjiijedcwslryqqguslno-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005266; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ckkfecwxlhzlisryjywxsjdpsp-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005267; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"clhzkltfafwolykndtauopcpeq-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005268; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"client-webhook-dot-qp-keybank-rrva-2020-04.uc.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005269; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"co.uvpn.west.corp.tiaabankvoices-com.out.paypallogon.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200005270; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"courrielsserveucio.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005271; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"csclifemillssxd.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005272; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ctgzqmevjbqefxcrrxqokmukgd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005273; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cvendoxjzrohuqkllpfweshwqa-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005274; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"cyrela-imoveis.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005275; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"davivinda.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005276; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ddnbflkzhpkwrvpnmkbkzrhwyw-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005277; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"deapplemoundo.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005278; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"declined-myaccount.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005279; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dekasse-berliner.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005280; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dfdavsfwfkmkvshecodrevwsge-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005281; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dgxnaqpxjfdsqbzfwwqrldwfil-dot-glmar9393293232323.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005282; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dgxxvglkfywtpilhvilbjoesrd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005283; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"diskussionsforen-ebay-de.test105227.test-account.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005284; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"diwcykiilkweuafxsmklqsjrkd-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005285; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dkjszcdujtbtaqqwfsxvebajqy-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005286; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dkptblzubazgvjptuoznvzyofu-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005287; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dngylnextoebqhmdhwxuudqhyx-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005288; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dowaba-s2dhl.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005289; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dpfoidspoifopdsifpoi.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005290; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dqjychiodigvqpzwekrjbkxspn-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005291; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"drmartensrabat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005292; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dspofipsdoifopsdifposidopfi.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005293; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dtiblog.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005294; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dvonqweogbpqcitqwhshdkgflb-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005295; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dvyqrabdukziycbjrstaumjvtr-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005296; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dxjtfdanidjevgmyfelunpysai-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005297; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dxtfupckqbtnxyfcxbyktpsfva-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005298; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"dzxfhrzzqdkoixjgnxxbrcxjyt-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005299; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ecfqlxjsqxgssxboqllqcylhfm-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005300; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"edapxirtnecpghamxcoiiihqbd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005301; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"efcgeprdhpurmdkbglxqavpgbv-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005302; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"efiserviciosint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005303; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"egdvuqvrvzumedwkjxbemvcpwf-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005304; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"egigdlgzkiuzrwkgqseutxtnkp-dot-gle34354569099988.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005305; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eiunhrjsicncneszgpboiogwuv-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005306; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ekhyknnsjsoauuxvohqhxfvupn-dot-gle34354569099988.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005307; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ekrjwxbyzrkrgwvwhovcfhhpnd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005308; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"elexbetgir1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005309; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"elexbetgirisadresimiz.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005310; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"elexusbetgir1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005311; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"elexusbetgirissitemiz.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005312; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"elexusbettgiris4.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005313; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"elexusgirisim1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005314; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"emaillogin.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005315; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"emjel.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005316; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"empleo-gt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005317; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"enel-dx.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005318; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"enel-dx.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005319; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eotjnoofnurpiyxrjmaortoezm-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005320; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"esgzkesbfsopegjocyyhtcegdl-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005321; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"evkpjlwhsoawbdgxuiemlzbkts-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005322; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ewnutupzzkogsiapmafhbcmprr-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005323; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"expcjcgmbbhkrzpsztzbpstllu-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005324; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"eypdnizsfgzkjhmhkytpltrvvz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005325; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fbpjpgbavqqyfhioqijgpfqebi-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005326; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fcmtgvmmwvamcfjgiisbwnyxsc-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005327; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fdlvietqahnjflkvfuvqnjcqcr-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005328; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"feceboolk.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005329; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fghjr74rhudfguhtfguji.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005330; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fgzmovaldltndbqwldcovmucfo-dot-gle34354569099988.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005331; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fifohbibou.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005332; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fixertawa.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005333; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fjflhvzfilaugutplitswzhxux-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005334; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fktevfabinwwgxvcqcvwmexjpe-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005335; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"flqmkxelztegbfmtxootpjbkpe-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005336; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fmbfmroamarzaeobhkaczdsndy-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005337; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fnhgjzzleamnkprxqdyvjfndfv-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005338; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"foonsmtbypjshbboxaglweukge-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005339; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"forbeservico.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005340; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"foyykiqrgnprkijhdjqgmjbxrt-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005341; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fuuclkahmtjnftffmotqlcevbq-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005342; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fwcfmuzsowlibaupgfvxgajamk-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005343; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fzajrvxkawovyxtrixjqtdlako-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005344; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fzewyfriltqxesltmxihnyttzt-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005345; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"fzwbsvfbmdwovkeahzaccfbsph-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005346; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"galjzmaugwhdpvznpzpihyyyzd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005347; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"garenafreefireinrorg.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005348; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gcgjpotqmolsyvmeuefforgehq-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005349; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gcnxhuihlzainvolqighctrgao-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005350; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"geeeculqlghwhzpulpigvxduyz-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005351; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gfzqkmcdwrxdmmvuocknyhiwdo-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005352; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"giguideut.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005353; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005354; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"glkskguyjgeeqgstqdvqqsmxuk-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005355; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmail-phone-support.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005356; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmfdlogshqmxzmaffkvlucrbfh-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005357; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gmjoqgfovewjxxvugqmlgxdzki-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005358; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"google-quality-rater-audit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005359; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gpagpegdmoixlecfzpdirvtmsy-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005360; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gqenouyupghgplahduvgzmmknq-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005361; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grandbettinggir2.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005362; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"grmjguciordvibvyrdjjcnigzg-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005363; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gshupljoghhrmeimlxtrnjcigx-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005364; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gshylemunfozjatqlskzsevesu-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005365; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gvgoheflclriltceaagsrpvvnx-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005366; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gxvxbubjtctvisfzqovipcemrg-dot-gle34354569099988.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005367; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gyubvsqwyxkvphwvgpmkavbsdw-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005368; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"gziywiolyhtiiuurreiznaathj-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005369; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"habbocreditosparati.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005370; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"halifax.deviceverificationalert.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005371; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hbhruwqjfggliiavrmumbndfmn-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005372; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"heinrylsgzfxdwtnmopbqdcyms-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005373; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"helpnew-devicerequest.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200005374; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hepsbahis01.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005375; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hepsbahis01.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005376; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hepsibahiis1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005377; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hepsibahisgirisimiz.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005378; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hepsibahisgirisimiz1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005379; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hepsibahisgirisimiz4.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005380; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hgaexdozbdxdmlrhndccuyxaxt-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005381; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hhhehdrofpjltxerompmlkxgea-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005382; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hhjxozxkuechvvuplhcdauwbwh-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005383; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hindmovie.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200005384; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hipckvcweliabpexzppnguomta-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005385; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hkiqmaczxdyofokqxjoiwunxgt-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005386; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hmsarnzjrtroorgybkxphrlyos-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005387; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"holiganguncelgir.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005388; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hostmaster.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005389; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hsbc.cancel-unauth-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005390; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hstaagwjfbslhnzruwefqnbhin-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005391; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"htwzdukvmupzdiplkjwntxzbvc-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005392; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hugncfsdzueqmirbtqcnsnslrb-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005393; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hvccjgvdenbupdpttdrnncfsjn-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005394; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hvzsusrfhrfnuaxljbzdrwgnki-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005395; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hwohwpghqothwjpjdwczixbkdz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005396; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"hxnfmkgswxvwbamzgwjknmbhlo-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005397; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"iaeaqrcydrnkpqbmhmdtrluoku-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005398; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"iczvayilwnhafzsnxekvdymnmq-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005399; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"idtbgsdlumknvzncviozvgdcvc-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005400; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"idyipsceazqejngczqikqduwkh-dot-gl909989876787.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005401; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ieecenhuovqsikthkxzmechvkt-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005402; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"igchnrisjmnneulfvngrgjejlh-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005403; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"igxxxstwwvxzyvsnxopnbtwhvu-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005404; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ihfnnirdeobpgsjbqakhfzmxaj-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005405; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"iit8866555.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005406; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ijvidnoizrupftwcfcsjtgjhkg-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005407; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ilove20.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005408; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"inopnhgolgkepdrlfiproniapo-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005409; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"instrgamsupport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005410; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"interbahis452.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005411; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"interbahisgirin.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005412; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"interbahisgirisadresimiz2.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005413; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"interbahiss1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005414; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"intergirisi.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005415; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"inzpthnpgouwpkhdrsmaehizqz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005416; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ip555644333.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005417; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ipbgdppmozpmpqiwjcyykwsrez-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005418; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ipjgcomynhbwcdmbiecmlkhxjg-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005419; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"itkrduskavqysizkizuahecmau-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005420; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"iuxunsvojakwvfwxhxoxpuajjq-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005421; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"iwkdygvimemxghrnikcorrcqga-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005422; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"iyoboaysyromudlutdpuztggmb-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005423; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jabkzahrimasjoun.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005424; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jackbinaspuol.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005425; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jdpiisjtfcsbtyvpwwgnpmxdqd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005426; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jfkpufigyptcxrtutyucgwpndr-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005427; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jlrnvrhhdhaiphhimtnfcdeevh-dot-gl909989876787.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005428; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jmbvwjobprxlwrwxzcyuuxjhrf-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005429; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jnhiqaasisespuzyxxjxgtqeqa-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005430; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joingrupwabokepx.b0tnet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005431; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"joudialbarat.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005432; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jqyenafeadrrjmgikrnxnpjfuc-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005433; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jruagbccrgiytfwurdgrzjomin-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005434; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jtkyktjvrobtabomzjjwmpqmyz-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005435; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jueimssdnngahlnvuwcfalvuby-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005436; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jupmznclsqivfsegzcnzdcxwcx-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005437; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jwrmdctbhstpklcdvbfgznhkii-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005438; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jxttvkkciklexbtaoscwzjkihn-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005439; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"jyzqezczejrlgpokadudltdgyu-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005440; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kassdrprhriaubkwkqjhpbdbsd-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005441; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kebmvtybaeeagojnftswchzccu-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005442; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kftbhedcwnfrixvstaozdizgjc-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005443; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kjkaarcxgfowtbuqftheclyumr-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005444; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"klsjdlfkjqslfkjsdlkfjldsfjldsf.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005445; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kmplgkiqtfftgqzsbdlpdphpnx-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005446; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kqcjntvqgdynoxlubbrdwaxiyo-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005447; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kqjgcscejwazmsuvzeehgqitdg-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005448; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"krakenrums.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005449; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ksnrkdpxsguonwqmrizxvmoxir-dot-gle34354569099988.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005450; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ktplcgmzvwbitgnnbavdduhlcu-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005451; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kwbmnkkwiquanlxefpokmexxfb-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005452; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"kwzbmulfvkledgeaqywwdqwaeo-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005453; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"labore-ma.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005454; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lbcointransfertfond.000webhostapp.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005455; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lbkofnlwyhbocpshekhxulqvzi-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005456; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lebbwqufwtwxxrlwdufngdbkwg-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005457; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lekeet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005458; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lerocice1911.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005459; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"levnvprozpebpbfytskliuzvoe-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005460; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lgjdlvjxqsfjnydqnqxzobmsdt-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005461; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lgsvmfhsowllqqzuwrjhdlqheu-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005462; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lifesoatpremium.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005463; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lksfbgvdwvakpxfrkqetuwrtpp-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005464; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"llifeqbrqlvngerjqqrohzvspo-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005465; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lloydsbank.protect-secure-prevent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005466; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmgxzmmkheehnixsnhktkdmkgr-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005467; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lmhwyryicszneuzbwmzkgwxzus-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005468; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"loginaccesswebmail.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005469; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"loto041219.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005470; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lqxgjrnsfgkapwlksxwwxpoesl-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005471; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lrkrodsghtqiksccrkqqkufsrb-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005472; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"luckylkhraylbwal.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005473; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"luhugxxkeixxlcyjutkaionrqq-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005474; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lxxivvvtbymtfgdodlgusrgzau-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005475; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lyzsobepxcrkqdujpzdrwexjdk-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005476; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"lzsjgqtnrlbggxnmhbqtafugon-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005477; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"macfnkgqcypvrtoumspfbicwyd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005478; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"maindiscount.su"; content:"Host"; http_header; classtype:attempted-recon; sid:200005479; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"matbetgir1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005480; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"matbetgirisimizgir.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005481; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mavibetgir5.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005482; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mavibets.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005483; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mavibett1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005484; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mavibett11.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005485; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mbobvnlykcukmfbpwnblthlzij-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005486; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"meinkonto-kontrol24.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005487; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"messageriepro3orangefrmails.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005488; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhfimkxovxnwryvuupdksqdzxz-dot-gle34354569099988.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005489; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mhmrntddrnnzuqtizixmyxbirz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005490; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"midasbuy-gift.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005491; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mjbppnpoxhpbiiwmurdmxqemuu-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005492; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mkiuyhakauywa.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005493; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mlstngtpzhbvixkcibgtyhekae-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005494; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mlxyuscsajhjsebdgmvsustxgu-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005495; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mmudatuqfhwsxvmfuxmiwztavo-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005496; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"momrnsvuryoydanfsgmupplvdv-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005497; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"monthly-o2-paymentsupport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005498; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"montmabesa1888.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005499; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mpnleiblepeanrjfdlzabmruiy-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005500; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mqyhnfcuvcddlokpvuvubxgzcn-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005501; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"msqxknfbbfeoybiagqkipoxpyb-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005502; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mtxbtbqxwgyevoyeqeegyswsbb-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005503; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"muwoughmczhpszelnkddksywto-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005504; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mvibtqxgurrssohjbqebvnzckp-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005505; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mwjwjispzyemmdsbuwppumsuxh-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005506; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mwnkvmmssxjennjyhedpfedyxf-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005507; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mxhfzfekikwqnovmmzcwzbvbdl-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005508; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myentnherballet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005509; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"myetherrwalliet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005510; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mzocyeguaokqsfmowowhkrmyhc-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005511; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"mzzhxktszzuasyqqxyxavfknzm-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005512; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nabagejec1893.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005513; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nabtolonu1913.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005514; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"neerslifemilsst.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005515; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"neltfxix.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005516; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"new1-paypal.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005517; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"newssfimilssxd.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005518; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nfhrdjinyltdttmsykogikhkub-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005519; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nfzlfwlmsrecornfuxaossebib-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005520; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ngwxqpqecmkaubcrdvwfmcbiug-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005521; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nicebradnlook.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005522; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"niqybkxwantzjehtpydryzqubm-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005523; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"niupdonhfzvctjgexzhlszuwpu-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005524; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"njjcsqfzckliiuewjgrejgzuna-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005525; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nkaqccflpbcoeoigossqcdrvkt-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005526; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nkcnuqtbzpedsnuriomdgglkiq-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005527; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nklddtqjrlzoktbrinazzcfshe-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005528; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nkyrhxklniycewnyptpwyddhrw-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005529; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nnjxvlqfoprwqjlxwxvnmfdzlj-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005530; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nnufableaxfhyzryulvhcwbwle-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005531; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"noreply-netelle.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005532; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"noreply-netelle.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005533; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nprsrritwboprvnkmtxhqxuqwb-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005534; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nqldnnnzqyrqkswjfbrkmqbrpw-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005535; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nqrwqxtcvhnjeyvmgthrqhaxcq-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005536; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nrrkgdzfirvsgcooigybhmesxx-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005537; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nsgoomqogosjieyabfjqowomgg-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005538; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nsooxqcyqbhwczpeyratdwtpxy-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005539; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nswqzktdedjqkshwmabfvrduvb-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005540; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nuqgkphjkylxnncgvpodsixrxm-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005541; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nutwlifemilsxdd.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005542; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nxbbwmyeglnisnoqhlxdzutwss-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005543; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nyqhwhnlpfvoxdgvuyaghoispc-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005544; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"nysllhnxxgmsqvpqftrretaswo-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005545; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"o2-service-account.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005546; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"obhdoxgetkjwiesxxchgzumdqv-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005547; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"obnsiujtazdghencwaepxxoquf-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005548; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ofaqfdaybabzfphbdwzvqcpmwz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005549; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"officialliker.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200005550; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ofnmznvwhsgkqjwkcvmezuwjwo-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005551; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ogmxytmsasmimgjagwtoyppyro-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005552; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ogznoctrhxgwosmlymzvwzdqci-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005553; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"okmqdygimkujaxsfvkjllgbkbg-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005554; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"olrratnbcjrijaskjecutneevl-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005555; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"omkqaqpdeghkmqxupdmromyqgr-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005556; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"online-payeerequest.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200005557; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onlinewoking.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005558; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"onsparks-dab.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005559; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"op56755543.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005560; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"opjnkdrdqigdpkyaerlzeroaxr-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005561; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"opsidposqidpoqsidpoiqspodiqsopdipqsd.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005562; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"optus-au.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005563; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"optus-com-au.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005564; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"optusnet-com.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005565; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oqskjhpgpczegrzqtsfuvyxcul-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005566; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"orange.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005567; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"otcchluxyfyexoudrkombndybx-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005568; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"outlooksffasdrewghs.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005569; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"outlookwebapp345654.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005570; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ovkwbxuphvilnapmocuhfkkjit-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005571; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"oyqlpbjivdfwrekzwplmnlwvlz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005572; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ozaydininsaat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005573; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paymentfailure-assistant.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005574; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"paymentnotificationnow.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005575; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pbeuqdqvkzzjxlkqkpdmyizjfu-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005576; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pcpuuymotbvwbllviirtazozfb-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005577; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"perabetgirs.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005578; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"percha.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005579; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"persclb.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005580; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pfabpmttcyjdujfjuemgudhbrg-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005581; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"piteqdiwdkjxpcwdbnbtntawuj-dot-gl909989876787.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005582; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"plcvxqwbylomchnydwqduupume-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005583; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pljsitpqblxikifglwsbsbosll-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005584; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pmiconnect-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005585; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pnvkjgbchjtwczggloosbncebo-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005586; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005587; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"polen-esquadrias.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005588; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"posteallert.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005589; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"productkeyforfree.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005590; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"protecctionline.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005591; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"prueba1log.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005592; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"prvtfijwncwqmonlinrocsphdx-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005593; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pslrnuvwybvrldjnjlghhnkzbj-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005594; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pubgsecretevent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005595; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pwtnwlzheicyfzfknqvxqfewfz-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005596; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"pxrnblpajwxjmhjukfkfkrwaww-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005597; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qcytvlxqxafzdkazqxpyoilqxi-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005598; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qesyvvvqcppmwlbamhmbzvfmoc-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005599; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qimecgyciqtlnmpomcvqxhmfye-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005600; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qjwulnefkmdifmsfccksiupgoh-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005601; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qjxdlervdlhjhfwegmlzeflqvv-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005602; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qkjbighjzjtpequioayegpfybd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005603; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qotexzmdkxsjscvxggolepfouj-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005604; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qprnwlqpipojxmnmqdryqcbcgs-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005605; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qqnntfnkkgyddkuyasekhrgqed-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005606; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qrkvrvbrczcmqkxwnkymequgza-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005607; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qwsqppubgntnzriifishjhjkjm-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005608; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qxmkmyhddsusmslkezojacrxax-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005609; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qxqysgrmhwlpeuhvfxmcdhmjtb-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005610; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qzeckfigxaqtmhvuztxuzshbqm-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005611; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"qztiqzwqwmvgcivbgkpgxqzspb-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005612; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rabofree.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005613; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"railcarpatient.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005614; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"raxwzcmueemsrxvqnstijzulzk-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005615; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rdbqvxlywwozvxqeykujqiptdf-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005616; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"re-redirection-acc-id923872635122.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005617; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"re-redirection-pp-account-id98763432.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005618; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rediractionid547012016089540218057.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005619; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rekapuolam.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005620; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"resbet.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005621; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"resbetsgiris.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005622; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"restbetgir1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005623; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"restbetgirisadresimiz.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005624; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"restbetgirisadresimiz1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005625; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"revert-payee-request.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005626; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"reybhmargaupbnkvocyrqlpieo-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005627; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rhenphyoefnsjswwfzrckubrdd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005628; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rimsdqbdivtkmrymlwslktderw-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005629; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"riuflumaztvfhdpdllvxurtdes-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005630; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rjlhorvkdujiojvqyzwbvjhdkq-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005631; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rjxhygxetbfszoksmpbozhlikq-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005632; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkbghlktlwymlmxhkcljlflbya-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005633; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rkybnqmxeznjdmjosmroyxvrss-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005634; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rm-parcel6297.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005635; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rmzengenharia.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005636; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rodgphcgsxwfroxxvuojkoboes-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005637; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"roupakids.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005638; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"royalmail-package-cost.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200005639; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rqbkgdzhdmmydqjnaevinoebcr-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005640; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rqqopwpnuaiurxlwdavwmhwcik-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005641; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rqxwomhgvyzsztgglcdjdrqwog-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005642; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rqyteseiociddtbisefgqmpzui-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005643; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rrngslplnsvrklexwfzfbckwza-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005644; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rrvrrwvgekbdloetwquevqepsd-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005645; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rtjwianizrsbintaqdcwcuhmgg-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005646; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rvycgfbkhjbpxlxmsutahpbqwq-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005647; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"rxpwtetasancamqlbusefctqlm-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005648; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"safirbetgirisadresimiz.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005649; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"safirbetgirisadresimiz.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005650; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"safirbetgiristikla.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005651; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sajkd12.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005652; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sbcgloballoginz.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005653; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sbvvhygnbhywmkaseyqlxtrwrz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005654; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sdxnxauuetspcyzgkmwktqkxkd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005655; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sebat-dhl.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005656; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-halifaxaccount.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005657; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"secure-verify-new-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005658; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"securecustomer-connect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005659; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"securehalifaxonline-account.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005660; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"security-hs-bc-payee-alert.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005661; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"seguritycbl.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005662; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sehmwdfgtnjepodlaucnctqxap-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005663; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sekabetgiriss.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005664; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sekabetgiriss1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005665; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sekabetgirissitemiz.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005666; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicabbout.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005667; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviceinfosclients01.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005668; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviciocourrio.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005669; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviciocourrio12.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005670; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"serviciomob.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005671; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"servicioscourrielos.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005672; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sgkipqqatecosndzdwisnpxcjk-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005673; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shkzsucomfangtitkxnegxszmq-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005674; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"shrkfhnqtwyrxgvikvsjrgsxzk-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005675; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"siporados15585.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005676; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sklepkody.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200005677; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sknkhmlltctsdkkunawatwiqad-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005678; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"skyjhagzdxgxrdgejycqamhkds-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005679; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"snnvyjeyrwcsiisnfvxxhdmfaz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005680; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"soatbanlifimils.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005681; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sobisparkss-poser.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005682; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"somsavritalses.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005683; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sonevie100.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005684; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sotprelifemils.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005685; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sotpremiunlapt.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005686; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sp579813.sitebeat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005687; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"specialxevent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005688; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"spjmpgijzwbqywfndsypsauwey-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005689; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sptweohnsonkiqrdzejcenxpjo-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005690; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sqairqessehilunlzweccacaih-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005691; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ssqbjxlizwszuhumnebriuynzi-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005692; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sthqncsdidugbpykytaycffowt-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005693; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"storespy.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200005694; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"suchenm0bile.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200005695; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sudkeuceihlmaxsnblrlwhhuil-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005696; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sultanbetgirisadresimiz.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005697; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"sultanbetgirisadresimiz1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005698; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"superbahisgir12.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005699; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"superbahisgir2.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005700; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"superbahisgirisadresimiz.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005701; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"superbahisgirisadresimiz3.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005702; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"superbahisim1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005703; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"support-att.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005704; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"surasoatlifes.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005705; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"syvqtyjsbsdzharvpimqdtmjwt-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005706; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"szsohghuqjzgyweaaeipphvwie-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005707; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tbndhkvlbuyqvvlxxezgjigezg-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005708; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tcolhjifjcddepbclghckcjraw-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005709; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tdnpaxrmnlanpqdkmeedlrbgmi-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005710; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tfyxjzraztydtcoxsacafuompt-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005711; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tifwcrqlrzyhugaazbuicveaum-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005712; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tllxebvisylrklwfziaeqvzoyg-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005713; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tmedfavfwrudfzvcaxfcxyaecp-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005714; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tmxcyusqtgwvkepjjplzngmvsp-dot-gle34354569099988.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005715; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tmxigmomwymprntqciqgzaxiqm-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005716; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tojolkbeyruscfqktunemucxiv-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005717; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"toplifemilexd.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005718; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpfzwhjdhlndrmahrgxbanpkie-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005719; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpslessdoow.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005720; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpswodonline.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005721; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tpupbfkqdnhnbpdcyxclqyadyn-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005722; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"trsdcbqbsctgogxloyclfqstti-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005723; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"trynbyonknwfdinbmezvswrvor-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005724; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsbrnmfftuyqpbmdnxnglbevvh-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005725; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsocchcctxposijmfkmkcqvlzd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005726; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tsvfbhudbcesyyuqucsquhkihl-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005727; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tttqtdqgcdhmuzdmcvkqpjkoxs-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005728; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"twfgadfuverwzhwigymnewsuyn-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005729; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"twqmelcinzffbgfxpdcnpsonke-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005730; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"txpqzgmhmivcvqwozsekyuavwd-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005731; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"txzllhpquzshdkbsjitxadzlgi-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005732; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tyacvhyxtjfhqtauvubhjpriwv-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005733; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tzaqleoribhqzfyqirsxnbsbvj-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005734; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"tzusgssiwqwzgzcxskkzplaweu-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005735; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uajttelworuzltgqjlzbmzdgvz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005736; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uammvcqlmluyhtaerunpmsvmok-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005737; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uebbubbhgicuiufdjajfvwabtc-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005738; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ufdimmaglpdoywiwlcjshwlsdq-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005739; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uilspavwghrlzcyktizluancrj-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005740; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ukdgndwofoulxaybxlvkpbcnxp-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005741; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uklloydscancel.helpnew-devicerequest.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200005742; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ukresidential-servicesupport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005743; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ulbnndlqqhloudajofhgwteqeh-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005744; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"umwkhuqlgntjwxqxkytewazsyz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005745; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uoitkilztxeaeicunjzwhthpfv-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005746; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"upt2234555.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005747; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"urtkjcxhpjdxmoanxiveejsffu-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005748; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"usifkziihxxttmiwqokencuenp-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005749; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"utkrwcqslzvzxhxtotckowbimo-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005750; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"utuumrukxkkjbwoejwspqecmvi-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005751; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uvjktpiobfkjfuykrombqafvss-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005752; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uvqjjzpjzsddffglnznygkssmg-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005753; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uvsmwvavrcjzyostrcidayyzit-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005754; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uwkxfdxkmqydzaoqppokvguvew-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005755; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uwmhstgcokecqohpahbfekgsvd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005756; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"uzrlcqeknffghnvofxmfcwjmfl-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005757; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"validatezim44-cdsggdx-s.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005758; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vanglzuawcothhvwuzndneishd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005759; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vanmarckegroup-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005760; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vbozlubquasoodkeczwekrwtef-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005761; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vcirxilfedrmlwnffzgotjqcxz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005762; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vclpcesmwwfymdtlxrxeoqcyls-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005763; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vegas-x.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200005764; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"verify-newpayee-support.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005765; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vevobahis211.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005766; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vevobahisbet.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005767; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vevobahisgirissite.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005768; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vevobahisgunceladres.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005769; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vevobahisimgir.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005770; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vevobahisimgir.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005771; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vevobahiss.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005772; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vevobahiss1.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005773; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vevobahissgir.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005774; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vevobahissguncel.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005775; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vevobahsgirisim.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005776; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vevoobahis.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005777; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vfcfthrlctfjyzvwpnpwozlwas-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005778; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vhfdricjycjeeyqzurpkbesdjs-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005779; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vhnptwatrwogcnzbgjtuerjrii-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005780; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"viettel-com-dot-c2c01-531c7.uc.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005781; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vipps-sikkerhet.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200005782; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"viptbslook.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005783; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vldzejxdyfqqeldpyyifmlcxwh-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005784; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vlttszmawuqrffeudikastnyee-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005785; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vmqxhagmyleckhrooraulycbne-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005786; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vngjusjjzyamcgcsogexelfvka-dot-gle34354569099988.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005787; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vodafone.billing-incorrect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005788; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"votrwisxc.moonfruit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005789; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vsrmjdzemzeivfptncxsrxemiy-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005790; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vswkuwstcwtwxbptfhtbgccvib-dot-gle34354569099988.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005791; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vvbzcdxbkprckhkctinikkisch-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005792; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vwcguauzkivykozaeoxvkaornb-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005793; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vxhkuihraoyiiqyojoxrdpldxu-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005794; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"vxshhayetbwpvmcchgvsibiluz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005795; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wcjnpbdkfaqhnlfsiysiuwzrxc-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005796; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"webexert.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005797; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wekwonamfxqucbpaazieheuvva-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005798; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"welyadzkzynmifvwfoijegzimg-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005799; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"weospojfwuqtrsdzfwtnodypjo-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005800; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wfnnhmleoipkzxgmbfogaxdrgo-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005801; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wgjflohpzqymtbuyiifinfphqh-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005802; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wireconfirmation68c10a25442a3e13.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005803; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wjgligxuvufpwyxafasccaitvk-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005804; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wjthgnlryrjblbgrzxnjhwaftr-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005805; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wkildgajztekgkqfhswlveupon-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005806; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wmvnwrknlprunvavsjygtsmtjf-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005807; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wmzhlieremguv.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005808; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wokrdlifemilss.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005809; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wordonlinexd.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005810; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"wqcobxallxtfhnacviaoivxzqx-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005811; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xag42asz.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005812; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xeqkapuosszpejuuxwsafagrce-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005813; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xfbmgcuwewmhzgulqdhldenpqc-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005814; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xfinityconnect4you.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005815; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xfjjrmvqlfymgjbqipetmstgpt-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005816; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xgcyynphjsakadedblmxrvxnkm-dot-gle34354569099988.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005817; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xjicgzwvsauxcfuemhztgsamfp-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005818; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xkmassmygwyyhxneczegddyghe-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005819; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xkrjgluhzwsxtegjyzgpplnrzo-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005820; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xkuiyhbhafsvwxmtjttdvflinc-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005821; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xlfgxbpuiujqdrjliisnsxemjo-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005822; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xlqkqlphwtbnwapcaciscaneak-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005823; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xmotbdbywfhqeemdkfgzzanfhn-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005824; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xpbmbjqmcupxwogwvpobxphaja-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005825; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xrgfyvukjbjmltptygybvfpddo-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005826; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xtzzjbbicmpdzxhuxsdzjqftkz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005827; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xucdaxleimwudtposjrquwdtrj-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005828; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"xxx-com-dot-c2c01-531c7.uc.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005829; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yauohwijrqefqyiywrxzejtqcw-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005830; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yauyatvbqcscfkfhbpjatczjdf-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005831; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ycmnrofybpeevyjahdxtrdoosy-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005832; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ycxldxoutrlsbaijddypracrds-dot-gl909989876787.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005833; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yezvjyinfyqucmuifwtuacudlm-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005834; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ygvshhhpdlapaxmbsbphpihgqz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005835; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yhpetzbusfpodtevjptlqurxga-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005836; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ykjixqdvuawmeuuhnzcfuezmmb-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005837; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ynlcbshuseksyfhioxptravohi-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005838; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"youwingirisimiz.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005839; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ypyztdoebuckpwjimctswtrbtv-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005840; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yttevwtbwazqqggxcwpglexowd-dot-poised-bot-306515.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005841; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yullkztrdcksaltuomquqwjjbd-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005842; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yuoshxnumidqzigyvuznddzyrk-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005843; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yvhlrpzjtbwmlixdclysackumt-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005844; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yxzyjhcvjvlxsqjhswzgsnxdwe-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005845; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yyubtfunzkkktkuzqrgpwuelzt-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005846; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"yzvazqpfknslwsolkgqzfyoqku-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005847; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zavfofgyuxicwtuzvokbemhpuj-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005848; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zbiforxqiqvdsaoivsynhmsjcr-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005849; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zdoydqgvkgsjizrojkyjroprzb-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005850; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zfskdnhnzmegbpxnljnhuspleu-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005851; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zhjlnoykuclbuhjitnzjtomgri-dot-gl099898987fhkl.uk.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005852; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zhwpnqkpacaxczukrumqkissbq-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005853; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zkhvfpgapichhmnjcxjqhwowij-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005854; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zmail221.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005855; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"ztowolmdxneypiyyfcsppghjyw-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005856; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zuqmmtrjjflsrnapdrloczhzvs-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005857; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zvxtgoavpqprobctdceqqnnegn-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005858; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zwnsyntowjpkhnkxxuydcdrxnx-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005859; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"zyggmdulzjyqdnywrpoipilkuq-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005860; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ameli-assurance/remboursement/login/"; http_uri; nocase; content:"000p6vl.wcomhost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005861; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ameli-assurance/remboursement/login/"; http_uri; nocase; content:"045a3c0.wcomhost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005862; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ameli-assurance/remboursement/login/iframe-page2.html"; http_uri; nocase; content:"045a3c0.wcomhost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005863; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/actualites/ameliassurance-sms/remboursement/login/iframe-page3.html"; http_uri; nocase; content:"045b66e.wcomhost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005864; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/form-5134768/serra-es"; http_uri; nocase; content:"123formbuilder.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005865; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/form-5220557/"; http_uri; nocase; content:"123formbuilder.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005866; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/form-5559915/microsoft-team"; http_uri; nocase; content:"123formbuilder.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005867; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/form-5578660/form"; http_uri; nocase; content:"123formbuilder.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005868; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/b/s!auksoo1k68f1grbxbhid1sl-ye8w"; http_uri; nocase; content:"1drv.ms"; content:"Host"; http_header; classtype:attempted-recon; sid:200005869; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/o/s!asdoqhdzchzkceksme1zxz0tbys"; http_uri; nocase; content:"1drv.ms"; content:"Host"; http_header; classtype:attempted-recon; sid:200005870; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/o/s!bhz_l4f82iidgdlq0yw9injcmrepsa?e=qj2ci0qsu0yjwbnbvhihag&\;at=9"; http_uri; nocase; content:"1drv.ms"; content:"Host"; http_header; classtype:attempted-recon; sid:200005871; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/o/s!biwi80oasoewgxoqavzz0prwohuk?e=c-d9fhgd9ue1qswmmond5w&\;at=9"; http_uri; nocase; content:"1drv.ms"; content:"Host"; http_header; classtype:attempted-recon; sid:200005872; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/u/s!aklt5-l7t4i2xvktl7g9mdgfcknm?e=cfngyw"; http_uri; nocase; content:"1drv.ms"; content:"Host"; http_header; classtype:attempted-recon; sid:200005873; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/u/s!aqzh3mzuvkddmbmdyu98fbfw9doy?e=mdjorx"; http_uri; nocase; content:"1drv.ms"; content:"Host"; http_header; classtype:attempted-recon; sid:200005874; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/u/s!auzzdh9o3pd3cutlhnbnixde2iu?e=bypust"; http_uri; nocase; content:"1drv.ms"; content:"Host"; http_header; classtype:attempted-recon; sid:200005875; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/u/s!avhfkscca3-jeadxnym7-7yxw9g?e=o7d49o"; http_uri; nocase; content:"1drv.ms"; content:"Host"; http_header; classtype:attempted-recon; sid:200005876; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/w/s!aguoqd84zse3gt7r1mqpd90amvv3"; http_uri; nocase; content:"1drv.ms"; content:"Host"; http_header; classtype:attempted-recon; sid:200005877; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/w/s!apd3vyavbh21ar0iamslddeaawa"; http_uri; nocase; content:"1drv.ms"; content:"Host"; http_header; classtype:attempted-recon; sid:200005878; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/w/s!aqddksghr0xkggfjgffiesdksvy4?e=o0s6zk"; http_uri; nocase; content:"1drv.ms"; content:"Host"; http_header; classtype:attempted-recon; sid:200005879; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/w/s!at6abcmxoqeqgrrahazju3fo1ojj"; http_uri; nocase; content:"1drv.ms"; content:"Host"; http_header; classtype:attempted-recon; sid:200005880; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/xs/s!am4xl7rvugywaxod-4xmpezy4mk?wdformid=%7ba1c5478a-c065-4b6f-b415-c1a0973f4392%7d"; http_uri; nocase; content:"1drv.ms"; content:"Host"; http_header; classtype:attempted-recon; sid:200005881; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/xs/s!am4xl7rvugywaxod-4xmpezy4mk?wdformid=%7ba1c5478a-c065-4b6f-b415-c1a0973f4392%7d%3e"; http_uri; nocase; content:"1drv.ms"; content:"Host"; http_header; classtype:attempted-recon; sid:200005882; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/a/321069"; http_uri; nocase; content:"1ka.si"; content:"Host"; http_header; classtype:attempted-recon; sid:200005883; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/a/328454"; http_uri; nocase; content:"1ka.si"; content:"Host"; http_header; classtype:attempted-recon; sid:200005884; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/a/328864"; http_uri; nocase; content:"1ka.si"; content:"Host"; http_header; classtype:attempted-recon; sid:200005885; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wordpress/wp-content/plugins/fighter/install/fr"; http_uri; nocase; content:"1vip188bet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005886; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wordpress/wp-content/plugins/fighter/install/fr/"; http_uri; nocase; content:"1vip188bet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005887; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/atualizacao/mobile/04/login"; http_uri; nocase; content:"247.48.198.104.bc.googleusercontent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005888; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/atualizacao/mobile/04/login/"; http_uri; nocase; content:"247.48.198.104.bc.googleusercontent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005889; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/home/home/01/device/?key=q5a2k4p77rphelpot5sacbrv1lom7y9v3xjc8xhowjrgaqwiubi0y8gmyqcgwcmd7sbgy4hikfjflfcllkob1vogtcibqzvyxqhyz2yjkuslw4zideoiuu6hpg87gmaabdllpghkc4zd392ykrpzmv"; http_uri; nocase; content:"247.48.198.104.bc.googleusercontent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005890; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/home/home/01/device/?key=z9plupytu8yklaaykxqdtuks8grsia1fo6lafnkes484hdzkanhne9gdey4nysiooac3wpcs1anl9k5g5uahzntjlu1memdgctlyaqsb10d6fetzbqefyygxdburcvnwsjrps5kdwtnj3nvuxy5bro"; http_uri; nocase; content:"247.48.198.104.bc.googleusercontent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005891; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/home/home/02/login/?key=k68ayig3d2ibfgfkeg1vhfkq6ms73oztqfgemdugv8wlwk0gnjr2hgz09dmcgr4jzkrfkykp6kyxbntykwbyedpndzkiy2giil3puuhotsqkjujjgpq9ho2dskmt2cqtwhvbwtn11a5ocz3wt2v2fw"; http_uri; nocase; content:"247.48.198.104.bc.googleusercontent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005892; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/home/home/02/login/?key=o7s6spkpgkqezvafmy42gtsb0vcq7xaspyy4garyholhp1dfgyf7phg1pk60xjhg2suiem8t0ucqm7tqni2rj10gz3plndt816sjchch6wzrrvnln0vnijyngii32op8obg4xvtl0o4eyfjhd7vcrj"; http_uri; nocase; content:"247.48.198.104.bc.googleusercontent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005893; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/atendimento/home/02/nick/?key=ladtjhyahj7pmllgynnoptnxpeofumoi5awrbvk7kstpwwz9nnyjz0ko2clar72wlnevi3iqzij3ubgwhbdawy7dwhkvq9iipuselxgzhxqx1gl13fvxhtfqvooi3haspkxza5axvs4ckyimgk69i8"; http_uri; nocase; content:"32.52.198.35.bc.googleusercontent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005894; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?m=0%5c"; http_uri; nocase; content:"377080202567359722137708020256735972.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005895; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/.inv2019/login.php?l=_jehfuq_vjoxk0qwhtogydw1774256418&\;fid.13inboxlight.aspxn.1774256418&\;fid.125289964252813inboxlight99642_product-email&\;email=frank@skyit.com.au"; http_uri; nocase; content:"3dhome.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200005896; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/themes/3rdst/8-login-form/"; http_uri; nocase; content:"3rdstreetmarket.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005897; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/index.php/false/false/py1n.html/discovercard.com/dfs/accounthome/summary/-www.schwab.com/secure.accurint.com/unfcu2.org/login1/wachovia.com/myaccounts.aspx/investing.schwab.com/secure/schwab/step1.html"; http_uri; nocase; content:"43-245-61-213.cprapid.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005898; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2529b.html"; http_uri; nocase; content:"6b92529b.storage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005899; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/update/mail/0/secure/confirm/login/inicio.html?i=1"; http_uri; nocase; content:"78689snusgh.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005900; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/update/mail/0/secure/confirm/login/inicio.html?i=2"; http_uri; nocase; content:"78689snusgh.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005901; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?m=0%5c"; http_uri; nocase; content:"8010361370310234068010361370310234.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005902; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/index.html"; http_uri; nocase; content:"97cebc60b732.storage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005903; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/sherring_aada_edu1/epxaaqphuzvnqoye4vgldzkbzmud1mij-ek8r72wltpdyq?e=szm5ky"; http_uri; nocase; content:"aadaedu-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005904; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/#andy.coles@aviva.com"; http_uri; nocase; content:"aagiineqxbcmnkdnceowacqnpi-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005905; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tee.html"; http_uri; nocase; content:"access2cars.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200005906; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ee"; http_uri; nocase; content:"accountbilling-security.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005907; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ee/"; http_uri; nocase; content:"accountbilling-security.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005908; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/servicelogin?passive=1209600&osid=1&continue=https://plus.google.com/%26&followup=https://plus.google.com/%26"; http_uri; nocase; content:"accounts.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005909; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/servicelogin?service=cds&\;passive=1209600&\;continue=https://storage.cloud.google.com/staging.maintainancecomponeta.appspot.com/bsnnindex.html&\;followup=https://storage.cloud.google.com/staging.maintainancecomponeta.appspot.com/bsnnindex.html"; http_uri; nocase; content:"accounts.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005910; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/servicelogin?service=cds&passive=1209600&continue=https://storage.cloud.google.com/appspotv450i7r8h9vf9y6yt8uiuft58f7uf5yye36u0jtyf78uuyfyy/index.html&followup=https://storage.cloud.google.com/appspotv450i7r8h9vf9y6yt8uiuft58f7uf5yye36u0jtyf78uuyfyy/index.html"; http_uri; nocase; content:"accounts.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005911; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/servicelogin?service=cds&passive=1209600&continue=https://storage.cloud.google.com/officpcpspbcncuser.appspot.com/index.htm&followup=https://storage.cloud.google.com/officpcpspbcncuser.appspot.com/index.htm"; http_uri; nocase; content:"accounts.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005912; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/servicelogin?service=cds&passive=1209600&continue=https://storage.cloud.google.com/poopnoomprops-oo987700ok/newrbindex.html&followup=https://storage.cloud.google.com/poopnoomprops-oo987700ok/newrbindex.html"; http_uri; nocase; content:"accounts.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005913; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/servicelogin?service=cds&passive=1209600&continue=https://storage.cloud.google.com/staging.maintainancecomponeta.appspot.com/bsnnindex.html&followup=https://storage.cloud.google.com/staging.maintainancecomponeta.appspot.com/bsnnindex.html"; http_uri; nocase; content:"accounts.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005914; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/servicelogin?service=cds&passive=1209600&continue=https://storage.cloud.google.com/user517497679326978.appspot.com/index.html&followup=https://storage.cloud.google.com/user517497679326978.appspot.com/index.html"; http_uri; nocase; content:"accounts.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005915; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/servicelogin?service=cds&passive=1209600&continue=https://storage.cloud.google.com/user7773578ixh1092839.appspot.com/index.html&followup=https://storage.cloud.google.com/user7773578ixh1092839.appspot.com/index.html"; http_uri; nocase; content:"accounts.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005916; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/servicelogin?service=cds&passive=1209600&continue=https://storage.cloud.google.com/xzrdzcdruerp.appspot.com/index.html&followup=https://storage.cloud.google.com/xzrdzcdruerp.appspot.com/index.html"; http_uri; nocase; content:"accounts.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005917; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/add/notla11/"; http_uri; nocase; content:"accounts.sanpchat.com.ghasalah.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005918; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/blondinfortin/gdhkjlhjdfhgjkh686e564wm/index.php"; http_uri; nocase; content:"accutechengg.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005919; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/qt3ug"; http_uri; nocase; content:"acortar.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200005920; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2021/banks/directing/easyweb.td.com/index.html"; http_uri; nocase; content:"adesignsovast.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005921; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/janne_advokatsf_no/emjxnmfjyfvnt-zxabbci14bjpxfodh3cynmh1kt5cdv-g?e=7ou09z"; http_uri; nocase; content:"advokatsf-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005922; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/alert.php"; http_uri; nocase; content:"aibservicesupport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005923; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2005/03/colourful-life-of-aij.html"; http_uri; nocase; content:"aijcs.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005924; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-active/index.php?dax=3d$ynbty2ludg9zaebiz="; http_uri; nocase; content:"akashnet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005925; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/modules/"; http_uri; nocase; content:"aladasinsaat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005926; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jczonoxlbc.html?jhbfdxeazsxdfcygvbhubnijnononjiuhbgvvgfcfdxsezxrdfcgvhbgvfcd"; http_uri; nocase; content:"albayrakspor.org.tr"; content:"Host"; http_header; classtype:attempted-recon; sid:200005927; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jczonoxlbc.html?jhbfdxeazsxdfcygvbhubnijnononjiuhbgvvgfcfxdsezxrdfcgvhbvgfcd"; http_uri; nocase; content:"albayrakspor.org.tr"; content:"Host"; http_header; classtype:attempted-recon; sid:200005928; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login"; http_uri; nocase; content:"alertabancainternet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005929; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/venus_gardose_talke_com/_layouts/15/wopiframe.aspx?guestaccesstoken=8extkunxrkqozifs2sycqmk4ox0ntao7cizsavm5mjc=&\;docid=1_14abcf62971634e6b8387df30ef7d978b&\;wdformid={83a6cfc0-5689-4aa4-ab13-96952b8999ba}&\;action=formsubmit"; http_uri; nocase; content:"alfredtalkelogisticservices-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005930; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/themes/wellsfargo"; http_uri; nocase; content:"aliceflorist.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005931; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/assets/netflix639/"; http_uri; nocase; content:"alishasproducts.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005932; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/mraee_nseir_almawakeb_sch_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=uiturlbbxai6dzplw74qggavcoaxilzfjv%2b4qbppv%2fk%3d&docid=1_1ccd7afd6f1dc4e7181cedf880bb25aa8&wdformid=%7bfe0bf4d3%2da69d%2d4464%2d9e31%2d7d4026f422a8%7d&action=formsubmit"; http_uri; nocase; content:"almawakebschool-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005933; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gjyi/img/folder/index2.html"; http_uri; nocase; content:"alresalahct.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005934; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hgfd/img/folder/index2.html"; http_uri; nocase; content:"alresalahct.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005935; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/templates/beez3/egaliciaeminent"; http_uri; nocase; content:"alspect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005936; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/templates/beez3/egaliciaeminent/188.166.98.24982502/agregar/telefono/contacto/operacion-exitosa.html"; http_uri; nocase; content:"alspect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005937; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/thomas_salemkour_open-xerox_com/eq5ps-07ovvnl5eo4rrthymb7a9euvzss3urntui3dvyyq?e=kqnstw"; http_uri; nocase; content:"alternanetworks-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005938; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/our/ourtime/ourtime.html"; http_uri; nocase; content:"ambrosecourt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005939; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/sebastiangerlach_amena-invest_de/_layouts/15/authenticate.aspx"; http_uri; nocase; content:"amenainvest-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005940; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jps/webmail_reset.htm"; http_uri; nocase; content:"anekaslot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005941; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/jklute_aahom_org/_layouts/15/wopiframe.aspx?sourcedoc={32b08432-df6e-45ce-b9dd-bd06a2fd8ffc}&\;action=default&\;originalpath=ahr0chm6ly9hbm5hcmjvcmhhbmrzb25tdxnldw0tbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvamtsdxrlx2fhag9tx29yzy9faktfc0rkdtm4nuz1zdi5qnfmowpfd0j2u3ewwjvxag1isnnittdkdvg4rdbrp3j0aw1lptnhmwxmtui0mtbn"; http_uri; nocase; content:"annarborhandsonmuseum-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005942; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/jklute_aahom_org/_layouts/15/wopiframe2.aspx?sourcedoc={32b08432-df6e-45ce-b9dd-bd06a2fd8ffc}&\;action=default&\;originalpath=ahr0chm6ly9hbm5hcmjvcmhhbmrzb25tdxnldw0tbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvamtsdxrlx2fhag9tx29yzy9faktfc0rkdtm4nuz1zdi5qnfmowpfd0j2u3ewwjvxag1isnnittdkdvg4rdbrp3j0aw1lptnhmwxmtui0mtbn"; http_uri; nocase; content:"annarborhandsonmuseum-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005943; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/mary_belisle_aw_org/_layouts/15/wopiframe.aspx?guestaccesstoken=rxpjqbfln4drfnv4sgfnnqwyldsjbnceldcpqdpe7hu%3d&docid=1_120e0a15e74f24c589d87788d99c1c667&wdformid=%7b493b5cd7%2d227e%2d4339%2d98b3%2da8644c8ce588%7d&action=formsubmit"; http_uri; nocase; content:"anniewright-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005944; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redirect?s=857592&\;at=4&\;rt=api&\;o=37248906&\;s1=2d8a1db7066ae145-5e70fb7b763882480f1ffb01&\;s2=&\;s3="; http_uri; nocase; content:"api.bdisl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005945; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redirect?s=857592&\;at=4&\;rt=api&\;o=96574574&\;s1=d2cb2653d154e850-5ea5960ca629f275326f9e81&\;s2=&\;s3="; http_uri; nocase; content:"api.bdisl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005946; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redirect?s=857592&\;at=4&\;rt=api&\;o=96668170&\;s1=2b94eb26dd71a6e0-5ea5961f20937a71e917f602&\;s2=&\;s3="; http_uri; nocase; content:"api.bdisl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005947; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/caja-de-herramientas/mx.com.vepormas.cajadeherramientas/downloading.html"; http_uri; nocase; content:"apkandroid.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200005948; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/banbif-empresas/com.banbifappbancaempresas"; http_uri; nocase; content:"apksfull.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005949; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/sac/gov/home.html"; http_uri; nocase; content:"aplicativo-caixa.atendimentos4.sg-host.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005950; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s/43l7nxncafyxdiaecwxblt0yo2hn7epz"; http_uri; nocase; content:"app.box.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005951; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s/ahjtfcbzgv4eqe763sqmdk4xby5dc89m"; http_uri; nocase; content:"app.box.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005952; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s/aju8uu3l7x4uusi7v53z09uk6rvwd161"; http_uri; nocase; content:"app.box.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005953; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s/b9fu9axf9rcv7bhjp80fpcm8zna5wcwi"; http_uri; nocase; content:"app.box.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005954; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s/bog5q0dw9nxw2zs7e01m5y6zw23oeszj"; http_uri; nocase; content:"app.box.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005955; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s/bqjrkxs7pfyfcf10sqcrn9gwah0p1d7k"; http_uri; nocase; content:"app.box.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005956; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s/if8xiaou5slu0ul71eoswkk6l13byalw"; http_uri; nocase; content:"app.box.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005957; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s/nnetuxxysx9wh6g5oim0kcvfx5h3q5t7"; http_uri; nocase; content:"app.box.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005958; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s/x6agocx9zvj049azirk4aw3xrqdedqhl"; http_uri; nocase; content:"app.box.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005959; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s/ymr0ltw3hmn8icxebz16gjhcyhqa49w4"; http_uri; nocase; content:"app.box.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005960; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/96f48ddb9415f1307e22c50a18ad07c1785a5164?"; http_uri; nocase; content:"app.pandadoc.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005961; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/22f3qw"; http_uri; nocase; content:"app.simplenote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005962; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/cmxgsj"; http_uri; nocase; content:"app.simplenote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005963; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/lhwhl9"; http_uri; nocase; content:"app.simplenote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005964; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/publish/xhrdvc"; http_uri; nocase; content:"app.simplenote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005965; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/gene_arisebuilds_com/eggkjirnlknoh4k8dkclnxcbpfg-oj1ihz4vpywlomnezw?e=gqgvfz"; http_uri; nocase; content:"arisebuildscom-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005966; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jcroofinginc/jcroofinginc/u.php"; http_uri; nocase; content:"arrowsurfandsport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005967; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/adupte/index.html"; http_uri; nocase; content:"arsino.chroniclerestaurant.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200005968; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?m=1"; http_uri; nocase; content:"aruba-iv.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005969; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/slurring.php"; http_uri; nocase; content:"asia-firstnews.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005970; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dropbx"; http_uri; nocase; content:"asiiadinova.goosecreektradingpost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005971; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dropbx/mrrivfqsx0w56yjs2n12ktqjai9rntduscz8tuksuljc9aqnx1hcetketfhhcuobuyrx1tde7ar"; http_uri; nocase; content:"asiiadinova.goosecreektradingpost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005972; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dropbx/mrrivfqsx0w56yjs2n12ktqjai9rntduscz8tuksuljc9aqnx1hcetketfhhcuobuyrx1tde7ar/"; http_uri; nocase; content:"asiiadinova.goosecreektradingpost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005973; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dropbx/zydqa2rp1pbhn5jfl8pcnq7rcox3i2ombnku03sbwoybgnquohbtmjtpe8mspvambxifeafwhez"; http_uri; nocase; content:"asiiadinova.goosecreektradingpost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005974; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dropbx/zydqa2rp1pbhn5jfl8pcnq7rcox3i2ombnku03sbwoybgnquohbtmjtpe8mspvambxifeafwhez/"; http_uri; nocase; content:"asiiadinova.goosecreektradingpost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005975; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?m=1"; http_uri; nocase; content:"assoalhosmadeiras.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005976; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/themes/twentyfifteen/cloud9/gucemail"; http_uri; nocase; content:"atagucsea.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005977; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/themes/twentyfifteen/cloud9/gucemail/"; http_uri; nocase; content:"atagucsea.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005978; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/themes/twentyfifteen/guce.advertising/8736443"; http_uri; nocase; content:"atagucsea.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005979; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/themes/twentyfifteen/guce.advertising/8736443/"; http_uri; nocase; content:"atagucsea.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005980; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/instalation/regionale-172-31-15-233-500/d3af68db02ed216ab18b26ea7ac7fe83/"; http_uri; nocase; content:"atefnet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005981; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/instalation/regionale-172-31-15-233-500/d3af68db02ed216ab18b26ea7ac7fe83/informations.php"; http_uri; nocase; content:"atefnet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005982; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/instalation/regionale-172-31-15-233-500/d3af68db02ed216ab18b26ea7ac7fe83/questions.php"; http_uri; nocase; content:"atefnet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005983; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/js/calendar/login/customer_center/customer-idpp00c699/"; http_uri; nocase; content:"atefnet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005984; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/js/calendar/login/customer_center/customer-idpp00c699/myaccount/signin"; http_uri; nocase; content:"atefnet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005985; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/js/calendar/login/customer_center/customer-idpp00c699/myaccount/signin/"; http_uri; nocase; content:"atefnet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005986; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/js/calendar/login/customer_center/customer-idpp00c699/myaccount/signin/?country.x=us&locale.x=en_us"; http_uri; nocase; content:"atefnet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005987; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/amalia_atmostechnology_co_uk/_layouts/15/wopiframe.aspx?guestaccesstoken=uiyaiqprc2ikxq0mezirqthais%2fdp9mp1hyqhjkscj0%3d&docid=1_1cbd4797f2749435a8f30af1a3f2d36b5&wdformid=%7b890161c9%2deb6d%2d44fc%2d9a59%2d0e4400a27203%7d&action=formsubmit"; http_uri; nocase; content:"atmostechnology-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005988; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/sue_atriumlandscape_com/_layouts/15/wopiframe.aspx?guestaccesstoken=f77ihhc%2fxkig6gfhqiddogtmjqoxm0%2fq%2bb2euyif%2bri%3d&docid=1_1c9c826e0945c4aae87a3cf1547b535ab&wdformid=%7b3565fd77%2dd37d%2d4ccf%2db660%2d25cb35a12799%7d&action=formsubmit"; http_uri; nocase; content:"atriumlandscape-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005989; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/sue_atriumlandscape_com/_layouts/15/wopiframe.aspx?guestaccesstoken=nrg8nkxnkyji2axm9efekdi62u6cuvrsxcypzfz9jay%3d&docid=1_10932d3dd2ac2478f833ee56388ecb767&wdformid=%7bfaebec1d%2dbc38%2d42bf%2dbe94%2d47ebb62d7501%7d&action=formsubmit"; http_uri; nocase; content:"atriumlandscape-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005990; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/sue_atriumlandscape_com/_layouts/15/wopiframe.aspx?guestaccesstoken=nrg8nkxnkyji2axm9efekdi62u6cuvrsxcypzfz9jay=&\;docid=1_10932d3dd2ac2478f833ee56388ecb767&\;wdformid={faebec1d-bc38-42bf-be94-47ebb62d7501}&\;action=formsubmit"; http_uri; nocase; content:"atriumlandscape-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005991; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/sue_atriumlandscape_com/_layouts/15/wopiframe.aspx?guestaccesstoken=f77ihhc%2fxkig6gfhqiddogtmjqoxm0%2fq%2bb2euyif%2bri%3d&docid=1_1c9c826e0945c4aae87a3cf1547b535ab&wdformid=%7b3565fd77%2dd37d%2d4ccf%2db660%2d25cb35a12799%7d&action=formsubmit&cid=f76562aa-9283-40ef-8ac9-15e5e7722d9b"; http_uri; nocase; content:"atriumlandscape-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005992; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/sue_atriumlandscape_com/_layouts/15/wopiframe.aspx?guestaccesstoken=nrg8nkxnkyji2axm9efekdi62u6cuvrsxcypzfz9jay%3d&docid=1_10932d3dd2ac2478f833ee56388ecb767&wdformid=%7bfaebec1d%2dbc38%2d42bf%2dbe94%2d47ebb62d7501%7d&action=formsubmit&cid=06548627-9647-42de-a0c7-75a424aaacde"; http_uri; nocase; content:"atriumlandscape-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005993; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/sue_atriumlandscape_com/_layouts/15/wopiframe.aspx?guestaccesstoken=nrg8nkxnkyji2axm9efekdi62u6cuvrsxcypzfz9jay=&\;docid=1_10932d3dd2ac2478f833ee56388ecb767&\;wdformid={faebec1d-bc38-42bf-be94-47ebb62d7501}&\;action=formsubmit&\;cid=06548627-9647-42de-a0c7-75a424aaacde"; http_uri; nocase; content:"atriumlandscape-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005994; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lloydsbank"; http_uri; nocase; content:"attemptdetectedpayment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005995; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/kramsey_auduboninstitute_org/evesqu6pzsxojjljb-ygjewbwb6dv_wn9ebmuzghm1jkbw?e=bcysta"; http_uri; nocase; content:"auduboninstitute-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005996; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"authorsationsetting-lloydsmanagement.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005997; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/access-token.php"; http_uri; nocase; content:"autolikesfree.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200005998; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?i_1"; http_uri; nocase; content:"avanzesegurita.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200005999; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/royalmail/secure.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"awaiting-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006000; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/royalmail/verifylogin.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"awaiting-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006001; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/peliculas"; http_uri; nocase; content:"awdescargas.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006002; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/citibank-bonuses"; http_uri; nocase; content:"bankcheckingsavings.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006003; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/citibank-bonuses/"; http_uri; nocase; content:"bankcheckingsavings.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006004; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/index.html"; http_uri; nocase; content:"baovesusonglcxt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006005; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/accounting_bluebridgefunding_com/_layouts/15/doc.aspx?sourcedoc={f0763374-6329-450f-94a4-11512ab3e2fe}&\;action=default&\;slrid=1cf04e9f-706e-0000-469d-3c7942c5beb8&\;originalpath=ahr0chm6ly9iymz1bmrpbmctbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvywnjb3vudgluz19ibhvlynjpzgdlznvuzgluz19jb20vrw5remr2qxbzdzlgbetrulvtcxo0djrcttnvrxnuvhjrm1fjae9qemetamxrqt9ydgltzt1ozy1mtmjqdjewzw&\;cid=81889f02-24c2-4efa-9e1e-1ccac075a22c"; http_uri; nocase; content:"bbfunding-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006006; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/accounting_bluebridgefunding_com/_layouts/15/doc.aspx?sourcedoc={f0763374-6329-450f-94a4-11512ab3e2fe}&\;action=default&\;slrid=3d693f9f-20ed-0000-3f04-fe0e8f6dfa87&\;originalpath=ahr0chm6ly9iymz1bmrpbmctbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvywnjb3vudgluz19ibhvlynjpzgdlznvuzgluz19jb20vrw5remr2qxbzdzlgbetrulvtcxo0djrcttnvrxnuvhjrm1fjae"; http_uri; nocase; content:"bbfunding-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006007; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/accounting_bluebridgefunding_com/_layouts/15/doc.aspx?sourcedoc={f0763374-6329-450f-94a4-11512ab3e2fe}&\;action=default&\;slrid=5961409f-c08a-0000-3fa1-75b979fb3192&\;originalpath=ahr0chm6ly9iymz1bmrpbmctbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvywnjb3vudgluz19ibhvlynjpzgdlznvuzgluz19jb20vrw5remr2qxbzdzlgbetrulvtcxo0djrcttnvrxnuvhjrm1fjae9qemetamxrqt9ydgltzt1yac0ycxkzttewzw&\;cid=c5f1ae7f-ac1c-4323-a07c-260e95800ab9"; http_uri; nocase; content:"bbfunding-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006008; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/accounting_bluebridgefunding_com/_layouts/15/doc.aspx?sourcedoc={f0763374-6329-450f-94a4-11512ab3e2fe}&\;action=default&\;slrid=59d2529f-d007-0000-3f10-e11b5cf398b3&\;originalpath=ahr0chm6ly9iymz1bmrpbmctbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvywnjb3vudgluz19ibhvlynjpzgdlznvuzgluz19jb20vrw5remr2qxbzdzlgbetrulvtcxo0djrcttnvrxnuvhjrm1fjae9qemetamxrqt9ydgltzt0zdnbfaxpqntewzw&\;cid=57281b4c-f8f3-415a-b048-b94ef5111d89"; http_uri; nocase; content:"bbfunding-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006009; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/accounting_bluebridgefunding_com/_layouts/15/doc.aspx?sourcedoc={f0763374-6329-450f-94a4-11512ab3e2fe}&\;action=default&\;slrid=62d2529f-7028-0000-3f04-f6b0a072a22a&\;originalpath=ahr0chm6ly9iymz1bmrpbmctbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvywnjb3vudgluz19ibhvlynjpzgdlznvuzgluz19jb20vrw5remr2qxbzdzlgbetrulvtcxo0djrcttnvrxnuvhjrm1fjae9qemetamxrqt9ydgltzt1jx3ktb1rqntewzw&\;cid=619fb8f1-b627-419b-80b1-cfd7e7cfa29b"; http_uri; nocase; content:"bbfunding-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006010; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/accounting_bluebridgefunding_com/_layouts/15/doc.aspx?sourcedoc={f0763374-6329-450f-94a4-11512ab3e2fe}&\;action=default&\;slrid=6744449f-f0b6-0000-3f10-e47497a0bdc8&\;originalpath=ahr0chm6ly9iymz1bmrpbmctbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvywnjb3vudgluz19ibhvlynjpzgdlznvuzgluz19jb20vrw5remr2qxbzdzlgbetrulvtcxo0djrcttnvrxnuvhjrm1fjae9qemetamxrqt9ydgltzt1jcuzuqwf2vjewzw&\;cid=06f20ebd-8518-4dfa-a8ce-3f796218604c"; http_uri; nocase; content:"bbfunding-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006011; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/accounting_bluebridgefunding_com/_layouts/15/doc.aspx?sourcedoc={f0763374-6329-450f-94a4-11512ab3e2fe}&\;action=default&\;slrid=7927489f-2081-0000-4704-eb1a7ea7761d&\;originalpath=ahr0chm6ly9iymz1bmrpbmctbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvywnjb3vudgluz19ibhvlynjpzgdlznvuzgluz19jb20vrw5remr2qxbzdzlgbetrulvtcxo0djrcttnvrxnuvhjrm1fjae9qemetamxrqt9ydgltzt0zeg04whlqzjewzw&\;cid=69a9adbf-9a76-4925-abca-a25903c1383e"; http_uri; nocase; content:"bbfunding-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006012; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/_layouts/15/wopiframe.aspx?guestaccesstoken=d96ydzq8vuilprdurtucov60qbtyz20222a95vav4da%3d&docid=1_1f81a6ca97d114a5f8e9829362518b16d&wdformid=%7b11b3b6fc%2d6e67%2d434d%2da029%2d3afe98d81a11%7d&action=formsubmit"; http_uri; nocase; content:"bdsfa.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006013; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/_layouts/15/wopiframe.aspx?guestaccesstoken=pbswcmyerrbau9nv%209vcodtblni2sahsdqci9c/qyr4=&\;docid=1_11dad9ed160d14dafa586323403d7fef8&\;wdformid={62e5338c-c4ba-43fd-ab98-d884748022e2}&\;action=formsubmit"; http_uri; nocase; content:"bdsfa.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006014; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/_layouts/15/wopiframe.aspx?guestaccesstoken=pbswcmyerrbau9nv%2b9vcodtblni2sahsdqci9c%2fqyr4%3d&docid=1_11dad9ed160d14dafa586323403d7fef8&wdformid=%7b62e5338c%2dc4ba%2d43fd%2dab98%2dd884748022e2%7d%2f&action=formsubmit"; http_uri; nocase; content:"bdsfa.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006015; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/_layouts/15/wopiframe.aspx?guestaccesstoken=pbswcmyerrbau9nv%2b9vcodtblni2sahsdqci9c%2fqyr4%3d&docid=1_11dad9ed160d14dafa586323403d7fef8&wdformid=%7b62e5338c%2dc4ba%2d43fd%2dab98%2dd884748022e2%7d&action=formsubmit"; http_uri; nocase; content:"bdsfa.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006016; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/goztepe/"; http_uri; nocase; content:"bekiroglunakliyat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006017; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/tfreeman_berry_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=gpjzqzx4udr gjomnqj9lcvwwiqvvwkiv5efan6aw1i=&\;docid=1_17c9d82461eb64869a103e0463529b21d&\;wdformid={628cee9e-90a4-41b1-9939-c804df4baf9a}&\;action=formsubmit"; http_uri; nocase; content:"berrycollege2-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006018; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/tfreeman_berry_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=gpjzqzx4udr%20gjomnqj9lcvwwiqvvwkiv5efan6aw1i=&\;docid=1_17c9d82461eb64869a103e0463529b21d&\;wdformid={628cee9e-90a4-41b1-9939-c804df4baf9a}&\;action=formsubmit"; http_uri; nocase; content:"berrycollege2-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006019; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/tfreeman_berry_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=gpjzqzx4udr%2bgjomnqj9lcvwwiqvvwkiv5efan6aw1i%3d&docid=1_17c9d82461eb64869a103e0463529b21d&wdformid=%7b628cee9e%2d90a4%2d41b1%2d9939%2dc804df4baf9a%7d&action=formsubmit"; http_uri; nocase; content:"berrycollege2-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006020; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"//"; http_uri; nocase; content:"betasus022.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006021; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/g/xx"; http_uri; nocase; content:"bioeurovit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006022; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/g/xx/"; http_uri; nocase; content:"bioeurovit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006023; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eventpubgmbile"; http_uri; nocase; content:"biolinky.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200006024; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/exodusmobile"; http_uri; nocase; content:"biolinky.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200006025; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/halloweeksevent"; http_uri; nocase; content:"biolinky.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200006026; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/legendarycontract"; http_uri; nocase; content:"biolinky.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200006027; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/m4glacier"; http_uri; nocase; content:"biolinky.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200006028; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/clubpubgmobile"; http_uri; nocase; content:"biolinky.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200006029; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmetro"; http_uri; nocase; content:"biolinky.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200006030; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/index.html?gcgdr@ewqa$zxfd*cgchjbjnhbgvfcdr*tcyvbuninhbygtfcrx"; http_uri; nocase; content:"bisonstburgersandbrews.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006031; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"//track-package"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006032; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bcefemxxreeglbi"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006033; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dhl-expres"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006034; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/en9net"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006035; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ff5sr"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006036; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ff9tn"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006037; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fg9w9"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006038; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fgday"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006039; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fgdbl"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006040; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fgmyy"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006041; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fhcyf"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006042; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fjxoo"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006043; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fl4er"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006044; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fl4ss"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006045; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fm3dy"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006046; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fp575"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006047; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hiosene"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006048; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hivos20b"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006049; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/huvis20b"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006050; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/microst-web-app15"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006051; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/outlookwebaccessupdate1"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006052; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/sac3004-1105"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006053; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/vt7eesyr5wfnwjncxgse?email=user@domain.com"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006054; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/web-sac-caixa"; http_uri; nocase; content:"bit.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006055; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2iz03nf"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006056; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2kduy2u"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006057; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2nog4ow?facebook_update"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006058; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2nwrbgj"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006059; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2ohlg0m"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006060; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2oq6dhz"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006061; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2p28z0h"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006062; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2pbi5mg"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006063; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2pmvqhh"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006064; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2q7fcpg"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006065; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2qgj1yj"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006066; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2wqlrea"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006067; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2yxmsxe"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006068; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2zaee65"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006069; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2zejaht"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006070; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/310p541"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006071; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/31cwtqd?facebook_update"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006072; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/31d3mp6?facebook_service"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006073; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/33ipjf7"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006074; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/34mhgdg"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006075; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/37r8zo3"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006076; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/37sfm2i"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006077; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/38a9umk"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006078; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/38fla6x"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006079; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/38xmo4d"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006080; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/392hszz"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006081; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/39tso26"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006082; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3afo6kx"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006083; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3an4lcn"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006084; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3aqvwmn"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006085; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3bje2js"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006086; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3bn5fpc"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006087; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3bsgkin"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006088; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3c2fsmi"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006089; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3c8oj6g"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006090; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3cvl6ir"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006091; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3d7ezub?facebook_update"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006092; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3dj0r1p"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006093; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3ejwrgv"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006094; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3ekdpzc"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006095; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3i8tjul"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006096; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3kplxza"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006097; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3kueruz"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006098; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3kxfgbu"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006099; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3ldovbh"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006100; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3lgmoqh"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006101; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3lyj971"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006102; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3mkihc9"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006103; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3mryk6q"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006104; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3mvzuye"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006105; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3nvr2mn"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006106; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3q1jbf6"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006107; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3reovvv"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006108; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3rtmiec"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006109; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3swpxho"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006110; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3tks2um"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006111; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3tzc89x"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006112; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3vvbwcv"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006113; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3w7o7fy"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006114; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3wb6m3i"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006115; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3wmwfrc"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006116; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3wx1unb"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006117; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/edoardopolaccoufficiale"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006118; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mr-pin"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006119; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/portale-mps-attivazione"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006120; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rbc975i"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006121; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/verifikasipemblokiran_id"; http_uri; nocase; content:"bit.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006122; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2ne0epo"; http_uri; nocase; content:"bitly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006123; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2p3bbbs"; http_uri; nocase; content:"bitly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006124; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/369t78f"; http_uri; nocase; content:"bitly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006125; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3aolo2y"; http_uri; nocase; content:"bitly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006126; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3koilft"; http_uri; nocase; content:"bitly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006127; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3p4hwwh"; http_uri; nocase; content:"bitly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006128; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3prjhpk"; http_uri; nocase; content:"bitly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006129; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wellsfargo/7d3d2656446d4c7fcb50725a0ed2e033/login.php"; http_uri; nocase; content:"blakeinsurancegroup.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006130; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/index2.html"; http_uri; nocase; content:"blandido.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006131; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/012dsd_fiestamart_com/_layouts/15/wopiframe.aspx?guestaccesstoken=t3v5ldmmhrtlw5cyiohlp9z4yo7ufnrop9j1plyfdkm%3d&docid=1_1d89d259f7e704301aca26ac4dbabaa8d&wdformid=%7bfeb771e5%2d93ee%2d4015%2d8e87%2dd1c30d0f406a%7d&action=formsubmit&cid=f609fe16-56c4-4e2b-a964-75e250d31c99"; http_uri; nocase; content:"bodegalatinacorp-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006132; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/012dsd_fiestamart_com/_layouts/15/wopiframe.aspx?guestaccesstoken=t3v5ldmmhrtlw5cyiohlp9z4yo7ufnrop9j1plyfdkm%3d&docid=1_1d89d259f7e704301aca26ac4dbabaa8d&wdformid=%7bfeb771e5%2d93ee%2d4015%2d8e87%2dd1c30d0f406a%7d&action=formsubmit&cid=f609fe16-56c4-4e2b-a964-75e250d31c99"; http_uri; nocase; content:"bodegalatinacorp-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006133; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/074mgr_fiestamart_com/_layouts/15/wopiframe.aspx?guestaccesstoken=3grgt23n7urwspwovyg%2fpgnclwfm%2fwm02msifjji33c%3d&docid=1_19b5c1e8433ba428ea23af4127d608ec4&wdformid=%7b7d1e10aa%2d4f8b%2d418e%2dad7e%2d65b1625b2140%7d&action=formsubmit"; http_uri; nocase; content:"bodegalatinacorp-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006134; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gr1qhuoedbxdz"; http_uri; nocase; content:"bom.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200006135; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/nlozan9lgoapq"; http_uri; nocase; content:"bom.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200006136; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rbobzzix0rrgy"; http_uri; nocase; content:"bom.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200006137; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/u7wgwg2vpfike"; http_uri; nocase; content:"bom.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200006138; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/xeqdubftucyzh"; http_uri; nocase; content:"bom.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200006139; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zsog9qbqjthup"; http_uri; nocase; content:"bom.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200006140; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/public/-/areaclient/"; http_uri; nocase; content:"bombogadget.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006141; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?aplicar"; http_uri; nocase; content:"bonomequedoencasa.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006142; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/rbennett_bowmanconsulting_com/_layouts/15/onedrive.aspx?id=/personal/rbennett_bowmanconsulting_com/documents/attachments/3/parcel209_fundsrequisition(rev).pdf&\;parent=/personal/rbennett_bowmanconsulting_com/documents/attachments/3&\;cid=3cd8dcbb-0e98-40c4-803e-02e9139b0130"; http_uri; nocase; content:"bowmanconsultinggroup-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006143; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/rbennett_bowmanconsulting_com/_layouts/15/onedrive.aspx?id=/personal/rbennett_bowmanconsulting_com/documents/attachments/3/parcel209_fundsrequisition(rev).pdf&\;parent=/personal/rbennett_bowmanconsulting_com/documents/attachments/3&\;cid=821bbc7d-47b9-43c4-b158-eb4f8a6a6eb2"; http_uri; nocase; content:"bowmanconsultinggroup-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006144; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/rbennett_bowmanconsulting_com/_layouts/15/onedrive.aspx?id=/personal/rbennett_bowmanconsulting_com/documents/attachments/3/parcel209_fundsrequisition(rev).pdf&\;parent=/personal/rbennett_bowmanconsulting_com/documents/attachments/3&\;originalpath=ahr0chm6ly9ib3dtyw5jb25zdwx0aw5nz3jvdxatbxkuc2hhcmvwb2ludc5jb20vomi6l2cvcgvyc29uywwvcmjlbm5ldhrfym93bwfuy29uc3vsdgluz19jb20vrvzuzhrfsdfjvtfmb3l5qlpkdi0wbffcuxrowec5rgu3rkhnu01cmfv0bzv2dz9ydgltzt1qve9itvhevtewzw"; http_uri; nocase; content:"bowmanconsultinggroup-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006145; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/rbennett_bowmanconsulting_com/_layouts/15/onedrive.aspx?id=/personal/rbennett_bowmanconsulting_com/documents/attachments/3/parcel209_fundsrequisition(rev).pdf&\;parent=/personal/rbennett_bowmanconsulting_com/documents/attachments/3&\;originalpath=ahr0chm6ly9ib3dtyw5jb25zdwx0aw5nz3jvdxatbxkuc2hhcmvwb2ludc5jb20vomi6l2cvcgvyc29uywwvcmjlbm5ldhrfym93bwfuy29uc3vsdgluz19jb20vrvzuzhrfsdfjvtfmb3l5qlpkdi0wbffcuxrowec5rgu3rkhnu01cmfv0bzv2dz9ydgltzt1ub3u1mfuwtjjfzw"; http_uri; nocase; content:"bowmanconsultinggroup-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006146; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"//#abuse@ionos.com"; http_uri; nocase; content:"bqqxpdkanoyeyuox-dot-bunta-opla.ue.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006147; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/r_bouman_bravobeveiliging_nl/eiafjbddqltcmdxxrdbajdsbhfr37kusmucacmgoxitraa?e=drnrdm"; http_uri; nocase; content:"bravobeveiliging-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006148; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/r_bouman_bravobeveiliging_nl/_layouts/15/doc.aspx?sourcedoc={b08d0520-a8dd-42bb-9835-d7443040243b}&\;action=default&\;slrid=1bef3f9f-6078-2000-b22e-969d6b1087ac&\;originalpath=ahr0chm6ly9icmf2b2jldmvpbglnaw5nlw15lnnoyxjlcg9pbnquy29tlzpvoi9nl3blcnnvbmfsl3jfym91bwfux2jyyxzvymv2zwlsawdpbmdfbmwvrwlbrmpirgrxthrdburywfjeqkfkrhncagzsmzdlvxnnvunhy01nt3hjvfjhqt9ydgltzt02wvjzd2hitdewzw&\;cid=fa76d1ab-0178-4af6-9277-2f7cec72f87f"; http_uri; nocase; content:"bravobeveiliging-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006149; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/r_bouman_bravobeveiliging_nl/_layouts/15/doc.aspx?sourcedoc={b08d0520-a8dd-42bb-9835-d7443040243b}&\;action=default&\;slrid=6da4499f-90c1-1000-2cd9-635a73663bb2&\;originalpath=ahr0chm6ly9icmf2b2jldmvpbglnaw5nlw15lnnoyxjlcg9pbnquy29tlzpvoi9nl3blcnnvbmfsl3jfym91bwfux2jyyxzvymv2zwlsawdpbmdfbmwvrwlbrmpirgrxthrdburywfjeqkfkrhncagzsmzdlvxnnvunhy01nt3hjvfjhqt9ydgltzt1obevty01yatewzw&\;cid=69b5ce36-07cd-492f-bbb2-469847146292"; http_uri; nocase; content:"bravobeveiliging-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006150; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/r_bouman_bravobeveiliging_nl/_layouts/15/doc.aspx?sourcedoc={b08d0520-a8dd-42bb-9835-d7443040243b}&\;action=default&\;slrid=8cda429f-002e-2000-286c-d631557a1a52&\;originalpath=ahr0chm6ly9icmf2b2jldmvpbglnaw5nlw15lnnoyxjlcg9pbnquy29tlzpvoi9nl3blcnnvbmfsl3jfym91bwfux2jyyxzvymv2zwlsawdpbmdfbmwvrwlbrmpirgrxthrdburywfjeqkfkrhncagzsmzdlvxnnvunhy01nt3hjvfjhqt9ydgltzt0tckpwa0rmuzewzw&\;cid=23ce5c18-dd3c-4739-8673-ca39efd1bbee"; http_uri; nocase; content:"bravobeveiliging-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006151; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/r_bouman_bravobeveiliging_nl/_layouts/15/doc.aspx?sourcedoc={b08d0520-a8dd-42bb-9835-d7443040243b}&\;action=default&\;slrid=970f5c9f-603c-1000-27b6-96f2f0a5205c&\;originalpath=ahr0chm6ly9icmf2b2jldmvpbglnaw5nlw15lnnoyxjlcg9pbnquy29tlzpvoi9nl3blcnnvbmfsl3jfym91bwfux2jyyxzvymv2zwlsawdpbmdfbmwvrwlbrmpirgrxthrdburywfjeqkfkrhncagzsmzdlvxnnvunhy01nt3hjvfjhqt9ydgltzt1oa05tru1judjfzw&\;cid=8b514f7f-072b-4d49-87f3-f1ff2f7c26f7"; http_uri; nocase; content:"bravobeveiliging-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006152; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/upload/"; http_uri; nocase; content:"brersont.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006153; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/mkhunt_bridgewaterma_org/_layouts/15/wopiframe.aspx?guestaccesstoken=qhrrwxcv%2fa2j8c%2fukg2hcmebzjijcu25gjll3su0xl0%3d&\;docid=1_16e44d08a60144801bbfe65418a14c35f&\;wdformid=%7b40dfd724%2db9a0%2d4f06%2d934b%2d85e6c322e875%7d&\;action=formsubmit"; http_uri; nocase; content:"bridgewaterma-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006154; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/mkhunt_bridgewaterma_org/_layouts/15/wopiframe.aspx?guestaccesstoken=/xnniui8cbcaalna0dt7bvzueqrakfgntkhwho5/z2k=&\;docid=1_16402b4f119204432b5a25eea9ef2a029&\;wdformid={154f97ef-3518-47f6-97a6-e96e783894e8}&\;action=formsubmit&\;cid=7e4a2819-73c1-4fca-9921-c9b62a19bd37"; http_uri; nocase; content:"bridgewaterma-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006155; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/login.globalsources.com/sso/generalmanager.php"; http_uri; nocase; content:"britainwestmotorsport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006156; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.html"; http_uri; nocase; content:"brooksoutlet.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200006157; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/build/mywebsites.aspx"; http_uri; nocase; content:"btck.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200006158; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.aspx?returnurl=/build/mywebsites.aspx"; http_uri; nocase; content:"btck.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200006159; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/c9i9xixx9yf5.html"; http_uri; nocase; content:"c9i9xixx9yf5.storage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006160; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/nationwide"; http_uri; nocase; content:"cancelpaymentonlinelogin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006161; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/nationwide/login.php"; http_uri; nocase; content:"cancelpaymentonlinelogin.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006162; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/assets/js/us/delta.com/index.php"; http_uri; nocase; content:"capilart.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200006163; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/helen_carnegieproperty_com/_layouts/15/wopiframe.aspx?guestaccesstoken=i93ri6e azsglandv8xwijahnamcfopa87otqqw4lly=&\;docid=1_18f09536ac24d4b6c9bd785b3d27746bc&\;wdformid={59ac2fc4-0767-42b6-a127-cc529a92b57e}&\;action=formsubmit"; http_uri; nocase; content:"carnegieproperty-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006164; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/helen_carnegieproperty_com/_layouts/15/wopiframe.aspx?guestaccesstoken=i93ri6e+azsglandv8xwijahnamcfopa87otqqw4lly=&\;docid=1_18f09536ac24d4b6c9bd785b3d27746bc&\;wdformid={59ac2fc4-0767-42b6-a127-cc529a92b57e}&\;action=formsubmit"; http_uri; nocase; content:"carnegieproperty-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006165; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/iogin.srfwa=wsignin10&\;rpsnv=13&\;ct=1598492685&\;rver=7067370&\;wp=mbi_ssl&\;wreply=httpsa2f2foutlooklivecom2fowa2f3fnlp3d126rpscsrfstate3d7ba2915c-d728-8d5a-9a51-5ead52784b37&\;id=41&\;aadredir=&\;cbcxt=out&\;lw=1&\;fl=dob2cflname2cwld&\;cobrandid=caso980321423x/cargando....html?i=1"; http_uri; nocase; content:"caso980321423x.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006166; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/iogin.srfwa=wsignin10&\;rpsnv=13&\;ct=1598492685&\;rver=7067370&\;wp=mbi_ssl&\;wreply=httpsa2f2foutlooklivecom2fowa2f3fnlp3d126rpscsrfstate3d7ba2915c-d728-8d5a-9a51-5ead52784b37&\;id=41&\;aadredir=&\;cbcxt=out&\;lw=1&\;fl=dob2cflname2cwld&\;cobrandid=caso980321423x/inicio.html"; http_uri; nocase; content:"caso980321423x.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006167; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/iogin.srfwa=wsignin10&\;rpsnv=13&\;ct=1598492685&\;rver=7067370&\;wp=mbi_ssl&\;wreply=httpsa2f2foutlooklivecom2fowa2f3fnlp3d126rpscsrfstate3d7ba2915c-d728-8d5a-9a51-5ead52784b37&\;id=41&\;aadredir=&\;cbcxt=out&\;lw=1&\;fl=dob2cflname2cwld&\;cobrandid=caso980321423x/inicio2.html"; http_uri; nocase; content:"caso980321423x.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006168; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/acastillo_castillohousing_com/_layouts/15/wopiframe.aspx"; http_uri; nocase; content:"castillohousing-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006169; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/b/-6fsywpzv0u0rstwnn2f7q?fid=180&hl_qs=4ly0jkaam70qgsf5dzytries7zmblqdnx7hib1siswlpfqxqcbt7mv2u7jgnwn6ac/nh5skijrn4wimno3znkp1v%20lpe5gbu58z3ygphrdhhzlbbswrmmidsns65hs2w4rsw8mf4huarnryh4hnuwinf1op3cvrs6xyfbrrne5ussnefw6hyqfz8gwqot9xusuce8vuhdxuvbruajubxppf4nettscj0w70qftem1mdpvmvrdvyyqrqd0emkus075idx30fzpqxcq7rj%20yrbsnnhf2wpeageca45bv%20v/ky=&ev=2&action=click&impressionpid=a0274737-90cc-4e64-9b93-818106ad9435&rn=627706495&dest=arancadi.bassiica.be"; http_uri; nocase; content:"cat.criteo.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006170; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/mariam_cciottawa_ca/_layouts/15/wopiframe.aspx?guestaccesstoken=ajn%2bclx8sn3dvninwzwtki88x1ysagpfqc0suqn4qui%3d&docid=1_15993ec557a6249418cf4deddf0aade39&wdformid=%7b727df2e9%2d0051%2d4601%2d84fc%2d40eff41d7eaf%7d&action=formsubmit"; http_uri; nocase; content:"cciottawa050-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006171; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/home_paie/zigzag.php/"; http_uri; nocase; content:"cddtbpost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006172; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s/files/1/0533/5367/6992/t/3/assets/home.html"; http_uri; nocase; content:"cdn.shopify.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006173; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/static/img/v1/newui/ph/general/1563911645084_183643882.html"; http_uri; nocase; content:"cdn.via.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006174; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/rnewcomer_centerstreetlending_com/_layouts/15/wopiframe.aspx?guestaccesstoken=j%2f9wodhj7u8077urui6lxbx%2b9vwlzr11ry0pztfyrwq%3d&docid=1_1fabe326fc77a4441995d0cc407c8c49c&wdformid=%7b56d05c68%2d7055%2d4573%2db79b%2df286b64f5853%7d&action=formsubmit"; http_uri; nocase; content:"centerstlending-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006175; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/basic.php?k=4fa9db0267dbfa61c8978ff8809f6b071f02c997&\;viewed=1"; http_uri; nocase; content:"chaisalert.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006176; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2020/07/repondrechronopost.html"; http_uri; nocase; content:"chronopostfrlivraison8.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006177; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2021/02/blog-post_12.html"; http_uri; nocase; content:"chronopostvalidation.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006178; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/eric_cimsltd_com/_layouts/15/wopiframe.aspx?guestaccesstoken=wnhqsp58ikn1qzzozpe2oiw%2fmizdr53wegdbyscml7y%3d&\;docid=1_1207bcf2f71094b5cb97dcb5bea3e1a3a&\;wdformid=%7bd98de46a%2d2777%2d417f%2dbbcf%2d5f08c8244727%7d&\;action=formsubmit"; http_uri; nocase; content:"cimslp-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006179; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/mkphenicie_bcps_k12_md_us/_layouts/15/wopiframe.aspx?guestaccesstoken=8mqz0pbaequkjg%2bwcpnqtgwrswdh4azr%2bsinor8cw8m%3d&docid=1_1058175d7d73f4b39bb114b0dd340d168&wdformid=%7b1fd2a3e2%2d7ce8%2d4700%2db944%2d171b6be0cea6%7d&action=formsubmit"; http_uri; nocase; content:"cityschools2013-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006180; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/jjkkii"; http_uri; nocase; content:"clayheart.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006181; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/jjkkii/"; http_uri; nocase; content:"clayheart.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006182; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pjhdg"; http_uri; nocase; content:"clck.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200006183; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?qs=9cf30363dd29315c3e11be7b9f86e0023a565c20a2375038e17cde83e3918d351e9c862894eecd698e1a9bb86157937bcf1b994ad1bf797a"; http_uri; nocase; content:"click.email.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006184; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?qs=db04a8b2d7b04d1f6b3c69c4c5805dfc93097e61c800b87bab9654d4ce1ee7f86c05b36196ea1c673c13d490edbadd368c6e8f39eb68b3bb"; http_uri; nocase; content:"click.mail.onedrive.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006185; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/owa"; http_uri; nocase; content:"clickent.co.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200006186; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/owa/"; http_uri; nocase; content:"clickent.co.jp"; content:"Host"; http_header; classtype:attempted-recon; sid:200006187; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/object/html_elements/laxx/en.php"; http_uri; nocase; content:"cnam.md"; content:"Host"; http_header; classtype:attempted-recon; sid:200006188; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/object/html_elements/laxx/en.php?rand=13inboxlightaspxn.1774256418&\;fid.4.1252899642&\;fid=1&\;fav.1&\;rand.13inboxlight.aspxn.1774256418&\;fid.1252899642&\;fid.1&\;fav.1&\;email=umf5lmlvenpvqhdlbgxzzmfyz29hzhzpc29ycy5jb20=&\;.rand=13inboxlight.aspx?n=1774256418&\;fid=4"; http_uri; nocase; content:"cnam.md"; content:"Host"; http_header; classtype:attempted-recon; sid:200006189; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/mfiorini_coastappliances_com/ekgio42ixgvmrgruj7hsx1sbuji-eqg6t2m9bxmcb9latw?e=4smg"; http_uri; nocase; content:"coastwholesaleappliances-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006190; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/d/microsoft-office365_duu9pzwq-rk"; http_uri; nocase; content:"coda.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200006191; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/files/225449569/featured.jpg?auto=compress%2cformat&\;q=80&\;fit=crop&\;crop=top&\;max-h=8000&\;max-w=590&\;s=632b2d2d56d2e639f1e656fae62ffd17"; http_uri; nocase; content:"codecanyon.img.customer.envatousercontent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006192; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/kristin_collinsfamilylaw_com/euf0wztyhj9kqzxuzlzixyabi4yll8ikkpy9hzw5mqnk3w?e=l7oitq"; http_uri; nocase; content:"collinsflg-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006193; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/agerzen_cpsk12_org/_layouts/15/wopiframe.aspx?guestaccesstoken=usnbe6ybjho9h25fk68jtyi54ok8%2b9ellr1aq%2fst9k8%3d&docid=1_1b3a9c7812c9d4683b1b5cc7fc8ae677d&wdformid=%7bf32b5748%2d8761%2d4d74%2db73e%2d295011a92875%7d&action=formsubmit&cid=84c7b00e-f"; http_uri; nocase; content:"columbiaps-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006194; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/agerzen_cpsk12_org/_layouts/15/wopiframe.aspx?guestaccesstoken=usnbe6ybjho9h25fk68jtyi54ok8%2b9ellr1aq%2fst9k8%3d&docid=1_1b3a9c7812c9d4683b1b5cc7fc8ae677d&wdformid=%7bf32b5748%2d8761%2d4d74%2db73e%2d295011a92875%7d&action=formsubmit&cid=84c7b00e-fca9-46c9-b4f6-6c3148ca22a4"; http_uri; nocase; content:"columbiaps-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006195; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/agerzen_cpsk12_org/_layouts/15/wopiframe.aspx?guestaccesstoken=usnbe6ybjho9h25fk68jtyi54ok8%2b9ellr1aq%2fst9k8%3d&docid=1_1b3a9c7812c9d4683b1b5cc7fc8ae677d&wdformid=%7bf32b5748%2d8761%2d4d74%2db73e%2d295011a92875%7d&action=formsubmit&cid=84c7b00e-f"; http_uri; nocase; content:"columbiaps-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006196; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/agerzen_cpsk12_org/_layouts/15/wopiframe.aspx?guestaccesstoken=usnbe6ybjho9h25fk68jtyi54ok8%2b9ellr1aq%2fst9k8%3d&docid=1_1b3a9c7812c9d4683b1b5cc7fc8ae677d&wdformid=%7bf32b5748%2d8761%2d4d74%2db73e%2d295011a92875%7d&action=formsubmit&cid=84c7b00e-fca9-46c9-b4f6-6c3148ca22a4"; http_uri; nocase; content:"columbiaps-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006197; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/nicky_tolley_communicourt_co_uk/_layouts/15/wopiframe.aspx?guestaccesstoken=eamfa28gqrgeiwgts4k6r4jeaw5r3nlvgmrujrqweeg%3d&docid=1_102ac4f4a82ef483da9397726d75865ca&wdformid=%7b6fc04434%2d1bec%2d4c45%2dbfde%2d62f16b91c9eb%7d&action=formsubmit&cid=5964b08a-e45b-4bd6-a4e5-d13338c37e65"; http_uri; nocase; content:"communicourt-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006198; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lloyds"; http_uri; nocase; content:"confirmnew-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006199; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/smartlistings/docusign/index.html"; http_uri; nocase; content:"cornersmascout.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006200; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/js/euro2.safelinks.protection.btinternet.com/voicemail/"; http_uri; nocase; content:"cortijolatapia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006201; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mailbox_validation_required/xchan_owa/?lo=zmluyw5jawfsaw5zdgl0dxrpb25zqgfrdglmymfuay5jb20udhi="; http_uri; nocase; content:"counselspirit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006202; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mailbox_validation_required/xchan_owa?lo=zmluyw5jawfsaw5zdgl0dxrpb25zqgfrdglmymfuay5jb20udhi="; http_uri; nocase; content:"counselspirit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006203; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/js/crop/cm"; http_uri; nocase; content:"createchsoft.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006204; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/js/crop/cm/"; http_uri; nocase; content:"createchsoft.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006205; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/network/acct/login.php"; http_uri; nocase; content:"creativecombat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006206; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/network/acct/login.php?.rand=13inboxlight.aspx?n=1774256418"; http_uri; nocase; content:"creativecombat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006207; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/network/acct/login.php?.rand=13inboxlight.aspx?n=1774256418&\;email=jackdavis@eureliosollutions.com&\;fid=1&\;fid=4&\;rand=13inboxlightaspxn.1774256418"; http_uri; nocase; content:"creativecombat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006208; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/network/acct/login.php?rand=13inboxlightaspxn.1774256418"; http_uri; nocase; content:"creativecombat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006209; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/network/acct/login.php?rand=13inboxlightaspxn.1774256418&\;"; http_uri; nocase; content:"creativecombat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006210; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/network/acct/login.php?rand=13inboxlightaspxn.1774256418&\;amp"; http_uri; nocase; content:"creativecombat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006211; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/network/acct/login.php?rand=13inboxlightaspxn.1774256418&\;amp\;ampopensource:observable-35835700-0d08-4c25-a188-b8312ba00a941067515"; http_uri; nocase; content:"creativecombat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006212; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/network/acct/login.php?rand=13inboxlightaspxn.1774256418&\;ampopensource:observable-35835700-0d08-4c25-a188-b8312ba00a941067515"; http_uri; nocase; content:"creativecombat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006213; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/network/acct/login.php?rand=13inboxlightaspxn.1774256418&\;fid.4.1252899642&\;fid=1&\;fav.1&\;rand.13inboxlight.aspxn.1774256418&\;fid.1252899642&\;fid.1&\;fav.1&\;email=&\;.rand=13inboxlight.aspx?n=1774256418&\;fid=4"; http_uri; nocase; content:"creativecombat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006214; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/network/acct/login.php?rand=13inboxlightaspxn.1774256418&\;fid.4.1252899642&\;fid=1&\;fav.1&\;rand.13inboxlight.aspxn.1774256418&\;fid.1252899642&\;fid.1&\;fav.1&\;email=jsmith@imaphost.com&\;.rand=13inboxlight.aspx?n=1774256418&\;fid=4"; http_uri; nocase; content:"creativecombat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006215; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/network/acct/login.php?rand=13inboxlightaspxn.1774256418&\;fid.4.1252899642&\;fid=4&\;fav.1&\;rand.13inboxlight.aspxn.1774256418&\;fid.1252899642&\;fid.1&\;email=jsmith@imaphost.com&\;.rand=13inboxlight.aspx?n=1774256418"; http_uri; nocase; content:"creativecombat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006216; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/network/acct/login.php?rand=13inboxlightaspxn.1774256418&fid.4.1252899642&fid=1&fav.1&rand.13inboxlight.aspxn.1774256418&fid.1252899642&fid.1&fav.1&email=jackdavis@eureliosollutions.com&.rand=13inboxlight.aspx?n=1774256418&fid=4"; http_uri; nocase; content:"creativecombat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006217; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/network/acct?email=jackdavis@eureliosollutions.com"; http_uri; nocase; content:"creativecombat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006218; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2011/02/habbo-crediti-gratis-sicuro-100.html"; http_uri; nocase; content:"creditiperhabbogratissicuro100.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006219; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/monica_crewscontrol_com/etsaeagbpbjbtwzh2tom1c4b-dgni3j2covr9b9jmky9na?e=7pz8vh"; http_uri; nocase; content:"crewscontrolmd-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006220; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/efawcett_crowleprimaryacademy_co_uk/_layouts/15/wopiframe.aspx?guestaccesstoken=pqjo%2b1du2x7gkpnwpj%2fpxrjb27yisjvjg%2fulmjfwpic%3d&docid=1_1a33d81e097f84f22a3ea2b3bdbe4bc3b&wdformid=%7b6c0f5018%2d9905%2d4c88%2d8e5e%2dc7b0bd411941%7d&action=formsubmit"; http_uri; nocase; content:"crowleprimary-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006221; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/efawcett_crowleprimaryacademy_co_uk/_layouts/15/wopiframe.aspx?guestaccesstoken=pqjo%2b1du2x7gkpnwpj%2fpxrjb27yisjvjg%2fulmjfwpic%3d&docid=1_1a33d81e097f84f22a3ea2b3bdbe4bc3b&wdformid=%7b6c0f5018-9905-4c88-8e5e-c7b0bd411941%7d&action=formsubmit&cid=d2ade5d4-a3d0-473a-b4f2-48fbbd37b450"; http_uri; nocase; content:"crowleprimary-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006222; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/michael_hammes_cteam_de/emvsa57h96dfn3pdorq6h9qbfjioxaqwsf3sn9gvu8tkzq?e=nvhbcy"; http_uri; nocase; content:"cteam-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006223; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/katie_higgins10_myhunter_cuny_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=x3sh4rrhfwiw8xu7klxkfkcjmabw3tf1t9zsf0ih3wu%3d&docid=1_1712dfa7447ed4258967f98253eab9afe&wdformid=%7b31b100cb%2db37a%2d4782%2d93ca%2d6e1136741ed8%7d&action=formsubmit"; http_uri; nocase; content:"cuny620-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006224; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/katie_higgins10_myhunter_cuny_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=x3sh4rrhfwiw8xu7klxkfkcjmabw3tf1t9zsf0ih3wu%3d&docid=1_1712dfa7447ed4258967f98253eab9afe&wdformid=%7b31b100cb%2db37a%2d4782%2d93ca%2d6e1136741ed8%7d&action=formsubmit&cid=d040c867-57be-47ca-a00d-7eee6d619875"; http_uri; nocase; content:"cuny620-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006225; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?m=0"; http_uri; nocase; content:"cusstomerservicee.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006226; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/7cdecaj"; http_uri; nocase; content:"cutt.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006227; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/8cmps8d"; http_uri; nocase; content:"cutt.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006228; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dkvkq49"; http_uri; nocase; content:"cutt.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006229; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dkvkq49/"; http_uri; nocase; content:"cutt.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006230; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ee-online-customer-reset"; http_uri; nocase; content:"cutt.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006231; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eklixfr"; http_uri; nocase; content:"cutt.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006232; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kkk8mtw"; http_uri; nocase; content:"cutt.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006233; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/laposte-colis"; http_uri; nocase; content:"cutt.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006234; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rcnfdfa"; http_uri; nocase; content:"cutt.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006235; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/reactiva-viabcponline"; http_uri; nocase; content:"cutt.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006236; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rkkrjxy/"; http_uri; nocase; content:"cutt.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006237; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rxudyrb"; http_uri; nocase; content:"cutt.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006238; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wchn5mq/"; http_uri; nocase; content:"cutt.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006239; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/xkxn2e1"; http_uri; nocase; content:"cutt.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006240; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/9wnkq"; http_uri; nocase; content:"cutt.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200006241; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jxqgq"; http_uri; nocase; content:"cutt.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200006242; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/msf1o?page-support"; http_uri; nocase; content:"cutt.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200006243; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/x41cc"; http_uri; nocase; content:"cutt.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200006244; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/f/j8j50t"; http_uri; nocase; content:"d.pr"; content:"Host"; http_header; classtype:attempted-recon; sid:200006245; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jiiayu?updateverify="; http_uri; nocase; content:"d.pr"; content:"Host"; http_header; classtype:attempted-recon; sid:200006246; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/amazon/#1616589828133"; http_uri; nocase; content:"d5-amazon.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200006247; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/network/www.t-online.de.html"; http_uri; nocase; content:"dailynewsvermont.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006248; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/access/index/wellsfargo/wells"; http_uri; nocase; content:"dakartransittransport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006249; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/access/index/wellsfargo/wells/"; http_uri; nocase; content:"dakartransittransport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006250; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/remboursement/"; http_uri; nocase; content:"danangxaydung.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006251; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/remboursement/04983522f756e8bf019193a0910bffab/?security=1qbx7holnntabiwdoj40icoja4v5pmzqblmirl3e8wokdjmc2q&email="; http_uri; nocase; content:"danangxaydung.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006252; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/update-account-secure"; http_uri; nocase; content:"darinsoat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006253; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/update-account-secure/"; http_uri; nocase; content:"darinsoat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006254; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/update-account-secure/015af42f710d3d75e4f7d78b32af9198/?dispatch=gysyxa9a27p9dmok60vswdj0sdwgedbq1qzrh1uqgpxsf23zfz&email="; http_uri; nocase; content:"darinsoat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006255; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/update-account-secure/8d72cd5c23ee6e45919f91a2417e19f4/?dispatch=igm0nrbfgz88gop3buwlptnwwvfzs1umgvptel2ywkdrqctfeg&\;email="; http_uri; nocase; content:"darinsoat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006256; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/update-account-secure/b73e7476d9137e6c6141059302492962?dispatch=skgvhqwbpp6s0yrga9qnvshqden8zmrytjxvcfhwh71f2mqf7q&\;email="; http_uri; nocase; content:"darinsoat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006257; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/update-account-secure/f155ac425ae448c9b5fe213abbd5de8b?dispatch=ohqzbcccskveub7jrsnnjudsd2ciazilnor0kavvmzj9hnaj7z&\;email="; http_uri; nocase; content:"darinsoat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006258; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dcw/posttourl.do?aid=549&url=https://bitly.com/3qhxr7p"; http_uri; nocase; content:"dcq.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200006259; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"declined-myaccount.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006260; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/royalmail/"; http_uri; nocase; content:"delivery-cost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006261; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/royalmail/secure.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"delivery-cost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006262; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/royalmail/user.php?&sessionid=f01f18eaec89816094bc3868f662d236&securessl=true"; http_uri; nocase; content:"delivery-cost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006263; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/royalmail/verifylogin.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"delivery-cost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006264; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/assets/vendor/icheck/square/cli/shop/includes/content/common/goto"; http_uri; nocase; content:"devbasicsoft.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006265; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/assets/vendor/icheck/square/cli/shop/includes/content/common/goto/"; http_uri; nocase; content:"devbasicsoft.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006266; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/assets/vendor/icheck/square/cli/shop/includes/content/common/goto/full.php"; http_uri; nocase; content:"devbasicsoft.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006267; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/assets/vendor/icheck/square/cli/shop/includes/content/common/goto/fulls.php"; http_uri; nocase; content:"devbasicsoft.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006268; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/assets/vendor/icheck/square/cli/shop/includes/content/common/goto/que.php"; http_uri; nocase; content:"devbasicsoft.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006269; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/okay/true/"; http_uri; nocase; content:"dfcsport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006270; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ellyn.html"; http_uri; nocase; content:"dgsols.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006271; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/home/components/com_user/bbtonline.html"; http_uri; nocase; content:"dichvuvnpt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006272; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/khi/daum/daaum/"; http_uri; nocase; content:"dipelnet.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200006273; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/khi/daum/daaum/login.php?cmd=login_submit&id=4f256653c22f8d03fa319b5f5ea1a33f4f256653c22f8d03fa319b5f5ea1a33f&session=4f256653c22f8d03fa319b5f5ea1a33f4f256653c22f8d03fa319b5f5ea1a33f"; http_uri; nocase; content:"dipelnet.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200006274; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/khi/daum/daaum/login.php?cmd=login_submit&id=6076928ad7f4955369e2a09ff95e6ad56076928ad7f4955369e2a09ff95e6ad5&session=6076928ad7f4955369e2a09ff95e6ad56076928ad7f4955369e2a09ff95e6ad5"; http_uri; nocase; content:"dipelnet.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200006275; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?url=http%3a%2f%2fv32vi.org%2fobj%2fx86%2fdebug%2fdebug.html&key=p5-unr13ef1nvpweoa4g6q"; http_uri; nocase; content:"disq.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200006276; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?url=http%3a%2f%2fwww.rmiembassyus.org%2fmedia%2fjui%2fjs%2f&key=i5eldkzvfyplzuuvh2xytg"; http_uri; nocase; content:"disq.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200006277; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?url=https%3a%2f%2fcompte-suspendu483.tk%2fcaptcha%2f&key=uouejqmfvkrmu_mnfmlqeg"; http_uri; nocase; content:"disq.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200006278; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?url=https%3a%2f%2fwww.adelaidetowingandcarremoval.com.au%2fwp-content%2f%2fuploads%2f2020%2fsocialsecurity%2f&\;key=yxyb8swn1zzjw8bcatgrjw######"; http_uri; nocase; content:"disq.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200006279; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?url=https%3a%2f%2fwww.gepard.ru%2flogin%2faccount%2f&key=jgdq7zs0ratd6src39cdig"; http_uri; nocase; content:"disq.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200006280; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ad/dhl.13.0.1/source/verify.php?email=ay.dios@mio.com"; http_uri; nocase; content:"distantinvestment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006281; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vqg5zz0tcdbhy7wfp_7qji6toegexolsgvf_176vf5srqdch5yoc7vqg92mmiz7yvesvbgmzvlagowo/pub"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006282; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vrsdmi8kqzhphmq1wq1it08vreztms3u-vsojet5ppl9zuo4ismcqxn4fwtissr-h0txmmzaohvs7ty/pub"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006283; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vrww694tkdqcdswba6r6qvkl2j8ggccuxtq-1x4ocowjttilaenattbakijulc7qev-4hqllutzogev/pub"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006284; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vs36y8r0dzpmbkk0kzlhwl7qp56-1x6jrq34lzp4a2cukpsl9y0gfpcpmx8sjlwiw2db5lysyzisg8o/pub"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006285; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vt_xl-m0ff8yqqhzhgseahgwejo0znh9re6w0qvgbe0qfe084hrebjjg673htphdnvbcdnq6agehncq/pub?mobilelogin"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006286; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vtj_-ldjfuxvxsbw2yivttmklhhwb0xalrxb_sxzub7mvm23nxxvor35_ppdltnvlm7bo8pc5oao0jn/pub"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006287; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vtlwgeeksjh9punn3qeb-g2-tyrz0vvkpjsh5lfovukecuw6wqcn11bmskuctg9x4ejnlr3ovcdgd24/pub"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006288; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/document/d/e/2pacx-1vts9czxqycsgi-quifs7m1mqjzmlcjlccnhw3dsahdss5ymnpy6y0vsgwvf3piu6js22ydjyew1oyo_/pub?embedded=true"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006289; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/document/u/6/d/e/2pacx-1vs1dvkfrujajsa7oo5lrr8jtgkptt5bkchxfesyemxh3tajbdgtb25uikmsqpb0kahma4jpgkbvhuw7/pub?embedded=true"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006290; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/12467akksjbdxtns1aefg-fo9hlxamtxynf5brvbz5tc/viewform?edit_requested=true"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006291; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/17rbx8y2bk8n4tzm0fbld5vi4ldsc0skyuqq0ocijhsu/viewform?edit_requested=true"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006292; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/17ykjtyquasvwqcygncvpk_tauut_upopxrzahp-kl88/edit"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006293; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/17ykjtyquasvwqcygncvpk_tauut_upopxrzahp-kl88/viewform?edit_requested=true"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006294; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/1at1szjcizcvzpxigp7kdqcqnldrhvbqraephkdthdzq/viewform?edit_requested=true"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006295; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsc7wk_lliii2kmlzioccedhth-8dtimxssmjlqhvyhgqcvhug/viewform?usp=sf_link/"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006296; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscbeerfyysxdza2oqbpaqv3bgg-btaukxob7fgw3ocadqr7_a/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006297; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsccrmuj1kgyaifnexjgz7uwtbq-welv7b6se4xggq0kozvomg/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006298; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscgfmbl_g3pnr0wnhsnlhnpgjsxpztuihfrhn4z1cdivkx6eg/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006299; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsch8_wrvwsg5klxptwjznnmghz9ny516msszkmzzjr6wqll4q/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006300; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscmdgj6qecrpzdeetekksdsi2dgbvcbvw-kbrq6ypfnjhoatw/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006301; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscnuhm7wijrt4ncghf1u7hljgc8fzbda9vaxwcbkerqbobyqa/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006302; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsco-kqtne3-k3es6vbiwm_9s0rnk1uqt6_ibg6auya8xowx7w/closedform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006303; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsco-kqtne3-k3es6vbiwm_9s0rnk1uqt6_ibg6auya8xowx7w/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006304; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsco0gvjsnu6vwouw1cnby9hqmoveqoekq63vj95s1xq5gc01g/viewform?vc=0&c=0&w=1&flr=0&usp=mail_form_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006305; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscpa8zgy_b8ph6q-ngor9tutn322gorvbbyvcs6pi5br5p7sq/closedform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006306; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscq8lwf5u5pxklisswjs79fcko1u76xaqw2cplb00uamj2epa/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006307; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscqmukecmtmp23rms6pzgaz1gmh1su9zhfhkee9co43bh-laq/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006308; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscrsmi7yivz8iyj-bxl0gvtyhvodzxaq15frcxyfz4yljthka/closedform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006309; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscrsmi7yivz8iyj-bxl0gvtyhvodzxaq15frcxyfz4yljthka/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006310; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscrwpy5ijddeveo24j9wvizwt5v2nnruqz_adhvkqn-9hgplq/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006311; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscsp2ltu8y_5h-m0512ckji9i1rwabxoforr5hgbkwi-gx9mg/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006312; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscsvqbqqwb6tkll9njrevs-2kydrbyerhhf7qdv3oy015fxkw/viewform?usp=sf_link%3e/"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006313; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscsvqbqqwb6tkll9njrevs-2kydrbyerhhf7qdv3oy015fxkw/viewform?usp=sf_link/"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006314; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsct1pxn0qq6ulzzs2kqgekpwoa-galaegxg5mzuxii-fvmwaq/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006315; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscwcsh_hzs9vbuy8ebi9hded6rnqndfzfph5b4ehfs_kpjfiq/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006316; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscwffsbhcdalis0tq6kyc2ldt6ew8eb-um_30rxblc5jc2zlg/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006317; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlscykc67tpqedqbogwqo68d7_-3pzqm6exykm2a-w9z6ss8jaa/viewform?usp=sf_link/"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006318; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsd5pkme7ixm1zrv37caywfimm1ewnbgs4v4tau_hbfmkbaz-w/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006319; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsd6h5k1kajgpan-tfvs7w4k_b4wq3m6wjdfh_kfrpiq-3w-ag/viewform?fbzx=8876075289152692257"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006320; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsd7shjgl-xzh0b--otxbgyaq02wjun61jituz_kgjvmoqhwrg/viewform?vc=0&\;c=0&\;w=1&\;flr=0&\;usp=mail_form_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006321; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsd8pwj0urcun-j-97onvbnkgtgodxjmfi-xl8bcjptdhtzuua/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006322; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsd8vkw5fxeroe_pxa7n5cdfpukhahbg_7k7sg0iuosh_xsyoa/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006323; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsd_ufmuc1h1k59csqk4tq_qfsx-k1r2tsr075oqvgste4cwyq/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006324; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsde1ytd1ixniiptb2ijsredmchzqihbwxzsisczaitffpidug/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006325; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdefq9jfitlsn0qsogjtunonyv2htj9mqaqwbvvzvjzkglbcg/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006326; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsder2phxogzlzxdomg6qzw-wa2tcc-xoktul9wln-r8qvrh0w/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006327; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdfarxg-0eurkyimsg-ukgl4mbtgvwfhe1wzbdxmb7oaosnyg/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006328; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdgik3q_epgueg5jm7wkb9hfuolopkdpionzoriclb4vq0xbq/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006329; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdhdloijpfz-djbc5k5nzwa_mbdym5kgjm1ssgrhwex3sj49g/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006330; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdhr2qehprrqzfimbwtlojynm_nvvsdovser7pmho5v5o4cxw/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006331; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdkyktaljlr1brgemikvngcntysunwsyoykmlj8yqinn54ala/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006332; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdm8dg7ek4wb9o7ovu9hes5ywrmqvmenl2knhz4yfzdge0kig/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006333; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdmhmrgusu9z2rq2l1uz7vhgsbuxmhyw_wsnrze_mrzfpzz3w/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006334; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdp-5roof4dzzivh9nvegldbqvrbi60inudyjxdj7qoevj9qw/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006335; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdp6gmot9lhhgyqmwp6tavohtvtacptly7nzcuiynoir9cjbg/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006336; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdpqkkmgs4sak2sfjan6pey8aioourp88n1miyrfqetirpeja/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006337; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdpu1i7oofsplo-eelvvqm_xfg1_9yerqqepyya-hudhbhskw/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006338; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdpyvreq-ep0jbvs8gp2oehnu3bxiac9fskhtmy4gmyvq5ihw/viewform?vc=0&c=0&w=1&flr=0"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006339; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdpyvreq-ep0jbvs8gp2oehnu3bxiac9fskhtmy4gmyvq5ihw/viewform?vc=0&c=0&w=1&flr=0&usp=mail_form_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006340; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdqcoor5hd4nvnl0epci6aq2wc-mk2bfrizvc5j71phhwxyug/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006341; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdqwd3x7oxndt_qsdhnlk8b1jkp3-9_ypyh9loclnunz90t_w/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006342; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdrgmsmwjbdnoref0qnmgcqlq0s4pgrmhj0iqyfrg0eqqi3jg/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006343; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdsguz5acr7fg2h1awh6fvhkpdbl2tvek4x8umeg5r167kdmq/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006344; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsduyjduynn1pyn6uouzxs00zao-l_e-xxzxpl0aaalgvilseq/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006345; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdvo-nueiprck-o5gw7-bnmsz9jvwlyspeqfhfr2g2osbsrba/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006346; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdwbz5hapgqojwjyndeeyjxamg0wnaj3kolh3fb6xf4c-fxjw/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006347; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdwbz5hapgqojwjyndeeyjxamg0wnaj3kolh3fb6xf4c-fxjw/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006348; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdxkjopelrwprbruv5pypgeut5c971mdpwp9w1ndxosaui0oa/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006349; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdxlavo6fubcjtjtvvtn98_t4mfml3doa2p_cyecldhozibug/closedform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006350; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsdzpz7mn6te18_1olbnvu14ez5j_lscj_pintnwldwht6wtaq/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006351; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlse2axrxuz4hf-wkps_tryezncrr3zvl_bm9icnltshp5fj60q/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006352; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlse8ds15kxxdcrhfspcfrbvy6sbdhp0e4540zzmhhvzouewvka/viewform?vc=0&c=0&w=1&flr=0&usp=mail_form_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006353; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsedqv25gmfbuzel2k1vcq-m73hioxsvwfvj9txciisakqjvkq/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006354; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsefcnwk7zgw3shfn7g7czhpmhprbk9xvussgkfo0bj9ejq2ia/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006355; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsefobujynmyi2xpjuku3qusvfpyatn4kevomjdaas4i1fkyxa/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006356; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsehk4tap2jdgccww_qbejncpxcstkhyi1jlrqabkmqrmnmi7q/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006357; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsejg2xiowc36xpgb4yrzafossvuajgg7b3kyoyr91ahcajyhg/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006358; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsejg2xiowc36xpgb4yrzafossvuajgg7b3kyoyr91ahcajyhg/viewform?usp=sf_link%3e"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006359; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlseke7h-uz45ye-38rzajai72zwledarzxbo13ozd3fcmlvdvg/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006360; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsel_ki8gcgzajteddl27pbkpo6w90de6hj6epzsurphsvekpg/viewform?embedded=true"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006361; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsemuphd9zpegybxx9gwrw-vsu9gbqjuufhz2wx34p7cj1cibq/viewform?vc=0&c=0&w=1&flr=0&usp=mail_form_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006362; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlseoekkrlsnwu8nd31v1i9lvvgprukrmqehwatueda5uq48sgg/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006363; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlseou9x6ynbrngwpjjjavdypjljoxfgtz_tk4xkxwvruwzxw8a/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006364; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlseqsyymqxpwa6zh67qmzvda7esy11ihhirovqdg8vfb8bxfbw/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006365; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsest8_rwxm6ce6jgwc0cvwll6rw70wuaxhhfhqzpcif3qzxpg/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006366; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlseszgantjzuxgteg0dsiizzmadcwjbjqcsri5nidod2rd2_lg/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006367; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsevlkj-wxfflm6xaqg7qiray3wchhhl_mdm62epebgn8qovfq/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006368; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsewhqkpda5rornxmecptyqqvnyyic3v_i3ajrq6xvhx3t1b8q/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006369; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsewrmf-csvroby-ketro5ndahy080piy5-zh0ou4wwmebarba/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006370; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsewth0iwp4d03yewdcbubgax6ftgolfxpebnmeh9cfkxtmm2w/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006371; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsexrthgahyza746esrgvtj4hqnjlqgmef_k2l3usnolt1fjgg/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006372; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsey-5kmlfgxx1mz3bvpmfly5uyiyfxylgqgdajj9bglqepzxq/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006373; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsey-5kmlfgxx1mz3bvpmfly5uyiyfxylgqgdajj9bglqepzxq/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006374; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsf0gsv5yuqbggvsrjcivlhe5kroccag3pbzucicgbnq9n4wbw/closedform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006375; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsf1ysr-9jy-n2hsh6rtxrsvxrsvi2yrraqueylgptsmvr2w7w/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006376; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsf43dgkrjoe0kbhyqzxvaswkmbstzlu6x-40xi-sxxgfevhww/viewform?vc=0&\;c=0&\;w=1&\;flr=0&\;usp=mail_form_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006377; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsf6p_80yq92a-_us2sofphw2hcm5zt6f6phft8jraibgfomtg/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006378; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsf_wng52uwsarcnof6_hd9p1o4mctalgjombr1l1vrex7pkrw/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006379; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfaexmgpgntdkiayu-wg3vbkhus9frurejyqxukiiydkjc3ug/viewform?vc=0&c=0&w=1&flr=0&usp=mail_form_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006380; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfagwtagrphkvtklixloz6fjr07qqsctkpirihjxzrgdlsnaa/closedform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006381; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfcbbgof7lfcganiwuiubcqdhwl_ppaaxbwiuf7aqmljimizq/viewform?vc=0&c=0&w=1&flr=0"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006382; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfdkosvk2hhajl6d_qyj7rz5olx6vqitbs413mgxqoeum7d9w/viewform?usp=sf_link%3e"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006383; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfdtgskanw6hzqm4qwepidpbrzfbnlqtovnznbcqvsifq3_iw/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006384; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfdtgskanw6hzqm4qwepidpbrzfbnlqtovnznbcqvsifq3_iw/viewform?usp=sf_link/"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006385; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfdwn92qvw38ss-20kzipddctgi6s6ih4nasxeqlgtvdjh4ea/closedform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006386; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfeoy_w3jwkkz8psgsw4nrja9tmg2lx0x0nvtmv38k0hjzzmq/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006387; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsffxdjsibp7kmfd28idwdkvupj3klesiwvpoiecz8xpgdh0cq/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006388; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfghx3hyhgfr1jp970gy2jhp0gjb0hh1sk4pmxon7h7rz2opg/viewform?usp=sf_link/"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006389; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfgomlcpbyhodks1bwjmx6f5jr0tqwhngun_juf2qk0jp8dbq/viewform?vc=0&\;c=0&\;w=1&\;flr=0&\;usp=mail_form_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006390; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfhzli805cycnlai887dfo6ra8bwbwjbc8uehmv5amiaqdbyq/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006391; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfkobo05nzcts8cbcep5gmswnodxxpt1evmdtqr5yzx2o6vla/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006392; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfnjsl9ry7bzzepaqrmopr8rexeascth2wvnf_dbqnzxhf-tw/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006393; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsforgq2zksc0soenei1m7xcow9surjrynoh6ppsku6_kxvdpw/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006394; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfp3troetr74o0b4lazn3lnrb1uuxueb_eionaobgh1subkdq/closedform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006395; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfqqzlbszgzyek62tcz4xfuynz1p1ld4wk5cxsr0e0mnoaamg/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006396; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfsr_hufaploql8ruxbcya-5su5xpkzee0qtzs6_ixatjrmcw/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006397; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfsxzzspfakizftohfsh_jzapengjfhdtr6uvutyrd4hl11sw/closedform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006398; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfsxzzspfakizftohfsh_jzapengjfhdtr6uvutyrd4hl11sw/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006399; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfsysrvjxms2_dloeyxhveap0tmaypl94fosq8vvwmg2msqta/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006400; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsftc8pzgnchucxppoh7dwdnwga1asfv5vioebd62xhw7uao3w/viewform?usp=sf_link/"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006401; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfvgwgijgampx2qfseard_pb2bcyonllojnjhrv9qxb8vpeva/viewform?vc=0&\;c=0&\;w=1&\;flr=0&\;usp=mail_form_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006402; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfvgwgijgampx2qfseard_pb2bcyonllojnjhrv9qxb8vpeva/viewform?vc=0&c=0&w=1&flr=0&usp=mail_form_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006403; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfvqkhdutqimzgq1xtwf9xs-f5ydlpvfn88taxmzpl18tgajw/closedform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006404; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfvqkhdutqimzgq1xtwf9xs-f5ydlpvfn88taxmzpl18tgajw/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006405; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfvvvnddwmy-3u-agx0bvar5wfmplx8bvgef_zdia7ra9llfg/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006406; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfwbcfrxuktidm2ctjalngebxbx4k_dijxbekg2y-naausaqw/viewform?vc=0&\;c=0&\;w=1&\;flr=0&\;usp=mail_form_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006407; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfxoc8vekgqzkhzna2nynvv4fpmbntvo6_rbnwinjte4at6ya/viewform?vc=0&c=0&w=1&flr=0"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006408; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfxrzxwjufyfzuebcb4flfnylf7qprxcsvbkkwmchoy6cum6a/viewform?usp=send_form"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006409; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfyjprmb9ayjnyx7pfozqp5vvs4ovuya64nmviid7pefbkk-g/viewform?usp=sf_link"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006410; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/d/e/1faipqlsfzhsjvdnah2glqvi9r_jhquixqxbp4k-zg9enl_bxurtyf3g/viewform"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006411; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/viewerng/viewer?url=proxy.ge.tt/1/files/5d0k9lx2/0/blob?referrer%3duser-a6kjrvmdexz9favkffsdh44k4iybrxak3pn41u-%26pdf&\;ddrp=1=secured"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006412; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/viewerng/viewer?url=proxy.ge.tt/1/files/8tnpiby2/0/blob?referrer%3duser-ur6z6ngiuctfxjqxnhc2bxyonvsmvcncqdrvc-%26pdf"; http_uri; nocase; content:"docs.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006413; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/nwqc2ax"; http_uri; nocase; content:"docsend.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006414; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/apc/login?id=dnvly0vmevnvt1dqouliudlyvgxntznuq2vnr1lxuwrmqtdiyuhnz0lqv1romw5nztrfvi9ba2gwdnuvk09zyzdkvhlsbdvcmljtwwthdkfxlzzfb05etursact5bgk2l0nmzlfmouzpmmjtyvboagt3u093bnk2yvryctc2wstybhzwukxjoel4cstjr3jzrwtjsk5qdnnxnuewzldacngxdfloevl6snczwuq5zfeyzglvmvmvm1bwb0txy0pcyvnpduhcqtzrt1mwthrprhlsz040eg5bu0rmn3buz0xssgr1mmpkly9ucusxtnarwffjwu1gri91tlzwwehjexfislg0ui9lsjdsdguwuna1t1zpttqvzmsvbwxeq0jim05zds9uwfazejjsv1rqnzvyynhfztfrtjhly01cnxvovvaregdbl1f1qml2ry83c3pkd2drpt0"; http_uri; nocase; content:"doctricant.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006415; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eur/login?id=k2ivcm8yt3hvbwuryxpnk0j1ttkrl0ruttzxexdja0xqum1krnlwwndtzi9oz0jmum1wztdsestnc1pmuvm1beltwkwvv0lzvguwumy4ativtvfdd29moeday1fpuuk4zxbvdgvod0zerktjrzvozejxwmviajhmr2jrtm1vrmlheke3mznjck52svjfrtfhmglpr2yvvdu2ufhbves2vxrzv1ncdzkrv2k5qk1jrdrjzlbju2hkzgrcvwgrtuxjzwpvb2tdtm5mshi0ohlachyxq2fun05eq2cvqk5ltw1cm3rueitnaujgnwovd2jkz2oxakxvwmxxzxnhn1lutvfwdkryytyvk0i4ekmrbcs4dejpwxdtelewwjzib3hhdxzice5hcfjymjhez2lvbhgrti9owst0y2tjeehenxm"; http_uri; nocase; content:"doctricant.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006416; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gbr/login?id=a0hkwjr2ugxnmujgdumrrzntoeriefnst251t2nkzg93bkxkugu4ali5ehpouw95mfhouuixeufrweneqlzqcmfzsmdkovjhvuvjwljznus4d2htegtpk0vrmfb2zef6d291d29hzk51d3m4ckxjz2diblnltdnrsgowvuhboulcwtz4q2vlemh5y2xbs3fmzucyrkpucknzukt0sutmqlk3y1u2vlnnt2r6qujvb3hbm0xtrvbbzvzvtux1wnc3tkztr0dodvown0w0qkryogdiums1vdhkenq3aetzwm9dektnyxhrdtywm0ftrlnkudflq1vrodjvwhpzunb1mvnvr3baqi9tqu1rufq1yvpitjqxrwxlwu9jaehvwuvpwk5vnu1oaklzvuk4cjlpbuzgykhvbxlqqulregmyyuw"; http_uri; nocase; content:"doctricant.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006417; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ind/login?id=s2zczexyvfremellelhybezsq3mxrjbsejrybukyeenosdjpu1nlbgjtmvpzmzlzejjoodjmuwjoejb3d2zkvit1euniqwhlte8wcdm5tmvcvw9pclvsuvnmzkfvntbxcxjxmuzvtkluzysxruzhqznyvwvadss1uno4bjlpd1c1emjcvefkk0k3dnpowwk5r2lxs2zpwmgvuhhfcgnol0g2bwjfmgtjdfjxdhfhbmndk2fgcwlvb0xzb25jzzn5yjqvngnqdy9os1c5ohpwafdlrw5jrlq5qtb0vezvzvk0buvtcmzkmmjka2x2r0xumww2u3djqtjlqi9rzwu5nhc1dfqrtflez2dhsmzlmwroefdizudeyktzr0juakryvjltm0hlb0kynstddny2wgjrdmviaelmaeqvvhjvvdvqwhvlm0q1uzd0vxffelziekjku01rpt0"; http_uri; nocase; content:"doctricant.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006418; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/nam/login?id=cuf6shhavuzaatvtuvduetvvuitsrxo1vmdrc1zxtufcn1rscxa5qwrzota4zzbxrtqrsfnwaji1nuteowhweupps2vxrxn3ujllbtbrnmzvcghpeukrqwhlakhzbxdomkhnb2q2mwziohivrmqxvwy1d3bzadfnq3jgv2rua0zqbzrdnctyrhloy2u1ce0rekxea2nnoffruffpofv4snjgaeg3skhol08vue44czv1vxrrdvkxwgf2zdlrcdfpvlmynmnkq04zumlis0pqblrquxjktjlyvgnqb283b3nyzuh1vzq0cys5du1hnzq1ddlcnmtuafmznwxoakx6azv0qkh6nmdssfi1de51wkjbk0g3qtdrl3z6y0lal1lztxv5svzvyzbim2z5l1rwne14zmnreuvmr0hbweg1bkttnjb0amw1vlcywkztwmo0yzdkn2yrtmtrwhdsa3ztrtlwmgpatg5sewrnpq"; http_uri; nocase; content:"doctricant.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006419; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/exchange328e91ec88ae4615bbc38ab6ce41104e/jspuser328e91ec88ae4615bbc38ab6ce41107e/?08a3ea=brian_casey@capgroup.com"; http_uri; nocase; content:"dolcevitabymerit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006420; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:b:/g/personal/alice_dovecare_co_uk/eux9kze32kbkhhfsn9xq0neblkljq83z_9o1u8jpewiq2a?e=4%3ah1ax4s&\;at=9"; http_uri; nocase; content:"doveadolescentservices-my.sharepoint.com:443"; content:"Host"; http_header; classtype:attempted-recon; sid:200006421; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:u:/g/personal/robson-hemmingsi_downehouse_net/evxeexzy66hjj9rkfmnus38bolc6coukehkxv--swrydfw?e=jvp1fk"; http_uri; nocase; content:"downehouseschool-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006422; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/easter/"; http_uri; nocase; content:"drawgames.top"; content:"Host"; http_header; classtype:attempted-recon; sid:200006423; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/19zpw90jgon3j5merxi1pauvkjdmx8nfq/edit"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006424; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1bcdyitw2vo5jp6yrbdmiy8cfrkcf4tby/view?usp=drive_web"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006425; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1c5o9_y8_octsepwyojfarn1k-kj4d9fe"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006426; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1cc4iizuwctob05muvpmydl-rruxdfimu/edit"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006427; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1cppgzjnodnftsks_w82um_b_ctgzn-ah/edit"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006428; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1cvc0ts0fkrsyx6vnnuypmotnh7jkcsln/edit"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006429; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1d47d5zh0cxucg1uupib1hyg9mhhe0ziq/view"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006430; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1fdgs5g6fqqkudcl2meym63ua3yu0o-tb/view?usp=drive_web"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006431; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1fsvmjkcq7ennrsfdufkcxshfhnda_fui/view"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006432; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1ginbnlpvt7kpfnog9a68fqmn7k3aivui"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006433; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1hdvx7j89h5l7yz39idgzhqji93jnkl_c/view"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006434; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1ik3uxh3rdigwar7d269wvkowp17cci1n/edit"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006435; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1jixb69t_nw9tmkhvfrejkfzof3d-ijet/view"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006436; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1jvfh6wq9ea9kxr1shhwbh3pecflqzppc/edit"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006437; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1knolz4xw7mgncsjysbomy_y4zxlk6zld/view?usp=sharing"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006438; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1mg5asnyoeet7qsg2n0d_2paxc3j7wx3k/edit"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006439; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1qf58h-1lunq1pubplwdhwd3uooj_vjxa/view"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006440; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1rngxz2sujnvysokmcvjpuzyljrdsetvc/view?usp=sharing_eil&ts=5e457ab9"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006441; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1robiosanbh8doqa7yuiewn3akz4094ho/edit"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006442; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1ttaa6m96xsz9kxqa0zy3mzoirfmbspkd/view?usp=sharing"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006443; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/d/1zmjm3f6e-mgx8ev829md4mxxyd300nbb"; http_uri; nocase; content:"drive.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006444; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/l/aabmsbm11bbmhboguaxc-7ijn4p_zrdd81i"; http_uri; nocase; content:"dropbox.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006445; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/l/aadakwg8ie5mo9zj3g2yippeasfhc1ciose"; http_uri; nocase; content:"dropbox.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006446; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s/8jlk677mjpkt7zo/balance_summary.htm?dl=1"; http_uri; nocase; content:"dropbox.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006447; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/transfer/aaaaahb-waj-e4g6xc1-zlhkqtut1utkvb6kfiibyv0iugf01blnnhc?download_all=true&email_type=send_by_email_recipient&ftref=65f8e83fd6ecb057cabb12153b9a4897ac928bac0a5c4e405f837fcc4810d5d9&oref=e"; http_uri; nocase; content:"dropbox.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006448; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/transfer/aaaaajtnkxz2ahm2bpzg_ntfz8gyioogcjx1qd09ffexylaokn28cyg?download_all=true&email_type=send_by_email_recipient&ftref=37be8053cec8e9e55deddb975b0124b6c71238653dfda3ebd6d46e91a51719ee&oref=e"; http_uri; nocase; content:"dropbox.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006449; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/transfer/aaaaajtnkxz2ahm2bpzg_ntfz8gyioogcjx1qd09ffexylaokn28cyg?ftref=37be8053cec8e9e55deddb975b0124b6c71238653dfda3ebd6d46e91a51719ee&oref=e"; http_uri; nocase; content:"dropbox.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006450; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tmp/?0120amyuym91y2hhcmraywkyyi5jb20n552"; http_uri; nocase; content:"e-donusum.vbt.com.tr"; content:"Host"; http_header; classtype:attempted-recon; sid:200006451; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/aat9ri06hv8xmyo/mtc1uzqfml2blna"; http_uri; nocase; content:"e-shlnegarment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006452; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/aat9ri06hv8xmyo/mtc1uzqfml2blna/"; http_uri; nocase; content:"e-shlnegarment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006453; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ls/click?upn=xvki30ts-2bm4ra9hhuoe-2fb72d791z950dfa2vkbspkrytbyxawmbb1sw12mtgrdceksxefczylz78w63dgubclulnudrvnzpo46vrk2ttj-2fqb-2b3p4kxl5-2fdvbkirvfys85ilnwlx-2bwf1sxdpztg6lirgd9t4qyhltk4zt5jufb-2bpbmpamsw82txso3ugbvkoi9itfcpqu7ckvsdc25nxwh5gaawjh3cqctseyvdd2pky-3dg4oj_wigizs5wrnthkxbti2efesrirzf7fl0j3dpjtdvhwmiu-2f4d1w2vbh8njcbmvkaa98msmltvf6jwcczn8pmlh-2f9po0shg48u5za9n5daexbisxfpbjymowl5mksmptvdb-2buf-2f8c1hyxqidlgnmocm7lw0nocpburgjcttxd5ipayq3b1hepdkwt04gtrkw1t57223wwoukvmdfudlkgwxl2ppha-2fnzbyec40je3b-2fnpelemrr8g5qihfp4miwydfj7qd0cswgm6ywmsrj69exvpfr-2fusei13mb2r6h-2beu0yhv-2buirgdaj3ec6i7g8lwiiyvt2ktnnasemjc-2bbdqdt1pa6albebjalfogw6wm9g60d1vugxqrayfhnxauutthe"; http_uri; nocase; content:"e2.udemymail.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006454; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fraudulent.html"; http_uri; nocase; content:"ebayfraud.gremlins-in-it.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006455; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/anoop_ecead_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=ob%2bx5gu%2byygxkxxbv4jv6m%2bahzjcdheae%2fczpgjdc6i%3d&docid=1_1b483039813af4707b9fefa62e8eb0625&wdformid=%7bb19c1f19%2d88a3%2d4bb2%2da0f6%2d40ff3f6c5714%7d&action=formsubmit"; http_uri; nocase; content:"eceadae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006456; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/alldomain/domain/dmain/index.php?i=i&\;0=abuse@optusnet.com.au"; http_uri; nocase; content:"ecomcrew.staging.wpengine.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006457; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/sb/asb/index.htm"; http_uri; nocase; content:"ecomkeeda.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006458; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/margishowalter_economyfurnaceco_com/_layouts/15/wopiframe.aspx?guestaccesstoken=3yiqriy9vn3m4dcuaohj4bowqckq9hroz911ptlk8b0%3d&docid=1_17af0439798e04aa493f8217d1689b887&wdformid=%7b610bc340%2d5ced%2d43a9%2d98be%2d7b650672a85a%7d&action=formsubmit"; http_uri; nocase; content:"economyfurnace-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006459; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/#sarah.collard@aviva.com"; http_uri; nocase; content:"ecpvzxbohtiavujpwrmzytboki-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006460; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/angela_ure_ecusltd_co_uk/_layouts/15/wopiframe.aspx?guestaccesstoken=umwosbguhwaqic3hhtqfly7zjwf8oggrcn6d ggohoc=&\;docid=1_1956f6e254d71417a89981b2a1c8d0a99&\;wdformid={e61ca4f5-c461-425a-a52e-4598e7b699e5}&\;action=formsubmit&\;cid=4ab9a2a7-7cf4-43ae-8149-ffead8d66e7b"; http_uri; nocase; content:"ecusltd-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006461; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/angela_ure_ecusltd_co_uk/_layouts/15/wopiframe.aspx?guestaccesstoken=umwosbguhwaqic3hhtqfly7zjwf8oggrcn6d%2bggohoc%3d&docid=1_1956f6e254d71417a89981b2a1c8d0a99&wdformid=%7be61ca4f5-c461-425a-a52e-4598e7b699e5%7d&action=formsubmit&cid=4ab9a2a7-7cf4-43ae-8149-ffead8d66e7b"; http_uri; nocase; content:"ecusltd-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006462; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/angela_ure_ecusltd_co_uk/_layouts/15/wopiframe.aspx?guestaccesstoken=umwosbguhwaqic3hhtqfly7zjwf8oggrcn6d%2bggohoc%3d&docid=1_1956f6e254d71417a89981b2a1c8d0a99&wdformid=%7be61ca4f5-c461-425a-a52e-4598e7b699e5%7d&action=formsubmit&cid=4ab9a2a7-7cf4-43ae-8149-ffead8d66e7b"; http_uri; nocase; content:"ecusltd-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006463; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/20jessicamiller_lindberghschools_ws/_layouts/15/wopiframe.aspx?guestaccesstoken=jv9wbvf6jfqmu%2bpjy3c%2bj7gd%2bvswnc1xz8o9bkulrkm%3d&docid=1_124e7318433ca471780ebffb8ed3119fb&wdformid=%7bfbf01b7f%2dc381%2d45e7%2daa1a%2d86eb8e279071%7d%2f&action=formsubmit"; http_uri; nocase; content:"edulindberghschools-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006464; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/system/renew.html?id=fr76zhsl9s8"; http_uri; nocase; content:"elgea-habitat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006465; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=akowbwdwm%2f15ep8zswuw1id0vmpqmkm3vc4jwvddirw%3d&docid=1_1b124a04726944c449498756807aaae31&wdformid=%7b4d4710fa%2d1101%2d4c23%2d9580%2d7cce85e183be%7d&action=formsubmit"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006466; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=akowbwdwm/15ep8zswuw1id0vmpqmkm3vc4jwvddirw=&\;docid=1_1b124a04726944c449498756807aaae31&\;wdformid={4d4710fa-1101-4c23-9580-7cce85e183be}&\;action=formsubmit"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006467; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=r0cwyxezu0u4qskhqlg4iuppg%2f8kb5p%2bbd26c7pm5mg%3d&docid=1_10a004d72e6c74e5da1a88324055cba4f&wdformid=%7b0457694d%2dea64%2d4327%2d9a31%2dbce69cae1542%7d&action=formsubmit"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006468; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=r0cwyxezu0u4qskhqlg4iuppg/8kb5p bd26c7pm5mg=&\;docid=1_10a004d72e6c74e5da1a88324055cba4f&\;wdformid={0457694d-ea64-4327-9a31-bce69cae1542}&\;action=formsubmit"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006469; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=r0cwyxezu0u4qskhqlg4iuppg/8kb5p%20bd26c7pm5mg=&\;docid=1_10a004d72e6c74e5da1a88324055cba4f&\;wdformid={0457694d-ea64-4327-9a31-bce69cae1542}&\;action=formsubmit"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006470; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=akowbwdwm%2f15ep8zswuw1id0vmpqmkm3vc4jwvddirw%3d&docid=1_1b124a04726944c449498756807aaae31&wdformid=%7b4d4710fa%2d1101%2d4c23%2d9580%2d7cce85e183be%7d&action=formsubmit&cid=734cacf3-54ff-4571-b776-3d8fea96b45d"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006471; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=akowbwdwm/15ep8zswuw1id0vmpqmkm3vc4jwvddirw=&\;docid=1_1b124a04726944c449498756807aaae31&\;wdformid={4d4710fa-1101-4c23-9580-7cce85e183be}&\;action=formsubmit&\;cid=734cacf3-54ff-4571-b776-3d8fea96b45d"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006472; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=r0cwyxezu0u4qskhqlg4iuppg%2f8kb5p%2bbd26c7pm5mg%3d&docid=1_10a004d72e6c74e5da1a88324055cba4f&wdformid=%7b0457694d%2dea64%2d4327%2d9a31%2dbce69cae1542%7d&action=formsubmit&cid=1a47822e-c696-4f00-b2bd-b89f0f160fcb"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006473; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=r0cwyxezu0u4qskhqlg4iuppg/8kb5p bd26c7pm5mg=&\;docid=1_10a004d72e6c74e5da1a88324055cba4f&\;wdformid={0457694d-ea64-4327-9a31-bce69cae1542}&\;action=formsubmit&\;cid=1a47822e-c696-4f00-b2bd-b89f0f160fcb"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006474; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=r0cwyxezu0u4qskhqlg4iuppg/8kb5p bd26c7pm5mg=&\;docid=1_10a004d72e6c74e5da1a88324055cba4f&\;wdformid={0457694d-ea64-4327-9a31-bce69cae1542}&\;action=formsubmit&\;cid=88eeca03-d4ac-4558-b97e-18a02dae5070"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006475; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=r0cwyxezu0u4qskhqlg4iuppg/8kb5p bd26c7pm5mg=&\;docid=1_10a004d72e6c74e5da1a88324055cba4f&\;wdformid={0457694d-ea64-4327-9a31-bce69cae1542}&\;action=formsubmit&\;cid=c90d1e34-23da-45a1-b4ba-84881dbfeb13"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006476; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=r0cwyxezu0u4qskhqlg4iuppg/8kb5p%20bd26c7pm5mg=&\;docid=1_10a004d72e6c74e5da1a88324055cba4f&\;wdformid={0457694d-ea64-4327-9a31-bce69cae1542}&\;action=formsubmit&\;cid=1a47822e-c696-4f00-b2bd-b89f0f160fcb"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006477; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=r0cwyxezu0u4qskhqlg4iuppg/8kb5p%20bd26c7pm5mg=&\;docid=1_10a004d72e6c74e5da1a88324055cba4f&\;wdformid={0457694d-ea64-4327-9a31-bce69cae1542}&\;action=formsubmit&\;cid=88eeca03-d4ac-4558-b97e-18a02dae5070"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006478; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=r0cwyxezu0u4qskhqlg4iuppg/8kb5p%20bd26c7pm5mg=&\;docid=1_10a004d72e6c74e5da1a88324055cba4f&\;wdformid={0457694d-ea64-4327-9a31-bce69cae1542}&\;action=formsubmit&\;cid=a282247b-742d-4691-a4d3-5c6a72070c7c"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006479; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/subind_eliotec_ae/_layouts/15/wopiframe.aspx?guestaccesstoken=r0cwyxezu0u4qskhqlg4iuppg/8kb5p%20bd26c7pm5mg=&\;docid=1_10a004d72e6c74e5da1a88324055cba4f&\;wdformid={0457694d-ea64-4327-9a31-bce69cae1542}&\;action=formsubmit&\;cid=c90d1e34-23da-45a1-b4ba-84881dbfeb13"; http_uri; nocase; content:"eliotecae-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006480; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/images?q=tbn:and9gctpssw1eco05z7yyt9h5de gpvythapzl23nhw&\;usqp=cau"; http_uri; nocase; content:"encrypted-tbn0.gstatic.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006481; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/link.n2s?url=https://www.wesellsupercars.eu//imgoe/doe/don/van/sgim/sne"; http_uri; nocase; content:"eproxy.pusan.ac.kr"; content:"Host"; http_header; classtype:attempted-recon; sid:200006482; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/nradonich_ersfilter_com/_layouts/15/wopiframe.aspx?guestaccesstoken=t6t%2fhn1dkbyhlyx%2beimbazufa43rrgz6%2faaaewnocdi%3d&docid=1_18168db23429e45f29fdf2e7be120efc4&wdformid=%7bb9970f62%2d44c3%2d4d09%2d9929%2d6e1eb652da57%7d&action=formsubmit"; http_uri; nocase; content:"ersfilter-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006483; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/nradonich_ersfilter_com/_layouts/15/wopiframe.aspx?guestaccesstoken=6ywmlbqi9 sjfgzhadhvte2gyowjf83iqbjrjehik4s=&\;docid=1_135f7008dfbfa44e6b09dab0eb165b997&\;wdformid={e037f2d9-5daa-4916-ba03-eb11d0aa6dea}&\;action=formsubmit"; http_uri; nocase; content:"ersfilter-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006484; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/nradonich_ersfilter_com/_layouts/15/wopiframe.aspx?guestaccesstoken=6ywmlbqi9%20sjfgzhadhvte2gyowjf83iqbjrjehik4s=&\;docid=1_135f7008dfbfa44e6b09dab0eb165b997&\;wdformid={e037f2d9-5daa-4916-ba03-eb11d0aa6dea}&\;action=formsubmit"; http_uri; nocase; content:"ersfilter-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006485; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/nradonich_ersfilter_com/_layouts/15/wopiframe.aspx?guestaccesstoken=6ywmlbqi9%2bsjfgzhadhvte2gyowjf83iqbjrjehik4s%3d&docid=1_135f7008dfbfa44e6b09dab0eb165b997&wdformid=%7be037f2d9%2d5daa%2d4916%2dba03%2deb11d0aa6dea%7d&action=formsubmit"; http_uri; nocase; content:"ersfilter-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006486; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/nradonich_ersfilter_com/_layouts/15/wopiframe.aspx?guestaccesstoken=t6t%2fhn1dkbyhlyx%2beimbazufa43rrgz6%2faaaewnocdi%3d&docid=1_18168db23429e45f29fdf2e7be120efc4&wdformid=%7bb9970f62%2d44c3%2d4d09%2d9929%2d6e1eb652da57%7d&action=formsubmit&cid=de35bc11-7371-4f25-96fc-d2f3d4588980"; http_uri; nocase; content:"ersfilter-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006487; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/selena_eternityflooring_com/_layouts/15/doc.aspx?sourcedoc={29a0efff-8f51-40d9-bcd9-4bcf8ae74f33}&\;action=default&\;slrid=6b27489f-b027-a000-cb27-3003139f9096&\;originalpath=ahr0chm6ly9ldgvybml0ewzsb29yaw5ny29tlw15lnnoyxjlcg9pbnquy29tlzpvoi9nl3blcnnvbmfsl3nlbgvuyv9ldgvybml0ewzsb29yaw5nx2nvbs9fdl92b0nsumo5bef2tmxmejryblr6tujpogm4v1nqd3pvbetjlw41q3u3ukrbp3j0aw1lpv91atzqq2pmmtbn&\;cid=1ad0104b-547c-477b-be5a-854c21f3580b"; http_uri; nocase; content:"eternityflooringcom-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006488; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/selena_eternityflooring_com/_layouts/15/doc.aspx?sourcedoc={29a0efff-8f51-40d9-bcd9-4bcf8ae74f33}&\;action=default&\;slrid=9e004d9f-c028-a000-7c23-0d326de333e6&\;originalpath=ahr0chm6ly9ldgvybml0ewzsb29yaw5ny29tlw15lnnoyxjlcg9pbnquy29tlzpvoi9nl3blcnnvbmfsl3nlbgvuyv9ldgvybml0ewzsb29yaw5nx2nvbs9fdl92b0nsumo5bef2tmxmejryblr6tujpogm4v1nqd3pvbetjlw41q3u3ukrbp3j0aw1lpxozoufndjdxmtbn&\;cid=502ded77-e010-4694-a1c8-3e651bc6ea9e"; http_uri; nocase; content:"eternityflooringcom-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006489; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?fbclid=iwar3cu_8pblosqw-rwa7evcrs5jpl6zvzkou0qrf7vl9oqge4h2ctmcxrdyk"; http_uri; nocase; content:"eurobankovnikredit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006490; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/matt_friendsmission_com/_layouts/15/wopiframe.aspx?guestaccesstoken=sdqu8zsaz2y6wit0jd9rcguunxzjtpfeujlvaaiz8lc%3d&docid=1_1245b1696199b4a9ea34b23cac546f087&wdformid=%7bc9148440%2db739%2d4438%2d9fdd%2d1915602e78df%7d&action=formsubmit"; http_uri; nocase; content:"evangelicalfriendsmission-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006491; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/matt_friendsmission_com/_layouts/15/wopiframe.aspx?guestaccesstoken=sdqu8zsaz2y6wit0jd9rcguunxzjtpfeujlvaaiz8lc=&\;docid=1_1245b1696199b4a9ea34b23cac546f087&\;wdformid={c9148440-b739-4438-9fdd-1915602e78df}&\;action=formsubmit"; http_uri; nocase; content:"evangelicalfriendsmission-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006492; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s321/client/snv?noteguid=777735b6-7206-0be1-628f-b095ff26a485&\;notekey=803670c5e267fe76b14b5c7466cb9dd8&\;sn=https%3a%2f%2fwww.evernote.com%2fshard%2fs321%2fsh%2f777735b6-7206-0be1-628f-b095ff26a485%2f803670c5e267fe76b14b5c7466cb9dd8&\;title=you%2bhave%2ba%2bfax%2521%2bcopy%2bcopy"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006493; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s321/client/snv?noteguid=777735b6-7206-0be1-628f-b095ff26a485¬ekey=803670c5e267fe76b14b5c7466cb9dd8&sn=https%3a%2f%2fwww.evernote.com%2fshard%2fs321%2fsh%2f777735b6-7206-0be1-628f-b095ff26a485%2f803670c5e267fe76b14b5c7466cb9dd8&title=you%2bhave%2ba%2bfax%2521%2bcopy%2bcopy"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006494; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s321/sh/9b9c2e56-0df3-1e03-5a66-617cf5ca0041/1153b91b874b7a19b82fe1a3955ecad2"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006495; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s339/client/snv?noteguid=f48e12fd-48da-e57f-8e76-cdf6e4054e1d¬ekey=02a9fa6bd051dc6b4581ee3b617b3f88&sn=https%3a%2f%2fwww.evernote.com%2fshard%2fs339%2fsh%2ff48e12fd-48da-e57f-8e76-cdf6e4054e1d%2f02a9fa6bd051dc6b4581ee3b617b3f88&title=optus%2bwebmail"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006496; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s339/sh/f48e12fd-48da-e57f-8e76-cdf6e4054e1d/02a9fa6bd051dc6b4581ee3b617b3f88"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006497; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s349/client/snv?noteguid=febdfb3a-d3dc-4087-8cc9-5f87708ee16b¬ekey=8ca96608bc2196024b9081f6dcfcfb14&sn=https%3a%2f%2fwww.evernote.com%2fshard%2fs349%2fsh%2ffebdfb3a-d3dc-4087-8cc9-5f87708ee16b%2f8ca96608bc2196024b9081f6dcfcfb14&title=new%2bfax%2bmessage%2breceived%2bcopy"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006498; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s417/client/snv?noteguid=df310074-30f9-9003-58c2-15885df371d2¬ekey=3f0a7060a363b0def315a6d1c98f0a9c&sn=https%3a%2f%2fwww.evernote.com%2fshard%2fs417%2fsh%2fdf310074-30f9-9003-58c2-15885df371d2%2f3f0a7060a363b0def315a6d1c98f0a9c&title=payment%2badvice%252fremittance"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006499; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s417/sh/df310074-30f9-9003-58c2-15885df371d2/3f0a7060a363b0def315a6d1c98f0a9c"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006500; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s430/client/snv?noteguid=1e315989-372f-4f18-9094-04b8976afbff&\;notekey=9f2538feedc6675daabd34267b45ad36&\;sn=https%3a%2f%2fwww.evernote.com%2fshard%2fs430%2fsh%2f1e315989-372f-4f18-9094-04b8976afbff%2f9f2538feedc6675daabd34267b45ad36&\;title=secured%2bmicrosoft%2bazure%2bfor%2bone%2bdrive%2bcloud%2bcopy"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006501; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s430/client/snv?noteguid=1e315989-372f-4f18-9094-04b8976afbff¬ekey=9f2538feedc6675daabd34267b45ad36&sn=https%3a%2f%2fwww.evernote.com%2fshard%2fs430%2fsh%2f1e315989-372f-4f18-9094-04b8976afbff%2f9f2538feedc6675daabd34267b45ad36&title=secured%2bmicrosoft%2bazure%2bfor%2bone%2bdrive%2bcloud%2bcopy"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006502; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s446/client/snv?noteguid=483c5f32-f1b7-7c70-925c-47f2705bab52¬ekey=911c810bd15ccbd1f19fba1c3e4cc4d5&sn=https%3a%2f%2fwww.evernote.com%2fshard%2fs446%2fsh%2f483c5f32-f1b7-7c70-925c-47f2705bab52%2f911c810bd15ccbd1f19fba1c3e4cc4d5&title=you%2bhave%2breceived%2ban%2binvoice"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006503; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s446/sh/483c5f32-f1b7-7c70-925c-47f2705bab52/911c810bd15ccbd1f19fba1c3e4cc4d5"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006504; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s661/client/snv?noteguid=bb8d3313-c8e9-0ead-34c7-0a149c4fd42d¬ekey=f25f8be6665ac7e37aff532080567fab&sn=https%3a%2f%2fwww.evernote.com%2fshard%2fs661%2fsh%2fbb8d3313-c8e9-0ead-34c7-0a149c4fd42d%2ff25f8be6665ac7e37aff532080567fab&title=you%2bhave%2breceived%2ba%2bsecure%2bdocument%2bvia%2bonedrive."; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006505; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s661/sh/bb8d3313-c8e9-0ead-34c7-0a149c4fd42d/f25f8be6665ac7e37aff532080567fab"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006506; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s672/client/snv?noteguid=b30b4b36-5bf9-846c-0577-bbb0c4439efc¬ekey=2f0f6f89194031fabbc3b4a455071a64&sn=https%3a%2f%2fwww.evernote.com%2fshard%2fs672%2fsh%2fb30b4b36-5bf9-846c-0577-bbb0c4439efc%2f2f0f6f89194031fabbc3b4a455071a64&title=microsoft%2boffice365"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006507; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s740/client/snv?noteguid=6dd4c982-2f3f-7d83-4e18-5e028127e7d1¬ekey=399d3f6c5e422fb90527fefea85cfc44&sn=https%3a%2f%2fwww.evernote.com%2fshard%2fs740%2fsh%2f6dd4c982-2f3f-7d83-4e18-5e028127e7d1%2f399d3f6c5e422fb90527fefea85cfc44&title=initial%2bpage"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006508; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/shard/s740/sh/6dd4c982-2f3f-7d83-4e18-5e028127e7d1/399d3f6c5e422fb90527fefea85cfc44"; http_uri; nocase; content:"evernote.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006509; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rrefeeieoj.html?erectrcsq@*cthiytvcdx$zsxycuikjmkjivee$terdtygjyvtrre"; http_uri; nocase; content:"explorebathurst.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200006510; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/baxie7/hdg83.html"; http_uri; nocase; content:"f000.backblazeb2.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006511; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/etr64746253aboki/index.html"; http_uri; nocase; content:"f000.backblazeb2.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006512; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/file/germanophilist-harmoniously-lommock/index.html#jaydene.graham@telecom.co.nz"; http_uri; nocase; content:"f000.backblazeb2.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006513; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?cp=hello20"; http_uri; nocase; content:"famous8536ylu.allsalelist.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006514; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/facebook-login-facebook-mobile-sign-facebook-help-www-facebook-com-login"; http_uri; nocase; content:"fbpassport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006515; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/facebook-login-facebook-mobile-sign-facebook-help-www-facebook-com-login/"; http_uri; nocase; content:"fbpassport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006516; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login-facebook-sign-up-facebook-login-page-facebook-login-welcome-to-facebook-facebook-com/"; http_uri; nocase; content:"fbpassport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006517; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/customercare/_layouts/15/wopiframe.aspx?guestaccesstoken=ce%2fd5uzxeu8hlntd6e5v18nttv4whxgmlwyudt4igom%3d&docid=1_1eb5df03726a240859b223a44b8b16724&wdformid=%7bb8008e00-21bc-4a4a-91dc-1e1b63610c96%7d&action=formsubmit&cid=c766f7bd-9562-4c9e-a9b0-75cf38b33e48"; http_uri; nocase; content:"fclighting.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006518; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/investorway"; http_uri; nocase; content:"feeds.feedburner.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006519; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?m=1"; http_uri; nocase; content:"fifohbibou.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006520; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/achproject509353-i353-3ih5f-10.appspot.com/o/achbf-vye-ur-g8%252fbv-ebry-8g%252fbf-vye-ur-g8%252fbv-ebry-8g%25%40fabf-vye-ur-g8%252fbv-ebry-8g10.html?alt=media&\;token=cf886132-ee55-43e8-9d0f-a6dbb7ba590a#"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006521; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/armaoffices.appspot.com/o/fdsklxrsqgdkqrwszsprjmbwtftqgpthwjwqjvvzscstgnmcvbblfcbcgwzjjbt.htm?alt=media&token=e3feec53-9d57-4eff-9b7a-d58e91e54d4c#user@domain.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006522; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/awesomeowa.appspot.com/o/rcowfort%2fr.html?alt=media&token=c9894bda-940e-457a-8649-00ed49c29eec&email=user@domain.ch"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006523; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/biyugbhiuhgy7o900-h9oh98h9-987.appspot.com/o/vnmbvuyt8-8y98yh0%3d890y8iuh9yyh%2f5rtyfghtfyu67-9876trfc%3d9ygv.htm?alt=media&\;token=dce6f041-19ff-4e8a-8012-1cfdac4cf369#bv@pplsi.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006524; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/bnnnnnn-2133f.appspot.com/o/sboy.htm?alt=media&token=4b58a3ec-3a18-4152-a41f-55a89a34d017&login"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006525; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/ceoagogo-76923.appspot.com/o/owa20934856%2findex.html?alt=media&token=7a9d6756-93f2-499f-9f94-a9aaa3c5dd51#reima.helminen@utu.fi"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006526; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/ceoagogo-76923.appspot.com/o/owa20934856%2findex.html?alt=media&token=7a9d6756-93f2-499f-9f94-a9aaa3c5dd51#service.itz@zhdk.ch"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006527; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/de-treikoz-hetrixo-13.appspot.com/o/%40%40%40indexv-vb-vau-ry-8%252fbv-yu-er-8f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525.html?alt=media&\;token=efb70ac2-20d4-4074-b86f-f5484e89a21e#mheiden@prepaidlegal.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006528; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/dr-clin-c4f68.appspot.com/o/drweb.html?alt=media&\;token=09293ba9-0738-41ea-9cf3-67cb43af2b88&\;x=famacas-cfa0appspotappspotmacas-macas-vfwefsaxsppspotcfa0ps&\;prox=p2000isolation@aaa.kr"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006529; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/dr-clin-c4f68.appspot.com/o/drweb.html?alt=media&\;token=09293ba9-0738-41ea-9cf3-67cb43af2b88&\;x=famacas-cfa0appspotappspotmacas-macas-vfwefsaxsppspotcfa0ps&\;prox=yourname@yourcompany.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006530; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/eu-oreiux-keriox-13.appspot.com/o/%40%40%40indexv-vb-vau-ry-8%252fbv-yu-er-8f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525.html?alt=media&\;token=5fa5b0c7-deef-4807-9630-9e1eaf32960f"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006531; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/goo2-ac630.appspot.com/o/goo (2).html?alt=media&\;token=2d1281a2-3364-420f-a3b5-c693b7bda1f2#a@b.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006532; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/grant-e7a33.appspot.com/o/fullzcrypt.html?alt=media&\;token=66773bc2-4b14-43a1-898a-9bb161f5618c"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006533; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/hing9-f9bc0.appspot.com/o/hi1 (9).html?alt=media&\;token=0d56c7d7-2e03-41f5-b764-4473f0ad4d51#a@b.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006534; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/ke-treuinx-metriox-13.appspot.com/o/%40%40%40indexv-vb-vau-ry-8%252fbv-yu-er-8f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525.html?alt=media&token=25657c63-3c2e-4f0b-b94a-e12adafcf0e1#user@domain.ch"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006535; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/lazar-9865e.appspot.com/o/indexvv.html?alt=media&\;token=1ae25ae0-0365-48cb-83b4-f64209600bba&\;&\;email=@yorku.ca"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006536; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/lines-c8ae9.appspot.com/o/webmail_login.html?alt=media&\;token=8d06efff-8a8b-406d-bf41-edff2e36b932"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006537; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/lines-c8ae9.appspot.com/o/webmail_login.html?alt=media&\;token=8d06efff-8a8b-406d-bf41-edff2e36b932#raymondtripp@prepaidlegal.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006538; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/macryti-109.appspot.com/o/kp-oe0%2fbtt-hash.html?alt=media&\;token=02abe8bd-5141-4b5a-a7d4-08120e5f43dd#choiteng@motenghaiplc.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006539; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/master-a7f25.appspot.com/o/cerkcfroek.html?alt=media&\;token=420caa32-915f-40c5-86a6-28ada5625a7a&\;prox=eimaste@stinpriza.org"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006540; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/master-a7f25.appspot.com/o/cerkcfroek.html?alt=media&token=420caa32-915f-40c5-86a6-28ada5625a7a&prox=eimaste@stinpriza.org"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006541; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/mic-apps03629.appspot.com/o/index.html?alt=media&token=d9f4f11c-e123-4b2b-8cba-b4f3f3541786#peterawl@prepaidlegal.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006542; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/mon-office.appspot.com/o/mscsq1-t-check-packet.htm?alt=media&token=72ab1aeb-a7a9-4a84-9852-099a56ca500e#dxnlckblegftcgxllm9yzw"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006543; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/office365user7856876769.appspot.com/o/securedata%2findex.html?alt=media&token=bd6d2063-1889-4e6b-81f5-c8fdde508797#janicewilliams@legalshield.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006544; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/on1rt-44071.appspot.com/o/index.html?alt=media&token=0d469e93-836b-4af8-b206-16a5d882d556#abuse@fasthosts.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006545; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/onlineupdatebase3456.appspot.com/o/sm123%2findex.htm?alt=media&\;token=158cbd55-4c67-4ef6-b13f-d69aba854f3a"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006546; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/onlineupdatebase3456.appspot.com/o/sm123%2findex.htm?alt=media&\;token=158cbd55-4c67-4ef6-b13f-d69aba854f3a#aaaa@example.jp"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006547; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/onlineupdatebase3456.appspot.com/o/sm123%2findex.htm?alt=media&\;token=158cbd55-4c67-4ef6-b13f-d69aba854f3a#fgsnews@yorku.ca"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006548; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/onlineupdatebase3456.appspot.com/o/sm123%2findex.htm?alt=media&\;token=158cbd55-4c67-4ef6-b13f-d69aba854f3a#test@test.de"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006549; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/onlineupdatebase3456.appspot.com/o/sm123%2findex.htm?alt=media&\;token=158cbd55-4c67-4ef6-b13f-d69aba854f3a#test@test.test"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006550; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/onlineupdatebase3456.appspot.com/o/sm123%2findex.htm?alt=media&\;token=158cbd55-4c67-4ef6-b13f-d69aba854f3a#vid@yorku.ca"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006551; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/onlineupdatebase3456.appspot.com/o/sm123%2findex.htm?alt=media&token=158cbd55-4c67-4ef6-b13f-d69aba854f3a"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006552; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/onlineupdatebase3456.appspot.com/o/sm123%2findex.htm?alt=media&token=158cbd55-4c67-4ef6-b13f-d69aba854f3a#kbaesler@bellsouth.net"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006553; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/onlineupdatebase3456.appspot.com/o/sm123%2findex.htm?alt=media&token=158cbd55-4c67-4ef6-b13f-d69aba854f3a#landman56@att.net"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006554; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/onlineupdatebase3456.appspot.com/o/sm123%2findex.htm?alt=media&token=158cbd55-4c67-4ef6-b13f-d69aba854f3a#sdeco@prodigy.net"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006555; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/onlineupdatebase3456.appspot.com/o/tb%2findex.htm?alt=media&\;token=8176e96d-c102-4018-9888-17d4dec8d489#"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006556; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/onlineupdatebase3456.appspot.com/o/web123%2findex.htm?alt=media&\;token=442069a5-b026-42a7-bcea-e6d92963d1d3"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006557; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/outlook-4c0f2.appspot.com/o/books%2fwebmail.htm?alt=media&\;token=216401d2-aba7-42f4-8fd5-9b672cade830#a@b.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006558; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/outlook-4c0f2.appspot.com/o/books%2fwebmail.htm?alt=media&\;token=216401d2-aba7-42f4-8fd5-9b672cade830#abuse@optusnet.com.au"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006559; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/outlook-4c0f2.appspot.com/o/books%2fwebmail.htm?alt=media&\;token=216401d2-aba7-42f4-8fd5-9b672cade830#teknik@iac.lu.se%20target="; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006560; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/outlook-4c0f2.appspot.com/o/books%2fwebmail.htm?alt=media&\;token=216401d2-aba7-42f4-8fd5-9b672cade830#tiekimas@tidlo.lt"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006561; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/rei-rezuio-rexire-565.appspot.com/o/%40%40%40indexv-vb-vau-ry-8%252fbv-yu-er-8f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%20-%20copy.html?alt=media&\;token=da92acdd-870d-4049-b9ac-f0d373777f06#broker@legalshield.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006562; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/rei-rezuio-rexire-565.appspot.com/o/%40%40%40indexv-vb-vau-ry-8%252fbv-yu-er-8f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%20-%20copy.html?alt=media&\;token=da92acdd-870d-4049-b9ac-f0d373777f06#info@legalshield.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006563; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/rei-rezuio-rexire-565.appspot.com/o/%40%40%40indexv-vb-vau-ry-8%252fbv-yu-er-8f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%20-%20copy.html?alt=media&\;token=da92acdd-870d-4049-b9ac-f0d373777f06#support@legalshieldcorp.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006564; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/rei-treioc-vetrazre.appspot.com/o/%40%40%40indexv-vb-vau-ry-8%252fbv-yu-er-8f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525.html?alt=media&\;token=61559c7d-ac3e-402c-9cd8-e7843742bbbb#associateservices@legalshield.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006565; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/rei-treioc-vetrazre.appspot.com/o/%40%40%40indexv-vb-vau-ry-8%252fbv-yu-er-8f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525.html?alt=media&\;token=61559c7d-ac3e-402c-9cd8-e7843742bbbb#broker@legalshield.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006566; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/rei-treioc-vetrazre.appspot.com/o/%40%40%40indexv-vb-vau-ry-8%252fbv-yu-er-8f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525.html?alt=media&\;token=61559c7d-ac3e-402c-9cd8-e7843742bbbb#businessmember@legalshield.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006567; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/rei-treioc-vetrazre.appspot.com/o/%40%40%40indexv-vb-vau-ry-8%252fbv-yu-er-8f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525.html?alt=media&\;token=61559c7d-ac3e-402c-9cd8-e7843742bbbb#memberservices@legalshield.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006568; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/rned-a824d.appspot.com/o/gen%252findex2oli.html?alt=media&\;token=ea1f404a-d74c-4ceb-b7ec-47fc4accf5b8#redvers@legalshield.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006569; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/serveradministratoryikjrpee1.appspot.com/o/second%20(1).html?alt=media&\;token=d92aaee3-61c4-4326-9384-d39d22513c26#info@cobos-fs.de"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006570; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/solomidey-57f22.appspot.com/o/%ec%8a%b5s832%eb%8b%a4%ed%95%a0j%ec%98%a4%eb%98%90%eb%8b%a4f-1dr2%ec%9d%80bo%2f-%ec%9e%88otr4s%eb%a1%9cuz9-tov%ec%9e%88-73l-os%eb%8b%88os9%ec%98%a4ck-z-rr%2f-5-lc:26ppdz3:a%ed%95%a0nb%ed%95%a08%eb%b0%9bw%ec%82%ac%2f487hhu74y.html?alt=media&\;token=2a2c8312-b0dd-4adf-8b8a-d5655ecb2174#"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006571; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/te-uriucx-reuines-253.appspot.com/o/%40%40%40indexv-vb-vau-ry-8%252fbv-yu-er-8f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525.html?alt=media&token=7fb7ef8c-0366-44c0-a0e2-a0152de28cdf#info@domain.ch"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006572; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/tei-neriou-reuix-678.appspot.com/o/%40%40%40indexv-vb-veu-ry-8%25433%2569.html?alt=media&\;token=6b0a9c43-8711-491b-9f40-50ad280ffb32#ggradnigo@prepaidlegal.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006573; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/tre-hreiocx-maeiox-12.appspot.com/o/%40%40%40indexv-vb-vau-ry-8%252fbv-yu-er-8f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525%2525252f%25252525.html?alt=media&\;token=cb4122a6-50a7-4e3e-b5f0-fbd0200f82da#admissions@utu.fi"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006574; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/tunewhctkjvzxjfzfxwkhnfshpct4.appspot.com/o/tuntbf-vye-ur-g8%252fbv-ebry-8g%252fbf-vye-ur-g8%252fbv-ebry-8g%25%40fabf-vye-ur-g8%252fbv-ebry-8g%20-%20copy%20(7).html?alt=media&token=27479f48-3c7f-4e9b-89f3-71d3885085aa#info@asona.nl"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006575; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/user3987267105468.appspot.com/o/a1%2findex.htm?alt=media&\;token=0ea51307-7b68-4058-abb5-4d7006478527#test@example.com"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006576; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/user3987267105468.appspot.com/o/xt%2findex.htm?alt=media&token=673d3b79-aa9b-43eb-8526-d9e508f2035c#"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006577; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/usghdihc62jdsjbvjcxbhv2678.appspot.com/o/__%26%26%25c2345%40%40%23%23!!gr%26%25.html?alt=media&token=3a184550-8b92-4d91-b0da-0533f3ace937"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006578; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v0/b/wdrhghxlcnwtjkjltmrtztqlh.appspot.com/o/celibacy - copy (7).html?alt=media&\;token=30c670b1-9299-45c6-a16b-5bd1037c4499#@yorku.ca"; http_uri; nocase; content:"firebasestorage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006579; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:b:/g/personal/joshua_pitts_firstgrade_com_au/ezsdc1nhrdbfoeztr4e1eigbqbwliqwmdrxbu3ws_hsvla?e=3d4%3aev0jjc&\;at=3d9"; http_uri; nocase; content:"firstgraderecruitment-my.sharepoint.com:443"; content:"Host"; http_header; classtype:attempted-recon; sid:200006580; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/themes/notificaciones_popularenlinea_consumo/home.html"; http_uri; nocase; content:"fizikagroup.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200006581; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mc.html"; http_uri; nocase; content:"flavena.co.rs"; content:"Host"; http_header; classtype:attempted-recon; sid:200006582; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/testo/wellsfargo/wellsfargo/wells/"; http_uri; nocase; content:"flooringexpert.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006583; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/event.claim.pubg"; http_uri; nocase; content:"flow.page"; content:"Host"; http_header; classtype:attempted-recon; sid:200006584; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tacazgiveaways15"; http_uri; nocase; content:"flow.page"; content:"Host"; http_header; classtype:attempted-recon; sid:200006585; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/1alrcrnkdj8mkguo7"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006586; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/6xrjdst5vy72cwqh9"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006587; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/8afvhxz6x4kwr2pxa"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006588; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cs4gorqpzdy9jxuu9"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006589; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cybsrnquqmvkacfd9"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006590; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ewzsr14c6zktbzbda"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006591; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fupktg3ezwcbwryza"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006592; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/goerpntl5tfeumdz6"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006593; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jclppgcchkt2slyn9"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006594; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jtefdwxoa8tqpaig6"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006595; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jw5mrytpvsrprswx7/"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006596; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kjagho44wwboxfrv7"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006597; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pqpntbtn4phymwhs8"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006598; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rk5edkr2gtfv47ph6"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006599; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/sxffnwvxz4frm7ah6"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006600; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/vdccgdoneyge5pdk9"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006601; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/vudcv1vwbiv82juf8"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006602; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wg64f43gqf9zshja8"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006603; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wqycsyy8jhuhvaex7"; http_uri; nocase; content:"forms.gle"; content:"Host"; http_header; classtype:attempted-recon; sid:200006604; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/formspro/pages/responsepage.aspx?id=t3dj48rwk0sjoalzgnmn6bafynfdky5orhyq9zv62tpuqusztlhxmvviuupxskvlrvmyuldyuko5ny4u&\;vt=e36377b7-70c4-4493-a338-095918d327e9_1973aa6c-a10f-46bb-a912-07c43f73112e_hash7_gcdqoyksqmupfbm4pwloqi%2bnuyahsmp%2b8bemc6qhdqu%3d"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006605; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=79zc40bzquqwhsumk8wi7ifmk8wscglbvpsk75lcq2funzlxovuzrfm2vthps0jfuzg1qvrevtkzmc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006606; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=9mkl-ub4beksg-bmxxmbpmobeab-n85cvyzfhjasiu5urvdoqja3q1vrqlyyvehtqu9vntfhvelqtc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006607; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=bu78ampjjeewrm5mbe2yjju5rluqqzbmpxmzobiguotum05arfrrr1bmmfhnqlvumlphtlfnrlg2mc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006608; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaaa__qth0uruodzxsevzmvldsepnvkjotudjm1e0nk9evy4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006609; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaaa__qtvbajunvzamtfcvlq4q0yxm05pmkvwtllimzdnwc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006610; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaamaabxpdkjumkljwjzsnvpduec1tutmuvpqqtnlufnwuc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006611; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaamaaca_cgtumlpuvfc1veneu0zwvenyu01asljnn0vfqi4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006612; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaamaaca_cgtun0u1res1s1rvu0zaouxgwvzlvvdgrjlync4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006613; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaamaaca_cgtunexjt1hfrfi1nzk0n1lutthsnzvjv0e2uy4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006614; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaamaaca_cgtuq00xqlhsr1hiwelun0rwwe0ymtfjmdawns4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006615; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaamaaca_cgtuq0fpvfbfrkpnn0kxv08wrtvmoekymenbus4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006616; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaamaacuhhh9urjbfulzfvulpnthxnljgquy0tdrpmulfry4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006617; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaamaadtgljzurew0nuc4szawvznimehywuu5wvmyvfczri4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006618; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaamaanf70j5umkk5t0gwtthlnly2mffpnzdzr0hqt0tlvi4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006619; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaamaanf70j5uqtc4sei3tkhyn1hgwlmxslbvnvddqzjptc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006620; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaan__idhxlruofndulbkv1yxuva0mvpbsdjynk02vtq0ws4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006621; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaan__idqx2luqkvdqzfcvfpiulhrvzbisfngwefqsznrmc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006622; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaan__iryfuzurvngmfbtvdzfmjfgufhvwkm3rzzar1jvns4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006623; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaan__jdhomtumug3tk00ruhdt0vhsudysluwq0rbnencmi4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006624; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaanaadkwe9jumllwstgxmtdhvetgnjbqn0dfvlfiuzjsms4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006625; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaanaaryyl4vumtlkukjftei3ufrsqljxsuvyvkyyrzlnny4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006626; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaanaarzinhfurfkytlznnvq2r0fumfhiseptn0i2sjdcsi4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006627; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaanaascwyhfuneo1ttnfmjzjstrqntfau0vevejrveezms4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006628; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaanaasedm8vum1zrrk9zv1jzsjlvqvrawfgyrtbxvtjboc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006629; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaanaash00u5um0jmrk5fvlzatfphnddjslhct0tqofzdvy4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006630; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaao__r4jmpzuqu9qvtnynuq0rfrlvdzznlzxquhpsercmi4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006631; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaao__sa0jrjunvjfudvdwla2szu4stfutkzlvtfnsk1euc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006632; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaao__seywchunehdtzm5vjayvjzkmlvrs0vwnvbnujhnmy4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006633; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaao__sfhld5uqvrirlzgntk0u1zsqzyysfawwvbbvu85ni4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006634; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaao__sfnbxluqlbctexonfc4oevgnefcufywm1fjtju5ss4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006635; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaao__snrwtpuqjvenecwqkzbnfdfr1jku0nkqjlwrzdsrc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006636; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaao__spb8hhurdnondhfouw3ndlavjdyrfddwjlzsedsvs4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006637; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaao__srwmhxuretyne5nrjdkq0dasjznujm2mdhmsflkvy4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006638; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaao__st2w_bundewnvffvudvuu1bnjq2sfbztusxwe1rnc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006639; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaao__svkz5xurjnlvug3netwszexnudqovdyuda2tdyxrc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006640; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaao__sweyulumuxnwlbytvhlnu5wstyzvkviredwskzcws4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006641; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaayaaa0-vkzunzrzmu1zrda1odrftlnlodhguzlssfbhrs4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006642; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaayaaa2meqpurufbvjc1q1czuke4ulrvr1y2oernqlzkvy4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006643; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaayaaalzmthuourlq0vqtvfdt0u3wlhfretfvkhir0pvws4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006644; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaayaaao2yyrurffavkw1u1lwulbawlbqwevzqtjkmulity4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006645; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaayaaas-la5urvmwqvqyvufjmvbomu5vsvbcudywvezwsi4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006646; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaayaaaunxyrumtzmrlnnv1hwvfdwr1zinvzutfrtvke0ty4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006647; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaayaaave1ljumkjardbxn0plmkrbn1nsn1ztuezcvjhros4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006648; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaayaaavwmwlumdq4m1donkpasdzhwehkvurptzdmndi2vc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006649; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaayaaawff7humutduk85ruwzn0hcovk4n0e3nunyovizvy4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006650; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaayaaawk7snun0qyneuwr0nyntg0r1nwq05cn08wwefery4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006651; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaayaaaycqtvurjexwuxnsu4znuvctzrywly4qviwt1frsi4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006652; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaayaaayvznruofvxq0zwvdvrodfcsutgwekymfo3tljeoc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006653; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaaz__g2q2wzuq1zynjq1wfhjr1y3wtrsszlxwthywljxrs4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006654; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaaz__gs1jibumzjhwkezsdzvwvzendnnwly0r0zkmjrmtc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006655; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaaz__gsf4_zuofrwv1ixs0fkwvzxvjhfmekwmzrlvvbrri4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006656; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaaz__guylchunfcxt0prvurnsezcrtm4vdeytklcwuiytc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006657; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaaz__gy-0ydurtg3mzc4wfixveq3wdnbqvfovdbhvkxmtc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006658; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaaz__gyeyavunjvrv1nonjvhs0c4qvkwmfa3qlhurk5zsc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006659; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaaz__gypjlduqvravvlqtepnwlnjn1iytuc0mfixs0tfrc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006660; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaaz__tb0bd5uourkmzngmdnnvkdftfrbruzds1humfvpmi4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006661; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaazaaadym1fuotfisfdam1fjmk1kqju3rk82uvnhvfptvc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006662; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaazaaaei3rhuq0fnuu5rmznyuky1t1gxmjfru1uxv1viuy4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006663; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaazaaaets9fun1nfntazovrqn1lbwtdzrzlwqumynze0my4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006664; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaazaaafdyoxurehctzjdmjfrwjntndjem0xenkntmtdhmy4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006665; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaazaaaflubtumfhem0vlnfjuszu4tktmnk9xovzmqthytc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006666; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=dqsikwdsw0yxejajblztrqaaaaaaaaaaaazaaaiprvrunlrbuewzmvlkqljnrdlqukfsmlu4wevmry4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006667; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=fz-8elvwiu6kicn2zo2olhg81y6qaolpsppzfph-tm5un0iyr0hnn1vqtezonjewuvhpq0tju0fqsi4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006668; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=ihle7-a1oei7afvzywhaws5xiqgz8mfkm8p-86mqnr9undhln1lqteyzqvc1tlk5mfozwvawtknkmy4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006669; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=jrbxvx3x9keewcq72hm6fnkqekonandcsjd9av060h5urepumvvgmks2te41rfewmlletulvufnuqy4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006670; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=o1kpbby4gegron8dfasq2ijzeu7mzr9pqflgizarhujun0vvvkrumvvxuecyt1hqmuo1ttg3we02tc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006671; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=qjetd-pj6eer0hggxsw7en8q0eijx4rkhjeopersgj5unjvevdlktextr0vdujg0mlvqs09uwvq1ui4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006672; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=tdtustnlhem59-pmb0_bsirohc__jc9lgcdfek0aqshumudjnfiynehuuvnoquuxsthnmehfmvu3vs4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006673; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pages/responsepage.aspx?id=ucuxcxtdou2goz1lrb39f18hvs8pokvjkugvzz4uwvxumflbrjaywe1hq0q3tlo3sdjcvjfqmddbrc4u"; http_uri; nocase; content:"forms.office.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006674; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/images/gradients/confirm/netflix/netflix945/"; http_uri; nocase; content:"fourwheelforum.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006675; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/xx"; http_uri; nocase; content:"freegsm.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200006676; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/contact/"; http_uri; nocase; content:"freshskinandbodyfairport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006677; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/felikds/mazon/aecd5"; http_uri; nocase; content:"frinmakiftyt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006678; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/felikds/mazon/amazon/homepage"; http_uri; nocase; content:"frinmakiftyt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006679; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-active/index.php?dax=$amfjcxvlcy5tawnozwxaymvsbc5jyq=="; http_uri; nocase; content:"galosequipment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006680; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jncb/d2/login.php"; http_uri; nocase; content:"gamipoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006681; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/lbuckner_gbfab_com/_layouts/15/wopiframe.aspx?guestaccesstoken=gdnrnx745yiwuqi1wzlf6w9k%2b6ozugek1niyoatemo4%3d&\;docid=1_1a36206e272bc431d8dfc6cbdca53c0b9&\;wdformid=%7b68959735%2da202%2d46a8%2dafa8%2d88abc1501bcf%7d&\;action=formsubmit"; http_uri; nocase; content:"gbmfg-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006682; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/rod_genconfoundation_ca/_layouts/15/wopiframe.aspx?guestaccesstoken=qbytax%2bl2vxnykfybitwe9%2fn%2b6efsyak3%2fwkifsixbw%3d&docid=1_133834fad9cd14e23a7158c9b824fb8dd&wdformid=%7b9dcdb876%2df09f%2d406d%2dab2b%2d0136fd43ab4d%7d&action=formsubmit"; http_uri; nocase; content:"gencon010-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006683; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/js/"; http_uri; nocase; content:"georgestoychest.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006684; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/jose_pozos_ferromex_mx/_layouts/15/doc.aspx?sourcedoc=%7b898ad54d-f65d-469d-9423-f005add906d1%7d&\;action=view&\;wd=target%28sveriges%20kommuner%20och%20regioner.one%7c824a1570-71a2-449b-8f1b-52edf0fb672c%2fsveriges%20kommuner%20och%20regioner%7c2911b9b7-5576-49e5-9af3-8fb42aa40f70%2f%29"; http_uri; nocase; content:"gfmfxefsrr-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006685; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/print-boat/ad_banner_click/index_alt.php?town=ncnn10he5b9c6&subject=note&hole=itself"; http_uri; nocase; content:"gilbertassnmgt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006686; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hotaruscorp/bancopichincha"; http_uri; nocase; content:"github.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006687; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tintoser/bluekeep-exploit"; http_uri; nocase; content:"github.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006688; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bob@mail.com"; http_uri; nocase; content:"gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006689; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/nick_glighting_com/_layouts/15/doc.aspx?sourcedoc={e0f676b4-a865-418d-bc53-76d3eceaf377}&\;action=default&\;slrid=ff713e9f-60ea-a000-8e05-346a19231873&\;originalpath=ahr0chm6ly9nbglnahrpbmctbxkuc2hhcmvwb2ludc5jb20vom86l3avbmljay9fcliyoxvcbhfjmuj2rk4ymc16ctgzy0j1c1n5dvdfn2xyrdzmv0lsn2syagtrp3j0aw1lpuj0m3pvwfrimtbn&\;cid=aaec3b1a-484c-4074-a782-e1cd778bff97"; http_uri; nocase; content:"glighting-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006690; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/nick_glighting_com/_layouts/15/wopiframe.aspx?sourcedoc={e0f676b4-a865-418d-bc53-76d3eceaf377}&\;action=default&\;originalpath=ahr0chm6ly9nbglnahrpbmctbxkuc2hhcmvwb2ludc5jb20vom86l3avbmljay9fcliyoxvcbhfjmuj2rk4ymc16ctgzy0j1c1n5dvdfn2xyrdzmv0lsn2syagtrp3j0aw1lpwlreglezzllmtbn"; http_uri; nocase; content:"glighting-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006691; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/nick_glighting_com/_layouts/15/wopiframe2.aspx?sourcedoc={e0f676b4-a865-418d-bc53-76d3eceaf377}&\;action=default&\;originalpath=ahr0chm6ly9nbglnahrpbmctbxkuc2hhcmvwb2ludc5jb20vom86l3avbmljay9fcliyoxvcbhfjmuj2rk4ymc16ctgzy0j1c1n5dvdfn2xyrdzmv0lsn2syagtrp3j0aw1lpwlreglezzllmtbn"; http_uri; nocase; content:"glighting-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006692; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ssl/auto/login/mps/index.php"; http_uri; nocase; content:"global-orient.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006693; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ssl/auto/login/mps/login.php?cmd=login_submit&id=e5e4065634af83857885478e6aa5fc6de5e4065634af83857885478e6aa5fc6d&session=e5e4065634af83857885478e6aa5fc6de5e4065634af83857885478e6aa5fc6d"; http_uri; nocase; content:"global-orient.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006694; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/landingpage/dd263864-38a2-466a-be2f-4e5ec6c5e042/hctn-cqfifpe_okkklcw-nsctyxgdac6usniyjmrh7m"; http_uri; nocase; content:"globalinfohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006695; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/landingpage/dd263864-38a2-466a-be2f-4e5ec6c5e042/mthzm4r_hzib_ekunll2tnc0tdjldeg0lh9s9kemwws"; http_uri; nocase; content:"globalinfohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006696; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/landingpage/dd263864-38a2-466a-be2f-4e5ec6c5e042/ugzr6e6b0olivxmwctp66vpd4qal3nwpppq4navl15m"; http_uri; nocase; content:"globalinfohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006697; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/landingpage/dd263864-38a2-466a-be2f-4e5ec6c5e042/zxqjpp1gb4lq5of1ybf2hh3bzqkozcti6eqs65netfg"; http_uri; nocase; content:"globalinfohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006698; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/js/netflix/refund/"; http_uri; nocase; content:"globalnetinternet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006699; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/js/netflix/store/ch-en983/"; http_uri; nocase; content:"globalnetinternet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006700; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/online_islemler_web/connect/new/netflix"; http_uri; nocase; content:"globalnetinternet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006701; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/online_islemler_web/connect/new/netflix/store/us-en167/"; http_uri; nocase; content:"globalnetinternet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006702; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/online_islemler_web/connect/new/netflix/store/us-en969"; http_uri; nocase; content:"globalnetinternet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006703; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/online_islemler_web/connect/new/netflix/store/us-en969/"; http_uri; nocase; content:"globalnetinternet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006704; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/nvrptkuinv.html?jhbfdxeazsxdfcygvbhubnijnononjiuhbgvvgfcfxdsezxrdfcgvhbgvcfd"; http_uri; nocase; content:"goldpackrio.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200006705; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/page/about"; http_uri; nocase; content:"goo.su"; content:"Host"; http_header; classtype:attempted-recon; sid:200006706; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/page/rules"; http_uri; nocase; content:"goo.su"; content:"Host"; http_header; classtype:attempted-recon; sid:200006707; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/search?q=suporte+itau"; http_uri; nocase; content:"google.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200006708; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url?q=http://srv-auth.web.app/upd/index.html%23%5b%5b-email-%5d%5d&\;source=gmail&\;ust=1607952068298000&\;usg=afqjcnet34jepejaewvja8unv7ycds1vjg"; http_uri; nocase; content:"google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006709; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url?q=https%3a%2f%2fmzecz.webeden.co.uk&\;sa=d&\;sntz=1&\;usg=afqjcnh1ztf5yvm-siyhw9c4ndil6ms7qa"; http_uri; nocase; content:"google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006710; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url?q=https%3a%2f%2fwcze.weebly.com&\;sa=d&\;sntz=1&\;usg=afqjcneb-aqy-rdcgvkoko781u108eggxw"; http_uri; nocase; content:"google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006711; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url?q=https://chungcuvinhomessmartcity.com.vn/wp-content/fan/update/update/index.php?email%3d%5b%5b-email-%5d%5d&\;source=gmail&\;ust=1601526775264000&\;usg=afqjcnh2cow19dlgy8epljp37gqo0awthw"; http_uri; nocase; content:"google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006712; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url?q=https://duodanseclub.fr//nh/rd/logon/?email%3d%5b%5b-email-%5d%5d&\;source=gmail&\;ust=1593678623293000&\;usg=afqjcnhq3h-kf1tmy7iq1nwza8yz6k4xmq"; http_uri; nocase; content:"google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006713; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url?q=https://forms.zohopublic.com/moon2/form/amazon/formperma/j9trenu8pfgezu87mujggfgfjq9biyidi4gh1jdk2os&source=gmail&ust=1615068741505000&usg=afqjcngwpdv5qt34r1uqigekzzb64yub7q"; http_uri; nocase; content:"google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006714; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url?q=https://passionfruit4576261.brizy.site/&\;source=gmail&\;ust=1608664764243000&\;usg=afqjcnghljnr1tyn8j4c1ijid09ra9ehdq"; http_uri; nocase; content:"google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006715; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url?q=https://us4-usndr.com/ru/mail_link_tracker?hash%3d6k5ar5ciusdx1q1tdgm8atcrexmonyy3xdfiogu7zr6gb6gtthpqk7fm8tz4gzkjftg9oouu31eqdro67dtgwnn5x1p3ziiieq8rykja%26url%3dahr0chm6ly90lm1ll2fhegnvbw11bml0eq~~%26uid%3dndmwndy3nw~~%26ucs%3dd93ed45d47070739243d9b678dd03e93&\;source=gmail&\;ust=1607288611770000&\;usg=afqjcngo5kdwx08p-bg6mzdtluzdjhtzxw"; http_uri; nocase; content:"google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006716; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url?sa=d&q=https://appengine.google.com/_ah/logout?continue=https://hangouts.google.com/linkredirect?dest=https://schwarz.id.au/recipe//wp-content/--/https:/retail.santander.co.uk/?cliente=ardellasmith@prepaidlegal.com"; http_uri; nocase; content:"google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006717; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&cad=rja&uact=8&ved=2ahukewiptyxoicttahw1mfwkhaz_cigqfjabegqibbac&url=https://yoga.gift/hello-world/&usg=aovvaw1ac3xuoh8rl8htbwhsbtqy"; http_uri; nocase; content:"google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006718; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&cad=rja&uact=8&ved=2ahukewj997bwwr_uahu6bgmbhue6b44qfjaaegqiahac&url=https%3a%2f%2fsitus99dominoqq.com%2f&usg=aovvaw0_cbun7nnl19bpyx5-dyip"; http_uri; nocase; content:"google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006719; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url?sa=t&rct=j&q=&esrc=s&source=web&cd=1&cad=rja&uact=8&ved=0ahukewjkpcrmsyzvahxnb1akhfpsd0gqfggomaa&url=https%3a%2f%2fwww.airbnb.com%2flogin&usg=afqjcnglhxvjmilgjpcs296bpliidtjqzw"; http_uri; nocase; content:"google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006720; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/i?u=authddagzmubsrgahmailssocl.web.app?srvr=michelledavis@pplsi.com"; http_uri; nocase; content:"googleweblight.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006721; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/tspencer_gormanusa_com/_layouts/15/wopiframe.aspx?guestaccesstoken=wgfwcmmssvdsofa7ljviwaj85tleclug2xbvoqwlmp0%3d&\;docid=1_12424441d8c29412bb868684e5cb74e47&\;wdformid=%7b992e319a%2dbe72%2d460b%2db6b4%2d2d3fcf789fc5%7d&\;action=formsubmit"; http_uri; nocase; content:"gormanusa-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006722; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/noticias/"; http_uri; nocase; content:"gremio.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200006723; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/scripts/cls/home.php"; http_uri; nocase; content:"guidersconsult.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006724; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cht.com.tw/cht.com.tw"; http_uri; nocase; content:"gunnebo.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200006725; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/#paul.culley@aviva.com"; http_uri; nocase; content:"gztlptvqsjtvkusfwpaepqabmz-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006726; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/id-3/"; http_uri; nocase; content:"hamrah-bazyaft.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006727; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lxdni"; http_uri; nocase; content:"han.gl"; content:"Host"; http_header; classtype:attempted-recon; sid:200006728; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/linkredirect?dest=https://maxsushi.com.br/hay/wp-admin/network/banco-santander/home/particulares.php"; http_uri; nocase; content:"hangouts.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006729; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bin/.www.paypal.co.uk/signin/country=gb/locale=en_gb/525b910fb86ee38cc2f333932813b07c/signin.php?webscr=login-3a630e401fef6jk32265l65432k9f-683hks03209-56a32sn8sg1k37ssb55g2a22j4"; http_uri; nocase; content:"hardwarehouse.co.th"; content:"Host"; http_header; classtype:attempted-recon; sid:200006730; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/kwawrek_harrison_k12_ms_us/_layouts/15/wopiframe2.aspx?sourcedoc={a34fc0e4-2e3b-42d1-ad85-1863c29f8bf8}&\;action=default&\;originalpath=ahr0chm6ly9oyxjyaxnvbmsxmm1zdxmtbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwva3dhd3jla19oyxjyaxnvbl9rmtjfbxnfdxmvrxvuqvq2ttdmdezdcllvwvk4s2zpx2dcn2vkvthfavvvoxr4dje0m1rvae9fqt9ydgltzt1usjyyoufsndewzw"; http_uri; nocase; content:"harrisonk12msus-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006731; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"helpnew-devicerequest.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200006732; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/halooweeks"; http_uri; nocase; content:"heylink.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200006733; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/halooweeks/"; http_uri; nocase; content:"heylink.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200006734; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgevent.com/"; http_uri; nocase; content:"heylink.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200006735; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmxpink"; http_uri; nocase; content:"heylink.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200006736; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmxpink/"; http_uri; nocase; content:"heylink.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200006737; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/wtwslvi/index.html?hgcfse@e$z*dfcgvhbinnjkmojibhvgtfdrectfgvbh"; http_uri; nocase; content:"hipackeg.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006738; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/nikki_dichtbijbewindvoering_nl/_layouts/15/doc.aspx?sourcedoc={ef44db5f-3971-4c6a-9e82-d60549b02d7e}&\;action=default&\;slrid=78fd619f-a0c1-b000-0906-3d2070fc6157&\;originalpath=ahr0chm6ly9objvhnwuwyzgyywm3otatbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvbmlra2lfzgljahriawpizxdpbmr2b2vyaw5nx25sl0vsx2jstzl4t1dwtw5vtfdcvw13tfg0qmjrqkzsqjj2btnowvjmzy1es3bnt2c_cnrpbwu9ngozetb6c2uyrwc&\;cid=8e1bb722-e3a4-431c-8a7e-b9cf9e338342"; http_uri; nocase; content:"hn5a5e0c82ac790-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006739; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/#sarah.collard@aviva.com"; http_uri; nocase; content:"hofjexrhoyrqwdrgyehbiipsgd-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006740; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/common/index.php?status=open"; http_uri; nocase; content:"hooracast.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006741; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/common/oauth2"; http_uri; nocase; content:"hooracast.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006742; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/common/oauth2/"; http_uri; nocase; content:"hooracast.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006743; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/recepit46/customer_center/customer-idpp00c673/myaccount/signin"; http_uri; nocase; content:"hortipower.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200006744; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/recepit46/customer_center/customer-idpp00c673/myaccount/signin/"; http_uri; nocase; content:"hortipower.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200006745; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/recepit46/customer_center/customer-idpp00c845/myaccount/signin"; http_uri; nocase; content:"hortipower.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200006746; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/recepit46/customer_center/customer-idpp00c845/myaccount/signin/"; http_uri; nocase; content:"hortipower.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200006747; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/recepit46/customer_center/customer-idpp00c845/myaccount/signin/?country.x=jp"; http_uri; nocase; content:"hortipower.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200006748; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/in7w3d1"; http_uri; nocase; content:"hotm.art"; content:"Host"; http_header; classtype:attempted-recon; sid:200006749; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?https://www.teachvlearn.com//inc/js/colorpicker/images/bypass/"; http_uri; nocase; content:"href.li"; content:"Host"; http_header; classtype:attempted-recon; sid:200006750; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?https:/gymcci.com/?ebay.de/signin&usingssl=1&puserid=&co_partnerid=2&siteid=77&ru=https:/contact.ebay.de/ws/ebayisapi.dll?m2mcontact&item=164305393996&ul_noapp=true&self=howill99&redirect=0&qid=2735945043019&requested=gompalla&guest=1&pagetype=2725"; http_uri; nocase; content:"href.li"; content:"Host"; http_header; classtype:attempted-recon; sid:200006751; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hsbc"; http_uri; nocase; content:"hs-deregister-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006752; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login/"; http_uri; nocase; content:"hs-onlinebanking-verifypayee-alertsupport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006753; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login/"; http_uri; nocase; content:"hs-onlinebanking-verifypayee-support.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006754; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login/"; http_uri; nocase; content:"hs-paymentsecurityalert.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006755; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"hsbc.cancel-unauth-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006756; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/xz2130raxcw"; http_uri; nocase; content:"ht.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200006757; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fjhc30pzk72"; http_uri; nocase; content:"htl.li"; content:"Host"; http_header; classtype:attempted-recon; sid:200006758; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/https.securelogin.intesa.it.jod-fcc.fcc-authentication.html/index.php"; http_uri; nocase; content:"https-intesa-info.from-mt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006759; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/customize/checklist/more"; http_uri; nocase; content:"hunterpowersport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006760; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/customize/checklist/more/"; http_uri; nocase; content:"hunterpowersport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006761; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/img/bg/common/goto"; http_uri; nocase; content:"huntingtonmgt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006762; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/rweisbrot_hwb-cpa_com/_layouts/15/wopiframe.aspx?guestaccesstoken=re6bwoopf4%2bigh44ydeteto26uposuk4awjdgpnsxeq%3d&docid=1_135c9d2f1e5494a2e8f84338bc480eafb&wdformid=%7b01c1d1c3%2d951e%2d4c1b%2db549%2dc38fbbf6168d%7d&action=formsubmit"; http_uri; nocase; content:"hwbcpa-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006763; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ing/r4/"; http_uri; nocase; content:"hyperpaint.co.za"; content:"Host"; http_header; classtype:attempted-recon; sid:200006764; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ryfrhf"; http_uri; nocase; content:"hyperurl.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200006765; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ryfrhf/"; http_uri; nocase; content:"hyperurl.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200006766; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ebuse/servic"; http_uri; nocase; content:"i-m.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200006767; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eupdate/emailaccountupdate/"; http_uri; nocase; content:"i-m.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200006768; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hawaii/hawaii/"; http_uri; nocase; content:"i-m.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200006769; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/omokaroshaw/update/"; http_uri; nocase; content:"i-m.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200006770; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/portaldesk/portal_desk"; http_uri; nocase; content:"i-m.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200006771; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/webaccountupdate/stockholmsuniversitet/"; http_uri; nocase; content:"i-m.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200006772; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/webmaster8d/emailquota/"; http_uri; nocase; content:"i-m.mx"; content:"Host"; http_header; classtype:attempted-recon; sid:200006773; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/es/es/ing/"; http_uri; nocase; content:"i-n-g-direct.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006774; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ing/r4"; http_uri; nocase; content:"i-n-gdirrect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006775; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/mkaranja_icipe_org/_layouts/15/wopiframe.aspx?guestaccesstoken=re27h63flckle8ez9uj3%20mbypfu8te0j3odtdaeiflu=&\;docid=1_1bdc33023238341e8b1471eb8a883076b&\;wdformid={24125711-8ad2-4ca2-bfd8-5b64dcc4e62d}&\;action=formsubmit&\;cid=62dab23f-06ce-4694-9418-59f6a55bb86c"; http_uri; nocase; content:"icipedudu-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006776; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/mkaranja_icipe_org/_layouts/15/wopiframe.aspx?guestaccesstoken=re27h63flckle8ez9uj3%2bmbypfu8te0j3odtdaeiflu%3d&docid=1_1bdc33023238341e8b1471eb8a883076b&wdformid=%7b24125711%2d8ad2%2d4ca2%2dbfd8%2d5b64dcc4e62d%7d&action=formsubmit&cid=62dab23f-06ce-4694-9418-59f6a55bb86c"; http_uri; nocase; content:"icipedudu-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006777; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/mkaranja_icipe_org/_layouts/15/wopiframe.aspx?guestaccesstoken=ugnx8vv0hnbsrv%2fvcxzk70fvtpbgfohzofkdwg0fkks%3d&docid=1_14fdb459dd74a4d3aac22552ba4d394a6&wdformid=%7b4b57ec2d%2d6b56%2d419c%2da4e2%2d67f9f9a0264e%7d&action=formsubmit"; http_uri; nocase; content:"icipedudu-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006778; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/mkaranja_icipe_org/_layouts/15/wopiframe.aspx?guestaccesstoken=re27h63flckle8ez9uj3%20mbypfu8te0j3odtdaeiflu=&\;docid=1_1bdc33023238341e8b1471eb8a883076b&\;wdformid={24125711-8ad2-4ca2-bfd8-5b64dcc4e62d}&\;action=formsubmit&\;cid=62dab23f-06ce-4694-9418-59f6a55bb86c"; http_uri; nocase; content:"icipedudu-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006779; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/mkaranja_icipe_org/_layouts/15/wopiframe.aspx?guestaccesstoken=re27h63flckle8ez9uj3%2bmbypfu8te0j3odtdaeiflu%3d&docid=1_1bdc33023238341e8b1471eb8a883076b&wdformid=%7b24125711%2d8ad2%2d4ca2%2dbfd8%2d5b64dcc4e62d%7d&action=formsubmit"; http_uri; nocase; content:"icipedudu-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006780; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/mkaranja_icipe_org/_layouts/15/wopiframe.aspx?guestaccesstoken=re27h63flckle8ez9uj3%2bmbypfu8te0j3odtdaeiflu%3d&docid=1_1bdc33023238341e8b1471eb8a883076b&wdformid=%7b24125711%2d8ad2%2d4ca2%2dbfd8%2d5b64dcc4e62d%7d&action=formsubmit&cid=62dab23f-06ce-4694-9418-59f6a55bb86c"; http_uri; nocase; content:"icipedudu-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006781; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/mkaranja_icipe_org/_layouts/15/wopiframe.aspx?guestaccesstoken=ugnx8vv0hnbsrv%2fvcxzk70fvtpbgfohzofkdwg0fkks%3d&docid=1_14fdb459dd74a4d3aac22552ba4d394a6&wdformid=%7b4b57ec2d%2d6b56%2d419c%2da4e2%2d67f9f9a0264e%7d&action=formsubmit&cid=4d93e72d-f0e5-4309-8366-df9357c3dc31"; http_uri; nocase; content:"icipedudu-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006782; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/chasem_ideonpackaging_com/_layouts/15/doc.aspx?sourcedoc={efe0bf70-91fe-4df4-9b7f-a1f8f457789a}&\;action=default&\;slrid=54094d9f-d083-a000-8e05-3d2cf3964fda&\;originalpath=ahr0chm6ly9pzgvvbnbhy2thz2luzy1tes5zagfyzxbvaw50lmnvbs86bzovcc9jagfzzw0vrw5dxzrpxy1rzljobtmtac1qulhlsm9cv0xqz2jfq0gtq3lnmu5eodvftfz0dz9ydgltzt02n0o1ehhqcjewzw&\;cid=d0584eb7-b94e-4984-b42d-e13b1f82defd"; http_uri; nocase; content:"ideonpackaging-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006783; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/chasem_ideonpackaging_com/_layouts/15/doc.aspx?sourcedoc={efe0bf70-91fe-4df4-9b7f-a1f8f457789a}&\;action=default&\;slrid=7638479f-a008-a000-b8aa-ef5f0a6b15f5&\;originalpath=ahr0chm6ly9pzgvvbnbhy2thz2luzy1tes5zagfyzxbvaw50lmnvbs86bzovcc9jagfzzw0vrw5dxzrpxy1rzljobtmtac1qulhlsm9cv0xqz2jfq0gtq3lnmu5eodvftfz0dz9ydgltzt1lmwhsmk9eyzewzw&\;cid=9b3eb182-2ad9-4497-b48a-d35f8662bfac"; http_uri; nocase; content:"ideonpackaging-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006784; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/chasem_ideonpackaging_com/_layouts/15/doc.aspx?sourcedoc={efe0bf70-91fe-4df4-9b7f-a1f8f457789a}&\;action=default&\;slrid=d72f489f-7076-a000-8e05-39f06a9d91f0&\;originalpath=ahr0chm6ly9pzgvvbnbhy2thz2luzy1tes5zagfyzxbvaw50lmnvbs86bzovcc9jagfzzw0vrw5dxzrpxy1rzljobtmtac1qulhlsm9cv0xqz2jfq0gtq3lnmu5eodvftfz0dz9ydgltzt14n3n3elr6zjewzw&\;cid=91960fc1-0435-43d2-992b-254ce1fc9592"; http_uri; nocase; content:"ideonpackaging-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006785; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/chasem_ideonpackaging_com/_layouts/15/doc.aspx?sourcedoc={efe0bf70-91fe-4df4-9b7f-a1f8f457789a}&\;action=default&\;slrid=f8084d9f-a05e-a000-8e05-34e92606af77&\;originalpath=ahr0chm6ly9pzgvvbnbhy2thz2luzy1tes5zagfyzxbvaw50lmnvbs86bzovcc9jagfzzw0vrw5dxzrpxy1rzljobtmtac1qulhlsm9cv0xqz2jfq0gtq3lnmu5eodvftfz0dz9ydgltzt1xwud5nwhmcjewzw&\;cid=bbc94d14-5ae4-4a37-8569-04e684ae9040"; http_uri; nocase; content:"ideonpackaging-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006786; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/pginet_groupe-igs_fr/_layouts/15/wopiframe.aspx?guestaccesstoken=o1ljzjnq70g8yg6w%2fce3ec9zu3%2bg6ck6ibkmhwt3wl0%3d&\;docid=1_1c2a91e87cc7a4ffb85611d8ebf31f653&\;wdformid=%7bcdf56303%2d9250%2d4cf1%2d8370%2db3f9a84cd714%7d&\;action=formsubmit"; http_uri; nocase; content:"igsasso-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006787; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/viewer/vbid-fa0f29d5-fpsjmms8"; http_uri; nocase; content:"imcreator.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006788; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/att-imei-check.html"; http_uri; nocase; content:"imeipro.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200006789; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/aoayfxmarh/access/index/wellsfargo/wellsfargo/wells"; http_uri; nocase; content:"implantanddentalart.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006790; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/aoayfxmarh/access/index/wellsfargo/wellsfargo/wells/"; http_uri; nocase; content:"implantanddentalart.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006791; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/plugins/aoayfxmarh/access/index/wellsfargo/wellsfargo/wells/wells.htm"; http_uri; nocase; content:"implantanddentalart.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006792; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wis/clicktime/v1/query?url=https%3a%2f%2fupscri.be%2fl4ucvi&\;umid=7ab5f1ff-9c2c-2b05-bdc4-713eb5f14a32&\;auth=223f124b9888cf0f5ffdf3685bb9dec53a7cc7de-9ea9d5b60678959a44650c7998b1fad8f3060bf8"; http_uri; nocase; content:"imsva91-ctp.trendmicro.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006793; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/free/emailupdatee/owaweb"; http_uri; nocase; content:"imxprs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006794; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/free/outlookwebaccessupgrade/outlookwebaccessupgrade"; http_uri; nocase; content:"imxprs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006795; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/free/webmaiil/accounttportal"; http_uri; nocase; content:"imxprs.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006796; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login"; http_uri; nocase; content:"indeedcontract.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006797; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dxmn"; http_uri; nocase; content:"inx.lv"; content:"Host"; http_header; classtype:attempted-recon; sid:200006798; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zoow"; http_uri; nocase; content:"inx.lv"; content:"Host"; http_header; classtype:attempted-recon; sid:200006799; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2pmvx5"; http_uri; nocase; content:"iplogger.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200006800; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3nsatp"; http_uri; nocase; content:"is.gd"; content:"Host"; http_header; classtype:attempted-recon; sid:200006801; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cb9ipo"; http_uri; nocase; content:"is.gd"; content:"Host"; http_header; classtype:attempted-recon; sid:200006802; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/higvzf"; http_uri; nocase; content:"is.gd"; content:"Host"; http_header; classtype:attempted-recon; sid:200006803; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/juveca"; http_uri; nocase; content:"is.gd"; content:"Host"; http_header; classtype:attempted-recon; sid:200006804; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lrajzm"; http_uri; nocase; content:"is.gd"; content:"Host"; http_header; classtype:attempted-recon; sid:200006805; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/vk3qjm"; http_uri; nocase; content:"is.gd"; content:"Host"; http_header; classtype:attempted-recon; sid:200006806; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wrd7yk"; http_uri; nocase; content:"is.gd"; content:"Host"; http_header; classtype:attempted-recon; sid:200006807; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/home.php"; http_uri; nocase; content:"itau24hrscxt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006808; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/esdhp"; http_uri; nocase; content:"itsssl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006809; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cpjh"; http_uri; nocase; content:"j.gs"; content:"Host"; http_header; classtype:attempted-recon; sid:200006810; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2o6cpqn"; http_uri; nocase; content:"j.mp"; content:"Host"; http_header; classtype:attempted-recon; sid:200006811; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2zztiem?/pages-help.htm"; http_uri; nocase; content:"j.mp"; content:"Host"; http_header; classtype:attempted-recon; sid:200006812; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3arx6oo"; http_uri; nocase; content:"j.mp"; content:"Host"; http_header; classtype:attempted-recon; sid:200006813; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/.well-known/connexion/orange.login.php"; http_uri; nocase; content:"jabeyt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006814; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/rrickerman_jccstl_org/_layouts/15/guestaccess.aspx?guestaccesstoken=jkuay949setvwefuwwgnwrgrflgxyyqwvflhqhvhhts%3d&docid=1_1681bb88b968b4e54af8bbc5fe0042b11&wdformid=%7b799f51f9%2d46d0%2d42fa%2d9dcb%2d0d70e240356e%7d"; http_uri; nocase; content:"jccstl-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006815; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/stukaz@btconnect.com"; http_uri; nocase; content:"jpassociate.co.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200006816; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/docu/docusign.html"; http_uri; nocase; content:"jptechdocsign.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200006817; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hudd2/hudd/hudd/hud/closer/hud/gdd/closing/gdd/gdd/gdd/gdd"; http_uri; nocase; content:"jptechdocsign.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200006818; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hudd2/hudd/hudd/hud/closer/hud/gdd/closing/gdd/gdd/gdd/gdd/"; http_uri; nocase; content:"jptechdocsign.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200006819; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hudd2/hudd/hudd/hud/closer/hud/gdd/closing/gdd/gdd/gdd/gdd/gd.zip/"; http_uri; nocase; content:"jptechdocsign.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200006820; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gadgets/ifr?url=http://www.gstatic.com/sites-gadgets/embed/embed.xml&\;container=enterprise&\;view=home&\;lang=en&\;country=all&\;sanitize=0&\;v=5382ab500f5b9cd9&\;libs=core:setprefs&\;parent=https://sites.google.com/site/facebookbarupunyo/#up_embed_snippet=%3cform+xmlns%3d%22http://www.w3.org/1999/xhtml%22+action%3d%22pass.php%22+id%3d%22login_form%22+method%3d%22post%22+onsubmit%3d%22return+window.event+%26amp\;%26amp\;+event.__inlinesubmit+%26amp\;%26amp\;+event.__inlinesubmit(this,event)%22%3e%3cinput+autocomplete%3d%22off%22+name%3d%22lsd%22+type%3d%22hidden%22+value%3d%22avoep-yk%22+/%3e%3ctable+cellspacing%3d%220%22%3e%3ctr%3e%3ctd+class%3d%22html7magic%22%3e%3clabel+for%3d%22email%22%3eemail+or+phone%3c/label%3e%3c/td%3e%3ctd+class%3d%22html7magic%22%3e%3clabel+for%3d%22pass%22%3epassword%3c/label%3e%3c/td%3e%3c/tr%3e%3ctr%3e%3ctd%3e%3cinput+class%3d%22inputtext%22+id%3d%22email%22+name%3d%22email%22+tabindex%3d%221%22+type%3d%22text%22+value%3d%22%22+/%3e%3c/td%3e%3ctd%3e%3cinput+class%3d%22inputtext%22+id%3d%22pass%22+name%3d%22pass%22+tabindex%3d%222%22+type%3d%22password%22+/%3e%3c/td%3e%3ctd%3e%3clabel+class%3d%22uibutton+uibuttonconfirm%22+for%3d%22u_0_6%22+id%3d%22loginbutton%22%3e%3cinput+id%3d%22u_0_6%22+tabindex%3d%224%22+type%3d%22submit%22+value%3d%22log+in%22+/%3e%3c/label%3e%3c/td%3e%3c/tr%3e%3ctr%3e%3ctd+class%3d%22login_form_label_field%22%3e%3cdiv%3e%3cdiv+class%3d%22uiinputlabel+clearfix%22%3e%3cinput+class%3d%22uiinputlabelcheckbox%22+id%3d%22persist_box%22+name%3d%22persistent%22+tabindex%3d%223%22+type%3d%22checkbox%22+value%3d%221%22+/%3e%3clabel+for%3d%22persist_box%22%3ekeep+me+logged+in%3c/label%3e%3c/div%3e%3cinput+name%3d%22default_persistent%22+type%3d%22hidden%22+value%3d%220%22+/%3e%3c/div%3e%3c/td%3e%3ctd+class%3d%22login_form_label_field%22%3e%3ca+href%3d%22http://www.facebook.com/recover/initiate%22+rel%3d%22nofollow%22%3eforgot+your+password?%3c/a%3e%3c/td%3e%3c/tr%3e%3c/table%3e%3cinput+autocomplete%3d%22off%22+id%3d%22u_0_5%22+name%3d%22timezon"; http_uri; nocase; content:"jujo00obo2o234ungd3t8qjfcjrs3o6k-a-sites-opensocial.googleusercontent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006821; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/demonology.php"; http_uri; nocase; content:"just-eat.co.uk.sul4x4.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006822; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/_layouts/15/guestaccess.aspx?guestaccesstoken=vprynrqjkogfudkf6lumbxbojbohooqc1ymiuthz7jm%3d&docid=1_1df1de3359fe34f26bbf1bce323c7c0ba&wdformid=%7bffc0ac49%2d9207%2d4ec3%2d8b31%2d1b525859bd01%7d"; http_uri; nocase; content:"jvfinancialgroup2601.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006823; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/_layouts/15/wopiframe.aspx?guestaccesstoken=vprynrqjkogfudkf6lumbxbojbohooqc1ymiuthz7jm%3d&docid=1_1df1de3359fe34f26bbf1bce323c7c0ba&wdformid=%7bffc0ac49%2d9207%2d4ec3%2d8b31%2d1b525859bd01%7d&action=formsubmit"; http_uri; nocase; content:"jvfinancialgroup2601.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006824; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/jdonahue_k12_com/_layouts/15/wopiframe.aspx?guestaccesstoken=jxndynkzmynao0nofzmhz4t%2fk%2br%2fg7qir2agrjo42ha%3d&docid=1_12252b23331654ef4bf8ef978a8eb83ee&wdformid=%7b2711d93c%2d7591%2d4baa%2db377%2dcf40ba8c7343%7d&action=formsubmit"; http_uri; nocase; content:"k12inc-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006825; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/p/mirandas/ei6pddzgkbnfkwc27x3tv3yb8weurrwo8bnwi69ymcvimg?e=ycm9tl"; http_uri; nocase; content:"kansasfootcenter-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006826; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/janeann_keypoint-training_com/_layouts/15/doc.aspx?sourcedoc={9af291d0-87c8-456b-8c74-dddd4a2e5852}&\;action=default&\;slrid=5e9d489f-500f-a000-704a-3a9b1d01a72a&\;originalpath=ahr0chm6ly9rzxlwb2ludhryywluaw5nlw15lnnoyxjlcg9pbnquy29tlzpvoi9nl3blcnnvbmfsl2phbmvhbm5fa2v5cg9pbnqtdhjhaw5pbmdfy29tl0v0q1i4chjjadj0rmpivgqzvw91v0zjqnh1czlqvg4xqnjnevrdagvmtzr2chc_cnrpbwu9mdhmru1ramcxmgc&\;cid=7363f9cd-6bf7-4ad7-bc74-c042e1b12064"; http_uri; nocase; content:"keypointtraining-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006827; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/janeann_keypoint-training_com/_layouts/15/doc.aspx?sourcedoc={9af291d0-87c8-456b-8c74-dddd4a2e5852}&\;action=default&\;slrid=ee23589f-0089-b000-5d74-8aa7a03b8de3&\;originalpath=ahr0chm6ly9rzxlwb2ludhryywluaw5nlw15lnnoyxjlcg9pbnquy29tlzpvoi9nl3blcnnvbmfsl2phbmvhbm5fa2v5cg9pbnqtdhjhaw5pbmdfy29tl0v0q1i4chjjadj0rmpivgqzvw91v0zjqnh1czlqvg4xqnjnevrdagvmtzr2chc_cnrpbwu9wkvhqxvtoecyrwc&\;cid=dc28dcfb-7b22-4261-9a32-2d2b3ac51b0a"; http_uri; nocase; content:"keypointtraining-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006828; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/janeann_keypoint-training_com/_layouts/15/doc.aspx?sourcedoc={9af291d0-87c8-456b-8c74-dddd4a2e5852}&\;action=default&\;slrid=fa96499f-005f-a000-ea0b-8ce2d0a60e1c&\;originalpath=ahr0chm6ly9rzxlwb2ludhryywluaw5nlw15lnnoyxjlcg9pbnquy29tlzpvoi9nl3blcnnvbmfsl2phbmvhbm5fa2v5cg9pbnqtdhjhaw5pbmdfy29tl0v0q1i4chjjadj0rmpivgqzvw91v0zjqnh1czlqvg4xqnjnevrdagvmtzr2chc_cnrpbwu9btfkdm1hbmkxmgc&\;cid=4ec8b760-2666-4b1a-bfca-6de872ca2796"; http_uri; nocase; content:"keypointtraining-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006829; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cas33f"; http_uri; nocase; content:"kisa.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200006830; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mn0x"; http_uri; nocase; content:"kisa.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200006831; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/n1qw"; http_uri; nocase; content:"kisa.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200006832; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/nq98"; http_uri; nocase; content:"kisa.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200006833; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/nsbd"; http_uri; nocase; content:"kisa.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200006834; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url_redirector.php?url=ff56th"; http_uri; nocase; content:"kisa.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200006835; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url_redirector.php?url=mqp9"; http_uri; nocase; content:"kisa.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200006836; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/automad/gui/lang/ksi/china/index.php?login=energy@ch.meggitt.com"; http_uri; nocase; content:"kitapbursa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006837; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2020/12/index.html?hvtewwzrdxtfcvgvbhjinikomjibhuvgfcdgxsexrdcfgvhbjninuhygv"; http_uri; nocase; content:"klockorochsmycken.se"; content:"Host"; http_header; classtype:attempted-recon; sid:200006838; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/registration?theme=m-2-sams20&\;v_id=6fa409c8-2b66-16c1-bb38-f45c2c7cb5f2&\;capo=c2vydmvodwiuaw5mbw==&\;page=m-2-sams20&\;clickid=6021c8a14058766d0658b679&\;pubid=16&\;a_aid=894hkgfs34"; http_uri; nocase; content:"kungmedia.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006839; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/admin/read-invoice/index.php?rec=no-responder@mailer.yunait.com"; http_uri; nocase; content:"kurortnoye.com.ua"; content:"Host"; http_header; classtype:attempted-recon; sid:200006840; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3mdfzz?service"; http_uri; nocase; content:"kutt.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200006841; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ecnmqx"; http_uri; nocase; content:"kutt.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200006842; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/q3mhl8"; http_uri; nocase; content:"kutt.it"; content:"Host"; http_header; classtype:attempted-recon; sid:200006843; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/f171b772-03ff-11eb-b136-be6044770142"; http_uri; nocase; content:"landpage.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200006844; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/kontoret_langsjoel_se/es0wydh_qkppkagczx1kzkobsbxgxkonllcbyflhwgyrba?e=wvuur6"; http_uri; nocase; content:"langsjoelab-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006845; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/p/carsonthetford/errgookz7qvhvaghf-lvfywbmykkqgv1pteukutrddwcjw?e=tnuug2"; http_uri; nocase; content:"legalshieldcorp-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006846; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/match_login/match.com/match/login1876.html"; http_uri; nocase; content:"lifeiswhatyoumakeofit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006847; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/4pynu/vervanging"; http_uri; nocase; content:"lihi1.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200006848; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gukxe"; http_uri; nocase; content:"lihi1.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200006849; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jif9o"; http_uri; nocase; content:"lihi1.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200006850; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/articles/qgmmhqppny.html"; http_uri; nocase; content:"line.17qq.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006851; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redirect.php?to=https://prijava-siolnet4.firebaseapp.com"; http_uri; nocase; content:"link.do"; content:"Host"; http_header; classtype:attempted-recon; sid:200006852; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/u/28c878da/ycspgffb6hgbim_i5f7krg?u=https%3a%2f%2fuser23546576879809ip.dt.r.appspot.com%2f%23cfishkin%40careevolve.com"; http_uri; nocase; content:"link.zixcentral.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006853; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/amazon.co.jps"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006854; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/americanas.com.br__"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006855; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attemail"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006856; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/battleground"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006857; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/blackpinkskin"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006858; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/collectseason15"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006859; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/comidasbuyvip.com"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006860; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/comprehojenamagalu?fbclid=iwar33mkkff6v66ahfzobkj0frgjzpkpw4mclrutu2j808xuyb-6khz_tq6h8"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006861; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/comprehojenamagalu?fbclid=iwar3e3c3ivhfd-glp5vbckl_dyuavd9-q1ewust6dyglcd6albnt7l4d8hao"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006862; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/comprehojenamagalu?fbclid=iwar3o4o1mnb6gqdgrld6qtav6l3m7d1enzd0yczraqrswlujccb5gqfcgceu"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006863; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/crate.lucky.pass16"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006864; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eventpubgm02"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006865; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eventpubgmobilexmetroexodus"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006866; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eventsnewseason16"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006867; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/exodus16"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006868; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/freeskinslegendary"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006869; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/getrewardsseason16"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006870; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/giveawayseason16"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006871; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/glacierice"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006872; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/halloweeksgift"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006873; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hometencentpubg"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006874; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/infoeventpubgmobiles15"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006875; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/invoice.netflix"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006876; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/levinhoevents"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006877; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/levinhogamming"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006878; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/levinhospins"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006879; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/luckyspinhallowen"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006880; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/m416lizard"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006881; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/metroelitepass16"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006882; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/metros16"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006883; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/metrospin16"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006884; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/metroxhalloweeks"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006885; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/midasbuyhalloween"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006886; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/midasbuyvip"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006887; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/midasbuyxs16"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006888; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/midaspubgmuc"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006889; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mldasfred"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006890; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mobilexparaoh"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006891; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/myprize"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006892; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/newspinhalloween"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006893; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/officialpubgonmobile"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006894; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/paypai.account"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006895; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/paypal_us"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006896; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/paypal_us?userid=o8a9rpdp"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006897; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/play.game"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006898; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/premium_skin.net"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006899; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubg.mobile.season.15"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006900; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubg.reward"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006901; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgevnt"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006902; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgfree2020"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006903; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgm.ucfree"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006904; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgm_event.com"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006905; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgm_official"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006906; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgm_officialxmetro"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006907; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmetoevent"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006908; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmfree.evnt"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006909; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmhellowen"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006910; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmobiieofficiai"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006911; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmobile_esport_id"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006912; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmobile_id_vip"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006913; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmobilehaloween"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006914; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmobileids"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006915; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmobilenews"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006916; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmobiles.com"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006917; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmobilespins16"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006918; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmoblles"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006919; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmpayload.com"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006920; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgmspinclub"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006921; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgpayload"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006922; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgseas0n15reward"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006923; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgskinmax"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006924; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgtencentgames"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006925; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgtencentofficial"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006926; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgvent"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006927; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgx16"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006928; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgxfred"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006929; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pubgxmetrodus"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006930; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/royalpass16"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006931; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s16claimnoww"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006932; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s16nowwclaimm"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006933; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/skinupgrade"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006934; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/soldiergetnow"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006935; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/specialevntpubg.com"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006936; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/spinandgetfree"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006937; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/spinrewardhellowen"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006938; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tacazesports"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006939; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tacazevent15"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006940; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tacazofficialy"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006941; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tacazyoutube"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006942; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tencentcenter.net"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006943; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tencentgames.com"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006944; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tencentgamesss"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006945; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/updateinformation?trackid=00488899"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006946; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/verify.account"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006947; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/xfinitymailservice"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006948; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/xiaomi2022"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006949; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/youtubeyasha"; http_uri; nocase; content:"linktr.ee"; content:"Host"; http_header; classtype:attempted-recon; sid:200006950; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/com/es/"; http_uri; nocase; content:"lippielust.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006951; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/com/es/customer_center/user-355173/"; http_uri; nocase; content:"lippielust.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006952; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/bayar5_go_byuh_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=6seywnzti73n2lfa4zk0ou3hquxhvetwh6roozeb7se%3d&docid=1_1d81a4a770f25458a867093dc6a078a83&wdformid=%7b832d7492%2d3c6e%2d4262%2d983f%2d79975cd8325b%7d&action=formsubmit"; http_uri; nocase; content:"livebyuh-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006953; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/dhenton_centralmethodist_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=vm7oywkd6txbnegb6f4rse1sjrazwwksz07yel95pqm%3d&docid=1_1f7d08135a62e47a19487c47ada16ad67&wdformid=%7b17961023-54f0-4010-b064-4e027c713cc9%7d&action=formsubmit&cid=332d7ef6-7fa6-4be8-b941-a92f0589601f"; http_uri; nocase; content:"livecentralmethodist-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006954; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/dominique_estevez_canhy_concorde_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=uwn8pijsuuqqvq3ithky2jhheajtiqxysrrj%2bgrwdc8%3d&\;docid=1_1ba256316f64c4524981f17cd22520e6e&\;wdformid=%7b6b0a9e3d%2df0ee%2d4787%2dbcab%2d8b915b8af637%7d&\;action=formsubmit"; http_uri; nocase; content:"liveconcorde-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006955; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/sofia_segura_casbn_concorde_edu/_layouts/15/guestaccess.aspx?guestaccesstoken=cfpri5iyk8vfhjlweteqtjaelz%2bit8e80ogjwtvujlc%3d&\;docid=1_1f700b55b23874de19595c967b1ee1e75&\;wdformid=%7b5f9c1dbd%2d28e2%2d479e%2dbe4e%2d4ce54e21fe0d%7d"; http_uri; nocase; content:"liveconcorde-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006956; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/czarina-cabalza_live_nmit_ac_nz/_layouts/15/wopiframe.aspx?guestaccesstoken=bcxwl3a7ttskgw2polh3cucg2dfe77pbj2gkmixkizs%3d&docid=1_1b87bddf46e1144efadb39c587acdadae&wdformid=%7b5b4e96cf%2d1bcd%2d468f%2da845%2d09b4d8027bc2%7d&action=formsubmit"; http_uri; nocase; content:"livenmitac-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006957; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/czarina-cabalza_live_nmit_ac_nz/_layouts/15/wopiframe.aspx?guestaccesstoken=bcxwl3a7ttskgw2polh3cucg2dfe77pbj2gkmixkizs=&\;docid=1_1b87bddf46e1144efadb39c587acdadae&\;wdformid={5b4e96cf-1bcd-468f-a845-09b4d8027bc2}&\;action=formsubmit"; http_uri; nocase; content:"livenmitac-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006958; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/czarina-cabalza_live_nmit_ac_nz/_layouts/15/wopiframe.aspx?guestaccesstoken=fnyckzjagh3z%2bl1cadcdqxot6rfyhmeonulx7ksc7pq%3d&docid=1_15129478f60da40db8395b5675832ef56&wdformid=%7b000c8ab1%2dcbc8%2d44e3%2dac19%2d0015f01b771e%7d&action=formsubmit"; http_uri; nocase; content:"livenmitac-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006959; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/hannah-daly_live_nmit_ac_nz/_layouts/15/wopiframe.aspx?guestaccesstoken=ia5uzzon3iviku4f3pxemyhhabfwkpdjirpftfear%2fk%3d&docid=1_169208e425ed84fea9fd294a6886d67e9&wdformid=%7b06255f86%2d4bf9%2d4ee8%2dbd7e%2dfef81913a79b%7d&action=formsubmit"; http_uri; nocase; content:"livenmitac-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006960; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/hannah-daly_live_nmit_ac_nz/_layouts/15/wopiframe.aspx?guestaccesstoken=ia5uzzon3iviku4f3pxemyhhabfwkpdjirpftfear/k=&\;docid=1_169208e425ed84fea9fd294a6886d67e9&\;wdformid={06255f86-4bf9-4ee8-bd7e-fef81913a79b}&\;action=formsubmit"; http_uri; nocase; content:"livenmitac-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006961; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/hannah-daly_live_nmit_ac_nz/_layouts/15/wopiframe.aspx?guestaccesstoken=za7yvssjtzxen%2fcnb0hswkqniem%2fcumgrmfvnt4f8cy%3d&docid=1_128a2a62563b647c9b1b6806600fd8a09&wdformid=%7b20510126%2dfb1d%2d4e63%2d9e6a%2df86488e1d5c6%7d&action=formsubmit"; http_uri; nocase; content:"livenmitac-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006962; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:b:/p/jay_gilmour/exhqlax-ttzblxuozhpnm8ibzjzs2np0tpsknw-4kbeb5a?e=ewkjcb"; http_uri; nocase; content:"ljbarton-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006963; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"lloydsbank.protect-secure-prevent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006964; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dvewnpt"; http_uri; nocase; content:"lnkd.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200006965; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/6z7w"; http_uri; nocase; content:"lnkmeup.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006966; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/78q2"; http_uri; nocase; content:"lnkmeup.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006967; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rtxusers.onmicrosoft.us/oauth2/authorize?client_id=5c8081f1-46af-4077-a0e2-b12ad052a0cb&\;resource=5c8081f1-46af-4077-a0e2-b12ad052a0cb&\;response_mode=form_post&\;response_type=code%20id_token&\;scope=openid%20profile&\;state=openidconnect.authenticationproperties=acrqlwatikp0abt8hj_ouut9bpttsvhcn6bai95z6hpe8rm1atyy2-actt9mxkzdovvftglbtspnzfbg68zi59ikcpgij-ysd0zqwsmnd44o2xohhterzop6tfcegikirilh077uif_-pd0sk2rktn-bcfe2gwi9-wum3tthfkqzojzjkapjflddtan3skbkmmdxb53vfwdthopwbzentmvpqni26bstcumzjgcvsqtu&\;nonce=637485738042802211.zmuznjm5ytktogy3nc00mge2ltg4ntqtnzk3yty3ndcxztblmju2ytvinjytmwuwzi00ndizltgwntitmty5ztzmmgy4ztg0&\;redirect_uri=https://tasks.office365.us/landing&\;ui_locales=en-us&\;mkt=en-us&\;x-client-sku=id_net461&\;x-client-ver=6.5.0.0"; http_uri; nocase; content:"login.microsoftonline.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200006968; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rtxusers.onmicrosoft.us/oauth2/authorize?client_id=5c8081f1-46af-4077-a0e2-b12ad052a0cb&\;resource=5c8081f1-46af-4077-a0e2-b12ad052a0cb&\;response_mode=form_post&\;response_type=code%20id_token&\;scope=openid%20profile&\;state=openidconnect.authenticationproperties=av8xafvlbjl8lveyf112dlrykz1za2fd6roj7a4wst794dn-f5sqocbr8ywev5f9zf62koqwtmgls1ki6kk2gufthuiwhh8dktfndjhnflk-phai2ham7lsuxwzw_betpc3owljmnp57neynhsvjqmifs4qzk-5-1psc4i5afw_ereflxuibhuxktqjkvv2n6u9chaak_no55v_iwarchknnphrsskxl9bdnv8_zdus7&\;nonce=637486060621877491.otrmm2m2owmtytnjny00ngvmlwixntctmmzinjzlnzq5ntllmzlkndk2zdktmjjmmy00yjg5lwjkodqtmtc2zdrjndfkytrk&\;redirect_uri=https://tasks.office365.us/landing&\;ui_locales=en-us&\;mkt=en-us&\;x-client-sku=id_net461&\;x-client-ver=6.5.0.0"; http_uri; nocase; content:"login.microsoftonline.us"; content:"Host"; http_header; classtype:attempted-recon; sid:200006969; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/index.php?key=wor4sp111n0qjnxh327r&\;batchid=es_static_1st_80k_3_re1_5k_5&\;dob=&\;address=avenida%20villanueva%2030&\;city=badajoz&\;email=maribeljvaldivia@gmail.com&\;fname=maria%20isabel&\;lname=jimenez&\;phone=34639307184&\;postcode=6005"; http_uri; nocase; content:"ltitrk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006970; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/anne46523_5tb_in/_layouts/15/acceptinvite.aspx?invitation=%7b9614113b%2dbe07%2d438b%2d963d%2d659c8690fbd2%7d"; http_uri; nocase; content:"lu9-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006971; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/margaret43636_5tb_in/_layouts/15/acceptinvite.aspx?invitation=%7b94ca64e1%2db293%2d4622%2d9504%2d695384f21579%7d"; http_uri; nocase; content:"lu9-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006972; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/info_lunaclothing_nl/_layouts/15/wopiframe.aspx?sourcedoc={aace4e9a-412a-4eb0-b7b6-23c76317f081}&\;action=default&\;originalpath=ahr0chm6ly9sdw5hy2xvdghpbmctbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvaw5mb19sdw5hy2xvdghpbmdfbmwvrxbwt3pxb3frykjpdddzangytvg4suvcvtyznhnmlxnwr3bvytryuzdbaxzfdz9ydgltzt05uzqwnmvssjewzw"; http_uri; nocase; content:"lunaclothing-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006973; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/info_lunaclothing_nl/_layouts/15/wopiframe.aspx?sourcedoc={aace4e9a-412a-4eb0-b7b6-23c76317f081}&\;action=default&\;originalpath=ahr0chm6ly9sdw5hy2xvdghpbmctbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvaw5mb19sdw5hy2xvdghpbmdfbmwvrxbwt3pxb3frykjpdddzangytvg4suvcvtyznhnmlxnwr3bvytryuzdbaxzfdz9ydgltzt1ucddud2vssjewzw"; http_uri; nocase; content:"lunaclothing-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006974; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/info_lunaclothing_nl/_layouts/15/wopiframe.aspx?sourcedoc={aace4e9a-412a-4eb0-b7b6-23c76317f081}&\;action=default&\;originalpath=ahr0chm6ly9sdw5hy2xvdghpbmctbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvaw5mb19sdw5hy2xvdghpbmdfbmwvrxbwt3pxb3frykjpdddzangytvg4suvcvtyznhnmlxnwr3bvytryuzdbaxzfdz9ydgltzt1vvm5wuy1ssjewzw"; http_uri; nocase; content:"lunaclothing-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006975; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/info_lunaclothing_nl/_layouts/15/wopiframe2.aspx?sourcedoc={aace4e9a-412a-4eb0-b7b6-23c76317f081}&\;action=default&\;originalpath=ahr0chm6ly9sdw5hy2xvdghpbmctbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvaw5mb19sdw5hy2xvdghpbmdfbmwvrxbwt3pxb3frykjpdddzangytvg4suvcvtyznhnmlxnwr3bvytryuzdbaxzfdz9ydgltzt05uzqwnmvssjewzw"; http_uri; nocase; content:"lunaclothing-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006976; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/info_lunaclothing_nl/_layouts/15/wopiframe2.aspx?sourcedoc={aace4e9a-412a-4eb0-b7b6-23c76317f081}&\;action=default&\;originalpath=ahr0chm6ly9sdw5hy2xvdghpbmctbxkuc2hhcmvwb2ludc5jb20vom86l2cvcgvyc29uywwvaw5mb19sdw5hy2xvdghpbmdfbmwvrxbwt3pxb3frykjpdddzangytvg4suvcvtyznhnmlxnwr3bvytryuzdbaxzfdz9ydgltzt1vvm5wuy1ssjewzw"; http_uri; nocase; content:"lunaclothing-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006977; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/awojtysiak_lycroproducts_com/_layouts/15/wopiframe.aspx?guestaccesstoken=tm4hdli4pqjohabewhneps%2fipugbtnfdpb1ddrpktda%3d&docid=1_1c8af22d6f14945c79e2efb4790644dcd&wdformid=%7b804f6e96%2d698d%2d43f5%2d9707%2d8f97539a7466%7d&action=formsubmit"; http_uri; nocase; content:"lycroproducts-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006978; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2020/06/mailfreemobilefr.html"; http_uri; nocase; content:"mafacturefreemobile.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006979; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2021/02/blog-post.html"; http_uri; nocase; content:"magyarpoosta.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006980; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forms/forms/form1.html"; http_uri; nocase; content:"mail.hfcfit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006981; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/covid-19/ebay.de.singonacccountc53335b82cb093170657a560aa633ae793b1b483d10d47e1b06db4e/"; http_uri; nocase; content:"malukutenggarakab.go.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200006982; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/soman.php"; http_uri; nocase; content:"mange.google.com.brunocpa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006983; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fgn/"; http_uri; nocase; content:"mangojacket.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006984; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/dejackson_mapei_com/eoimj1iifxtkuvej7paluwmb8rmln15hjfe2y09qaqtd6a?e=w9mk"; http_uri; nocase; content:"mapeigroup-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006985; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/about.php"; http_uri; nocase; content:"marbet-transport.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200006986; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/helaine_marketinghbt_onmicrosoft_com/_layouts/15/doc.aspx?sourcedoc={399d080d-00f3-498e-ab31-d3871303131e}&\;action=view&\;wd=target%28payment.one%7cab348455-fd82-496a-a5fb-d3816a55a264%2frobin%20kallas%20has%20sent%20you%20a%20secure%20document%20%22payment%22%7cedaf5b03-0f86-4664-902e-2e69550aa890%2f%29"; http_uri; nocase; content:"marketinghbt-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006987; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/aus/login?id=rkturevowxvon0xqy3gwqulms3j6qtd2wvdmwtnpn2dtwepocmvhwgffsytsczcvt0tqyzrrzkhceee1sgx3wfbrr0pfd0x3vjrrvendbfpfdctxbgw5dgt3afzpefpfrxzowk1nwgqyvghxtwv0szj6mlhimejhwfrlzwdvwhdusk14evnhdwdxtvl5cwxmctv4zhi4n0x0allzceiwmkjeteo2dufnewl6vmy4b3rkq3e5wedkquxiu2xpnwtpuejyauvym3fprmduvhdxdwtlvzl2mvvuvjbymxo2skpiwtewanbya2vna1bdnu1kwhrwutzib2xvrnlnn0k1r2evk3dyvtvvexj0vgjvtgjiqlnvd2o5tdv4n1loc0d5n0fvdelztlj5ofj3t0r4sdhmuuvryk1rcxbkve1vykm"; http_uri; nocase; content:"mcsharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006988; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eur/login?id=dgw0bhvyqm5mz1c5emzkwkfac2d4mzyrwjd4tmzymfjdy0ovmgg4sfmxaehhuuzitktnz2u1t09zcdjkquq2dvfzsgvutvhksvpdy0x4nwrjcxznmmsvbk0wbkr4q2xrddngr0xfrvjzd2ltzffvshrrymdykzvqd1h1mxrhrgxovkhrmglbbk1xynz6bmz2oeric0hinfm4mezxm211t0jpsnvzmjqznjlcdithdlvpctrqm1p2wgd4uu1otmficzvxenu5aevfr1gzv283zwrqvkpzoenbndhxofvht1jjbvvruvjybtg0awcxukn6awrluunjag5mrwlpauy0rza4yzkyzjfpbw5cbwhanyszsk9one15nwnqsxzgbtuyrvbdq2yzvkpjynrveexmnfjmselrvdvdovfyddk2bk8"; http_uri; nocase; content:"mcsharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006989; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/nam/login?id=u1u5surzk0v0uk5tmxrlchzju2q4ulznrtjby281vkfpznmyl3dowfj3tgd1qvexoentnknzn2fleethd1hgtfbhdzbpvnfiou9jzhn0envss1nkvhbfaevlsitet2fybuhqtstoendxtkf0eldqbeu3nvf5ugfgr2nbagpit2dkbfztte5wuu9eqs9pthziy1jdyxh3ndgzajluwfdyy0jouctnn1hucuzinfbtdzflb3jdclvmq1biy2dxmxjbeexwajjwqis5evdfa1rtn2pvqu0xnjvbzwl4u29oz0yru1pqcgvuvtb4wljyr1lmm2zxnmjsywxcajdiqzqvzmp4qndsvjbpm3j6z0h2r3fds0xidkrtum1pngjpsurjq3ovbe0rwk1hrdc5zjrsnfy5vdvnsfa0rgfdl25toujqawtyt0tbqzvvbw9nauhtzgz5otzrpt0"; http_uri; nocase; content:"mcsharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006990; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/vv/index.html?#pmcmickle@legalshield.com"; http_uri; nocase; content:"medspecialtybilling.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006991; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006992; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/071acd8d543ab940f29000aebc318935"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006993; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/071acd8d543ab940f29000aebc318935/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006994; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/09c0ae09ff8a9241b3b596dd8feaf328"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006995; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/09c0ae09ff8a9241b3b596dd8feaf328/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006996; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/0dc02c9149d683da1e6c075834445171"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006997; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/0dc02c9149d683da1e6c075834445171/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006998; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/1896fed01204b629dd6579ff4cd8aa10"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200006999; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/1896fed01204b629dd6579ff4cd8aa10/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007000; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/1ddeb46b171d44442a39c0c257c33d10"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007001; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/1ddeb46b171d44442a39c0c257c33d10/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007002; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/236d7f9ad4868d35620a394c8c0e136a"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007003; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/236d7f9ad4868d35620a394c8c0e136a/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007004; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/28c36402e717bd2f1b84e64aa7b7447e/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007005; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/309859a614d1555a8a409a895ade952e"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007006; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/309859a614d1555a8a409a895ade952e/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007007; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/30c2ce87985f3a7aa9a0ab270cfbd9f7"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007008; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/30c2ce87985f3a7aa9a0ab270cfbd9f7/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007009; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/325aca03661ed01475a6f5c3bbec1e4c"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007010; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/325aca03661ed01475a6f5c3bbec1e4c/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007011; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/333efdbfad2c354a0b29787e8ae7a0a2"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007012; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/333efdbfad2c354a0b29787e8ae7a0a2/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007013; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/3a99089b392932b921d8925e876622ea"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007014; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/3a99089b392932b921d8925e876622ea/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007015; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/403d78309778733763832d0523132892"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007016; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/403d78309778733763832d0523132892/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007017; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/456d7bd3bfea7eae661bab20f677ccd6"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007018; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/456d7bd3bfea7eae661bab20f677ccd6/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007019; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/484e3f92a1c196280b83925c7045771f/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007020; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/4ea81806fe799a412a4de93490fa8d0a"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007021; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/4ea81806fe799a412a4de93490fa8d0a/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007022; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/4fa987c3201caf3b19798ea41f5f3620"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007023; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/4fa987c3201caf3b19798ea41f5f3620/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007024; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/55e39113899c5ab4949d5f988c9d49bb"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007025; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/55e39113899c5ab4949d5f988c9d49bb/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007026; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/5c21a5cf8eff7d3d92fd52856a1eb697"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007027; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/5c21a5cf8eff7d3d92fd52856a1eb697/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007028; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/5f4ccaf93d1a504e22c59b272001b6b5"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007029; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/5f4ccaf93d1a504e22c59b272001b6b5/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007030; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/62672b5295faf28eb017e192c8730554"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007031; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/62672b5295faf28eb017e192c8730554/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007032; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/632f8c4dfdc69bb2dabd94483b1ba0ef"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007033; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/632f8c4dfdc69bb2dabd94483b1ba0ef/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007034; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/6c72e7f9a3a5490bfbba634ec21705d1"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007035; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/6c72e7f9a3a5490bfbba634ec21705d1/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007036; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/6caf9fa634583830e737debbe3fabf9b"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007037; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/6caf9fa634583830e737debbe3fabf9b/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007038; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/7d8694352cdef4741a1a1f8b1b1508b9"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007039; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/866e67132014095fd9db23551f9009f4"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007040; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/866e67132014095fd9db23551f9009f4/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007041; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/87b5f1a718f9eca71ab5add4dbc75dbe"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007042; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/87b5f1a718f9eca71ab5add4dbc75dbe/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007043; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/88ffd3012fdf67b417d849efabf30137"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007044; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/88ffd3012fdf67b417d849efabf30137/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007045; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/8969b9ede83d803e8c1d90b005661b9b"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007046; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/8969b9ede83d803e8c1d90b005661b9b/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007047; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/8f49c129dd03a5912d0ac6f8747c8a83"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007048; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/8f49c129dd03a5912d0ac6f8747c8a83/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007049; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/9246a1af7e07a6625c8c8ccb9c78d995"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007050; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/9246a1af7e07a6625c8c8ccb9c78d995/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007051; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/94798d20f591a986ecc49ec0a1ac34fc/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007052; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/9d6a1c11e0a86b254bd9e768623f8ab6"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007053; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/9d6a1c11e0a86b254bd9e768623f8ab6/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007054; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/a066cf03da6e95a7e6f545db9e9186ec"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007055; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/a066cf03da6e95a7e6f545db9e9186ec/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007056; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/a2e03b9b94f9b880baa3175c8c7d61ac"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007057; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/a2e03b9b94f9b880baa3175c8c7d61ac/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007058; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/a39784a0fceb35ea56516d497bab1f45"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007059; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/a39784a0fceb35ea56516d497bab1f45/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007060; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/a3bfd2ec5e42500a5b07113773891dca/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007061; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/b64e90c3937a06571297b382d65d3dda"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007062; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/b64e90c3937a06571297b382d65d3dda/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007063; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/b8fb9fa9864a1f4cdce67864e8082819"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007064; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/b8fb9fa9864a1f4cdce67864e8082819/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007065; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/b972baba711afda1f498007b48ac63e2/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007066; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/b9a156d014c5b2a95523655b2343f275"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007067; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/b9a156d014c5b2a95523655b2343f275/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007068; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/bbf1f14af7bed7f249616c07b6b5f3c3"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007069; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/bbf1f14af7bed7f249616c07b6b5f3c3/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007070; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/c510074d9a36305c03fb30956b7cccdb"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007071; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/c510074d9a36305c03fb30956b7cccdb/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007072; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/c559176f09fed92c51c29f769bcbdc3d"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007073; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/c559176f09fed92c51c29f769bcbdc3d/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007074; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/de1a98e834e89aedbfb0d526f6d6db1b"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007075; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/de1a98e834e89aedbfb0d526f6d6db1b/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007076; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/f84c596ac7d6009bd173835ed6fc3d03/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007077; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/f8537ae683b0d1fb04cdf8a01a65add4"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007078; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/f8537ae683b0d1fb04cdf8a01a65add4/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007079; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/fa5232a0686754b783535771632446f6"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007080; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/fa5232a0686754b783535771632446f6/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007081; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/faa3ef5fcddc8372cbdf257d3dd4ad36"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007082; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/chase/faa3ef5fcddc8372cbdf257d3dd4ad36/"; http_uri; nocase; content:"mee-ralbead.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007083; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/linkredirect?authuser=0&\;dest=https%3a%2f%2flinktr.ee%2fpaypai.serviceid?idtrack=kzsykctt"; http_uri; nocase; content:"meet.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007084; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lovingg.php?utm_source=google&\;amp\;utm_medium=adwords&\;amp\;utm_campaign=b"; http_uri; nocase; content:"melbournehairextension.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007085; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/docusign/docusign/docsign"; http_uri; nocase; content:"member-mailtech-support.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007086; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/docusign/docusign/docsign/"; http_uri; nocase; content:"member-mailtech-support.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007087; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login/domain.com/office_365_authentication"; http_uri; nocase; content:"member-mailtech-support.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007088; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login/domain.com/office_365_authentication/"; http_uri; nocase; content:"member-mailtech-support.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007089; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login/domain.com/office_365_authentication/office.php?11kd051617588590ec69beb630c68a267a277590c3f709d1ec69beb630c68a267a277590c3f709d1ec69beb630c68a267a277590c3f709d1ec69beb630c68a267a277590c3f709d1ec69beb630c68a267a277590c3f709d1"; http_uri; nocase; content:"member-mailtech-support.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007090; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login/domain.com/office_365_authentication/office.php?bj886b16175953298d2e60f8a73bbd00f696eb436652ba648d2e60f8a73bbd00f696eb436652ba648d2e60f8a73bbd00f696eb436652ba648d2e60f8a73bbd00f696eb436652ba648d2e60f8a73bbd00f696eb436652ba64"; http_uri; nocase; content:"member-mailtech-support.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007091; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ind/login?id=r00rwwj4clivnulmsusyww4ynfrlafpnyzy4a0y2nkx6dfvoehfqb1bkmfi5rwx4cxzpmkzlt1v3ti9dv0tvqzk2z1dnbuztmm11nnhvz0rhrlq4ceurslnjevdpoewrc0uxz1hmtgdldnl1zghpdxbtzxhvvzfsvjyznxvyszldbxgvtlgrnhbczknhvknpa0llzddnu0nfvmr6ufztotm2b1vqn1g0tlzfci9mmfywvur0nngvbkdzrujishczeitlmuq4r0ffuhleqkttmugrvwfwyllpy0j5z3q2bfznkzltvxnytenrcvazbexpvfoxotvqvjd1n0nctdnaugloczvmk0ncckgwehnyqjazajrulzblcfhzek9uwxp3mnvmcjzvttvvzuxmou1qt3b5dudfdtdsn1q2ynd5qzvhngxhexz5wg91wjfyv0rvs1fqck1bpt0"; http_uri; nocase; content:"mesharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007092; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/cp/46595ecebf250010/c?mi_u=54632464&\;url=https%3a%2f%2fwww.google.com%2furl%3fsa%3dt%26rct%3dj%26q%3d%26esrc%3ds%26source%3dweb%26cd%3d%26cad%3drja%26uact%3d8%26ved%3d2ahukewiq5z7q2ehsahvt5uakhem0c-cqfjaaegqibrac%26url%3dhttp%253a%252f%252fwww.agtroma.it%252fesperienze.htm%26usg%3daovvaw0qjsiebpcbznvj3y5d6wvu"; http_uri; nocase; content:"mi.homedepot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007093; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/midas/dropbox/dropbox.com/dropbox"; http_uri; nocase; content:"midasglitter.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007094; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/css/dist/org/w"; http_uri; nocase; content:"mightier.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007095; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/css/dist/org/w/"; http_uri; nocase; content:"mightier.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007096; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/click.php?uri=http://myaccountoptus.com/index.php?userid=abuse@optusnet.com.au"; http_uri; nocase; content:"migrate.upcontact.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007097; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/requests/response/sincro/atendimento/"; http_uri; nocase; content:"milad-ghasemi.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007098; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2020/11/fiyatlar.html"; http_uri; nocase; content:"milanno342.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007099; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/vgibbs_mhmltd_com/epp3aeyaxrlkqypm5j3ps5ib0imi6otftjp4ijzlbe4pyq?e=5:r8hnxr&\;at=9"; http_uri; nocase; content:"millenniaco-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007100; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/vgibbs_mhmltd_com/_layouts/15/doc.aspx?sourcedoc={ec69f793-5e80-4ab9-ab2a-66e49de9b392}&\;action=default&\;slrid=dca0489f-f03b-b000-9fd0-1e171e182306&\;originalpath=ahr0chm6ly9tawxszw5uawfjby1tes5zagfyzxbvaw50lmnvbs86bzovzy9wzxjzb25hbc92z2liynnfbwhtbhrkx2nvbs9fcfazywv5qvhybetxexbtnuozchm1suiwaw1pnk90znrqcdrpsnpmqmu0uhlrp3j0aw1lpujzclb1vkrnmtbn&\;cid=0e1475ff-8901-48a8-aeae-660a9e5b5547"; http_uri; nocase; content:"millenniaco-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007101; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ecuador/estado-de-cuenta-produbanco/"; http_uri; nocase; content:"mistramitesyrequisitos.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007102; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/khunsley_modularmovements_com/_layouts/15/onedrive.aspx?id=/personal/khunsley_modularmovements_com/documents/dbc%20sharepoint.pdf&\;parent=/personal/khunsley_modularmovements_com/documents&\;originalpath=ahr0chm6ly9tb2r1bgfybw92zw1lbnrzlw15lnnoyxjlcg9pbnquy29tlzpioi9wl2todw5zbgv5l0vhuupzyxbquvvkq25wtxjfexzgd2tbqm5bmly0s0tzu01kdu0tukvns1h6tle_cnrpbwu9d0s0z1iwdguyrwc"; http_uri; nocase; content:"modularmovements-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007103; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/khunsley_modularmovements_com/_layouts/15/onedrive.aspx?id=/personal/khunsley_modularmovements_com/documents/dbc%20sharepoint.pdf&\;parent=/personal/khunsley_modularmovements_com/documents&\;originalpath=ahr0chm6ly9tb2r1bgfybw92zw1lbnrzlw15lnnoyxjlcg9pbnquy29tlzpioi9wl2todw5zbgv5l0vhuupzyxbquvvkq25wtxjfexzgd2tbqm5bmly0s0tzu01kdu0tukvns1h6tle_cnrpbwu9dzhiulbwaguyrwc"; http_uri; nocase; content:"modularmovements-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007104; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/user_monovative_onmicrosoft_com/emczkjnkzgxdtejtstz67qqblknarn4da620kjaje91ewq?e=5:weseg8&\;at=9"; http_uri; nocase; content:"monovative-my.sharepoint.com:443"; content:"Host"; http_header; classtype:attempted-recon; sid:200007105; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2020/07/blog-post.html"; http_uri; nocase; content:"monremboursementgouv.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007106; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2009_01_01_archive.html"; http_uri; nocase; content:"mundovirtualhabbo.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007107; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/_layouts/15/wopiframe.aspx?guestaccesstoken=xvdowzk%2bkm4wndrziofnpfcj8fb8rkrsqt%2bkybvollg%3d&docid=1_16fb1a2a3e2f9468aa7cebc35874c9da0&wdformid=%7b95111770-0103-492b-8c70-e9625f96b49a%7d&action=formsubmit&cid=4d02a372-8b83-4120-84b5-1d9a2a3492dd"; http_uri; nocase; content:"myparc.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007108; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/_layouts/15/wopiframe.aspx?guestaccesstoken=xvdowzk%2bkm4wndrziofnpfcj8fb8rkrsqt%2bkybvollg%3d&docid=1_16fb1a2a3e2f9468aa7cebc35874c9da0&wdformid=%7b95111770-0103-492b-8c70-e9625f96b49a%7d&action=formsubmit&cid=4d02a372-8b83-4120-84b5-1d9a2a3492dd"; http_uri; nocase; content:"myparc.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007109; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/royalmail/"; http_uri; nocase; content:"myparcel-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007110; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/royalmail/secure.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"myparcel-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007111; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/royalmail/user.php?&sessionid=f01f18eaec89816094bc3868f662d236&securessl=true"; http_uri; nocase; content:"myparcel-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007112; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/royalmail/verifylogin.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"myparcel-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007113; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/ebenezer_ajayi_edu_sait_ca/_layouts/15/wopiframe.aspx?guestaccesstoken=y%2bhr1dv9mxgpih7r4y%2f%2fjkhvv1nxdh3imaz%2bmjeumni%3d&docid=1_1ff1eb35301564d1698455e7de780fe7f&wdformid=%7b2b1e75ff%2d4748%2d448a%2db5f7%2d7d4a5138e7f7%7d&action=formsubmit&cid=b8bab67a-6675-4883-8c86-32942813ffb3"; http_uri; nocase; content:"mysait-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007114; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/ebenezer_ajayi_edu_sait_ca/_layouts/15/wopiframe.aspx?guestaccesstoken=y%2bhr1dv9mxgpih7r4y%2f%2fjkhvv1nxdh3imaz%2bmjeumni%3d&docid=1_1ff1eb35301564d1698455e7de780fe7f&wdformid=%7b2b1e75ff%2d4748%2d448a%2db5f7%2d7d4a5138e7f7%7d&action=formsubmit&cid=b8bab67a-6675-4883-8c86-32942813ffb3"; http_uri; nocase; content:"mysait-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007115; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/4gezz"; http_uri; nocase; content:"mysp.ac"; content:"Host"; http_header; classtype:attempted-recon; sid:200007116; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/4jaza?userid=w0hspaxq"; http_uri; nocase; content:"mysp.ac"; content:"Host"; http_header; classtype:attempted-recon; sid:200007117; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/4kmf1?userid=6oysmmeg"; http_uri; nocase; content:"mysp.ac"; content:"Host"; http_header; classtype:attempted-recon; sid:200007118; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/m2m0"; http_uri; nocase; content:"mysp.ac"; content:"Host"; http_header; classtype:attempted-recon; sid:200007119; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/forum/for_camp_directors_c3/research_and_learn_f10/bridging_the_gap_at_summer_camp/gforum.cgi?url=http://server.bludomain82.com/~bree2/review/#_&\;?hannah.judge@discsystems.co.uk"; http_uri; nocase; content:"mysummercamps.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007120; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bots/runescape-bot/"; http_uri; nocase; content:"naverbot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007121; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/peter_baumanglobal_com/_layouts/15/authenticate.aspx"; http_uri; nocase; content:"netorg4219258-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007122; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/ddoris_airservicesco_com/_layouts/15/wopiframe.aspx?guestaccesstoken=%2b3y%2bcdfvdslxx0tgrivwrfjqapqcjfpi%2fnyhmijz6qa%3d&docid=1_1021e11db2d82413ebf54355221c28513&wdformid=%7b5bf1f9e2%2d5212%2d4414%2d8e87%2d9d18071fcce1%7d&action=formsubmit"; http_uri; nocase; content:"netorg5539223-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007123; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/alan_etkinpllc_com/emv9ti9prk1ioco67l0q4eybqcu9jbj--dz3wlksvzg3lg?e=8ainmj"; http_uri; nocase; content:"netorgft1393773-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007124; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/jackcasiere_interiorresourcesllc_com/_layouts/15/wopiframe.aspx?guestaccesstoken=q4k2ijw5n56wcijbywugmtwo%2btia72scpc%2f9uoe%2bpxg%3d&docid=1_1dd9f10a6bdc94b9cb94ee659f839180c&wdformid=%7ba6451884-7364-4e8e-a333-196fb7a2c202%7d&action=formsubmit&cid=8bfe7a6d-44f0-46a0-82c0-bdf02140c5aa"; http_uri; nocase; content:"netorgft1705483-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007125; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/leon_leongavartin_com/_layouts/15/wopiframe.aspx?guestaccesstoken=rpanwaz3gooz0d20j9wu7zzskog8p5egpbt4oc5j5bq%3d&docid=1_137b486a2059c4fc7b670d2ddb8f27254&wdformid=%7b07fe213f%2d4079%2d45b9%2db73f%2dfa9809248dd7%7d&action=formsubmit"; http_uri; nocase; content:"netorgft2223515-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007126; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/leon_leongavartin_com/_layouts/15/wopiframe.aspx?guestaccesstoken=xamh1yie5ztbehymkwldcb6bkcf1kqp13dwjvauswg4%3d&docid=1_10f85e31d21194b00bc5c96bd48a6a4fc&wdformid=%7b702d2762%2df654%2d423b%2dba6b%2d850079f6ed46%7d&action=formsubmit"; http_uri; nocase; content:"netorgft2223515-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007127; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/leon_leongavartin_com/_layouts/15/wopiframe.aspx?guestaccesstoken=rpanwaz3gooz0d20j9wu7zzskog8p5egpbt4oc5j5bq%3d&docid=1_137b486a2059c4fc7b670d2ddb8f27254&wdformid=%7b07fe213f%2d4079%2d45b9%2db73f%2dfa9809248dd7%7d&action=formsubmit"; http_uri; nocase; content:"netorgft2223515-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007128; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/leon_leongavartin_com/_layouts/15/wopiframe.aspx?guestaccesstoken=rpanwaz3gooz0d20j9wu7zzskog8p5egpbt4oc5j5bq%3d&docid=1_137b486a2059c4fc7b670d2ddb8f27254&wdformid=%7b07fe213f%2d4079%2d45b9%2db73f%2dfa9809248dd7%7d&action=formsubmit&cid=650c66d5-f562-4aa4-8db5-c02c515ec8c4"; http_uri; nocase; content:"netorgft2223515-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007129; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/leon_leongavartin_com/_layouts/15/wopiframe.aspx?guestaccesstoken=xamh1yie5ztbehymkwldcb6bkcf1kqp13dwjvauswg4%3d&docid=1_10f85e31d21194b00bc5c96bd48a6a4fc&wdformid=%7b702d2762%2df654%2d423b%2dba6b%2d850079f6ed46%7d&action=formsubmit&cid=1dae315f-39cb-430d-b680-e50b0146e685"; http_uri; nocase; content:"netorgft2223515-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007130; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/leon_leongavartin_com/_layouts/15/wopiframe.aspx?guestaccesstoken=xamh1yie5ztbehymkwldcb6bkcf1kqp13dwjvauswg4%3d&docid=1_10f85e31d21194b00bc5c96bd48a6a4fc&wdformid=%7b702d2762%2df654%2d423b%2dba6b%2d850079f6ed46%7d&action=formsubmit&cid=78b96c55-f4b4-49a8-ba46-9d2cd15837b5"; http_uri; nocase; content:"netorgft2223515-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007131; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/service_grandisleties_com/_layouts/15/wopiframe.aspx?guestaccesstoken=pmxhjtsepwbmxi%20afreenyvyn0jrccvcgbqrd0jtcq8=&\;docid=1_1e318a834149c47f884752e9315da88d5&\;wdformid={21f3b38e-e8d9-4097-be99-0cb952413aff}&\;action=formsubmit"; http_uri; nocase; content:"netorgft7625533-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007132; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/service_grandisleties_com/_layouts/15/wopiframe.aspx?guestaccesstoken=pmxhjtsepwbmxi%2bafreenyvyn0jrccvcgbqrd0jtcq8%3d&docid=1_1e318a834149c47f884752e9315da88d5&wdformid=%7b21f3b38e%2de8d9%2d4097%2dbe99%2d0cb952413aff%7d&action=formsubmit"; http_uri; nocase; content:"netorgft7625533-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007133; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/malteserde/wp-file/"; http_uri; nocase; content:"newavenueconsultant.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007134; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/css/colors/ocean/js/theme.js/inc-style/grece.paypai-id.pro968/myaccount/identity/?cmd=_session=us&\;amp"; http_uri; nocase; content:"newsbrigade.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007135; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/css/colors/ocean/js/theme.js/inc-style/grece.paypai-id.pro968/myaccount/identity/?cmd=_session=us&\;d34320f63d56ede7fd814ae4fb903952&\;dispatch=28eb2b0dad222b43ece5890ac6c4995f14fbf092"; http_uri; nocase; content:"newsbrigade.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007136; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/css/colors/ocean/js/theme.js/inc-style/grece.paypai-id.pro968/myaccount/identity/?cmd=_session=us&\;dispatch=a747fec16e90d03372eec4b410a064f3315fc8ab"; http_uri; nocase; content:"newsbrigade.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007137; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/css/colors/ocean/js/theme.js/inc-style/grece.paypai-id.pro968/myaccount/identity/?cmd=_session=us&\;e74cc56f728f08bf36fd1c917b4a5074&\;dispatch=a747fec16e90d03372eec4b410a064f3315fc8ab"; http_uri; nocase; content:"newsbrigade.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007138; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/doc/cmd-login=9feaf7f8354ad68ba40e29d70cd05405/?email=jjlytle@manatt.com&\;loginpage=&\;reff=nzk1mwu5mjzinza5ytexzjgxntrkmtk0mwqyzthimzk="; http_uri; nocase; content:"newsimdigital.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007139; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/examination/admitpanel/filemanager/5365678587"; http_uri; nocase; content:"nihmt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007140; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/acolon_norcaltc_org/_layouts/15/wopiframe.aspx?guestaccesstoken=oblmrsnjab0plpjkem%20lpq7yi%20wxi62y3xtqo1ndk1m=&\;docid=1_1eacea0b62e3c42acadef15ddaf48dd46&\;wdformid={81c189e5-0638-4871-a666-551ab6c29185}&\;action=formsubmit"; http_uri; nocase; content:"norcaltc-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007141; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/acolon_norcaltc_org/_layouts/15/wopiframe.aspx?guestaccesstoken=oblmrsnjab0plpjkem%2blpq7yi%2bwxi62y3xtqo1ndk1m%3d&docid=1_1eacea0b62e3c42acadef15ddaf48dd46&wdformid=%7b81c189e5%2d0638%2d4871%2da666%2d551ab6c29185%7d&action=formsubmit"; http_uri; nocase; content:"norcaltc-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007142; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/acolon_norcaltc_org/_layouts/15/wopiframe.aspx?guestaccesstoken=oblmrsnjab0plpjkem%20lpq7yi%20wxi62y3xtqo1ndk1m=&\;docid=1_1eacea0b62e3c42acadef15ddaf48dd46&\;wdformid={81c189e5-0638-4871-a666-551ab6c29185}&\;action=formsubmit&\;cid=45f175e2-9177-41d1-a470-bdddc50821f9"; http_uri; nocase; content:"norcaltc-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007143; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/acolon_norcaltc_org/_layouts/15/wopiframe.aspx?guestaccesstoken=oblmrsnjab0plpjkem%20lpq7yi%20wxi62y3xtqo1ndk1m=&\;docid=1_1eacea0b62e3c42acadef15ddaf48dd46&\;wdformid={81c189e5-0638-4871-a666-551ab6c29185}&\;action=formsubmit&\;cid=b88a983f-2bdf-431d-8bcd-0042a72a8362"; http_uri; nocase; content:"norcaltc-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007144; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/acolon_norcaltc_org/_layouts/15/wopiframe.aspx?guestaccesstoken=oblmrsnjab0plpjkem%2blpq7yi%2bwxi62y3xtqo1ndk1m%3d&docid=1_1eacea0b62e3c42acadef15ddaf48dd46&wdformid=%7b81c189e5%2d0638%2d4871%2da666%2d551ab6c29185%7d&action=formsubmit&cid=45f175e2-9177-41d1-a470-bdddc50821f9"; http_uri; nocase; content:"norcaltc-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007145; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/acolon_norcaltc_org/_layouts/15/wopiframe.aspx?guestaccesstoken=oblmrsnjab0plpjkem%2blpq7yi%2bwxi62y3xtqo1ndk1m%3d&docid=1_1eacea0b62e3c42acadef15ddaf48dd46&wdformid=%7b81c189e5%2d0638%2d4871%2da666%2d551ab6c29185%7d&action=formsubmit&cid=b88a983f-2bdf-431d-8bcd-0042a72a8362"; http_uri; nocase; content:"norcaltc-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007146; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/acolon_norcaltc_org/_layouts/15/wopiframe.aspx?guestaccesstoken=yze2svus6et1yfbzbrrbp0zblkd6ftbulrue02wudhw%3d&docid=1_1f1c059892dd04acf92bca72fa2b86901&wdformid=%7b22fa7e1d%2d2b31%2d41b8%2da33f%2d0d3a531f6142%7d&action=formsubmit"; http_uri; nocase; content:"norcaltc-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007147; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/acolon_norcaltc_org/_layouts/15/wopiframe.aspx?guestaccesstoken=yze2svus6et1yfbzbrrbp0zblkd6ftbulrue02wudhw=&\;docid=1_1f1c059892dd04acf92bca72fa2b86901&\;wdformid={22fa7e1d-2b31-41b8-a33f-0d3a531f6142}&\;action=formsubmit"; http_uri; nocase; content:"norcaltc-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007148; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/19besoriob_nks_kent_sch_uk/eml51uxw3yblmb_cng_jobkbjiz5a9svhv-aa1dwwc9xqg?e=ufnvrz"; http_uri; nocase; content:"nortonknatchbull-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007149; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/voice/index.php?email=ged@jubileegroup.co.uk"; http_uri; nocase; content:"norts-import.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007150; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2021/02/blog-post.html"; http_uri; nocase; content:"norwayposten.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007151; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cb/pages/jsp-ns/login-cons/"; http_uri; nocase; content:"notigtclient-banruralgt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007152; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/at-t-42ce09acae7c45c5b7ef242bf7e6bd50"; http_uri; nocase; content:"notion.so"; content:"Host"; http_header; classtype:attempted-recon; sid:200007153; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?https://amazon.co.jp"; http_uri; nocase; content:"nullrefer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007154; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/certificates/login.php?l=_jehfuq_vjoxk0qwhtogydw1774256418&\;fid.13inboxlight.aspxn.1774256418&\;fid.125289964252813inboxlight99642_product-email&\;email=snkroll@emirates.net"; http_uri; nocase; content:"occmedconnect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007155; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/oceetee_oceetee_com_sa/_layouts/15/wopiframe.aspx?guestaccesstoken=5t/v57wosh/zuc+ubbpprapdh5daqzjepxbham/9wjy=&\;docid=1_129efcffef3324628b752d1139515937e&\;wdformid={0767107a-f265-4239-a58d-79524eada2a7}&\;action=formsubmit&\;cid=a79ba94e-e9be-4a5f-ba1d-20a889580d1b"; http_uri; nocase; content:"oceetee-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007156; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cash57008877"; http_uri; nocase; content:"olxpl.bank-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007157; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/uploads/2021/02/tracking-ch/login/index.php?trackid=cs471210241de"; http_uri; nocase; content:"oneclickchatbot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007158; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?authkey=!aacuhpdmy26a584&\;cid=5a1faf0110c4a22c&\;id=5a1faf0110c4a22c!1553&\;parid=root&\;o=oneup"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007159; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?authkey=!acxsks7gii7zuak&\;cid=f36853a446c64cd2&\;id=f36853a446c64cd2!1052&\;parid=root&\;o=oneup"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007160; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?authkey=!adixrsjrdlsoz7q&\;cid=f36853a446c64cd2&\;id=f36853a446c64cd2!1056&\;parid=root&\;o=oneup"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007161; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?authkey=!aiuszyywonlw6wq&\;cid=5a1faf0110c4a22c&\;id=5a1faf0110c4a22c!1550&\;parid=root&\;o=oneup"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007162; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?authkey=!aiwjcwhmidrycfe&\;cid=6ff30ec047bf7f90&\;id=6ff30ec047bf7f90!1118&\;parid=root&\;o=oneup"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007163; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?authkey=%21abdtnonrfuimmte&cid=8b06262ca3def289&id=8b06262ca3def289%21106&parid=root&o=oneup"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007164; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?authkey=%21abfqbc2symchkcu&\;cid=411ae82266f5c82f&\;id=411ae82266f5c82f%21111&\;parid=root&\;o=oneup"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007165; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?authkey=%21adgdsbylmqmjyce&\;cid=b209490283db4b3d&\;id=b209490283db4b3d%21113&\;parid=root&\;o=oneup"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007166; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?authkey=%21ag7v3k%5fv%5fvmx0wu&\;cid=2022b4d58b052264&\;id=2022b4d58b052264%21709&\;parid=root&\;o=oneup"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007167; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?authkey=%21ahm9ud6tremilmy&\;cid=d3acf7db10258474&\;id=d3acf7db10258474%21118&\;parid=root&\;o=oneup"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007168; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?authkey=%21am%5f1fgzd8staols&cid=362259935a9d4584&id=362259935a9d4584%2117198&parid=root&o=oneup"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007169; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/download?cid=93c3298d9984212f&resid=93c3298d9984212f%21107&authkey=ajtz9muc7rp7hbi"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007170; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/embed?cid=3871b7bad2d4fc0d&\;resid=3871b7bad2d4fc0d%21204&\;authkey=adyaqhce_iaophq&\;em=2"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007171; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redir?resid=15d888f2c88e7d68%21104&\;authkey=%21alapi82fus8uhw8&\;page=view&\;wd=target%28martco.one%7c248982a3-c6db-4608-9b3f-59d46f4a8f11%2fdan%20shared%20a%20file%20with%20you%7c85b5e37c-8918-4d14-b5a0-0742bfe487b0%2f%29"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007172; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redir?resid=1b259cec1257165d%21143&authkey=%21apkdm5ellcpwz_w&page=view&wd=target%28quick%20notes.one%7c70d4ff33-5389-4385-b3e5-751c2cf1989e%2frau%20construction%7c961392e9-1ab5-4334-9d52-69d0f17f7c4c%2f%29"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007173; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redir?resid=4e2bb29813ea0aaf!10031&\;authkey=!aldtiondcbvwyqe&\;e=kfcf2r"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007174; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redir?resid=7aa7bb4172c9678d%21104&authkey=%21ancnqdf2mi0o4bs&page=view&wd=target%28untitled%20section.one%7c78a1f9ff-7561-4169-a2f1-2b4bfce0e5d2%2fbusiness%20insurance%20services%2c%20inc.%7cb909bc92-cd18-491c-afbb-8e0537ffd3ed%2f%29"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007175; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redir?resid=85c38ec07aa8c9eb%21104&\;authkey=%21akfbbhbpqjalrag&\;page=edit&\;wd=target%28king%20plastic%20corporation.one%7c74227ab3-5b67-4fed-aee8-c6ec5625e330%2fmichael%20fabbri%20has%20shared%20a%20file%20with%20you%7c5ea49da5-4656-4a44-a813-5b186327c32f%2f%29"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007176; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redir?resid=a37258a5832f32b8%214551&authkey=%21ah-prmdnyc6z-he&page=view&wd=target%28quick%20notes.one%7c4617bc2b-8a69-4e83-9b28-fdc3f0e092a4%2freview%20document%20no.%20clt9071825%7ca63f7492-3a53-4740-8ff8-743d2bf58dd0%2f%29"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007177; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redir?resid=ca951cbce51dacca%21116&\;authkey=%21ajmfmeuw4quzlvq&\;page=view&\;wd=target%28beverly%20chew.one%7c58dc8802-6268-4ab5-9a46-390102e0eb16%2fbeverly%20chew%c2%a0has%20shared%20a%20file%20with%20you%7c16c9a1d9-4f23-4d43-b756-129ffe78db2b%2f%29"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007178; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redir?resid=cc542b30a231222a%21104&authkey=%21aagyx6eylxtvs0i&page=view&wd=target%28southwest%20funding.one%7cdb02ff26-a000-4a11-a770-a766574c7395%2feric%20barefoot%c2%a0has%20shared%20a%20file%20with%20you%7cbbd45792-c84c-4ac7-b2f5-1368247a21f4%2f%29"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007179; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redir?resid=cd559106ccc02352%211258&\;authkey=%21alvlfliaim3cv5q&\;page=view&\;wd=target%28quick%20notes.one%7c29565bf4-20e6-4f53-8609-4cdc4234bd80%2fthe%20people%20concern%20pending%20invoice%7cf677313c-0b2e-4631-a33d-afdae7a7d091%2f%29"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007180; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redir?resid=e218f633c86c6761%2113932&authkey=%21af_tcwfbnw3a2pa&page=view&wd=target%28quick%20notes.one%7ceb47ef04-fc74-4a6b-a3aa-5c74bc87b2db%2famerican%20international%20gemologists%20investment%20proposal%20for%202020%7cae9939c7-9475-42e1-a29d-4bb3ce9d27bf%2f%29"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007181; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redir?resid=f224e40f244f69d%213603&authkey=%21aa0etofrovbzrds&page=view&wd=target%28quick%20notes.one%7cef3efdee-f2ab-465b-af63-7c751f8ee737%2feddie%20winfrey%20has%20shared%20a%20document%20with%20you%7c2c2aaad0-b64f-4424-9eed-b8e299fa1177%2f%29"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007182; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redir?resid=f950f8718f3413f!139&authkey=!abm4jclf3vh4_ea&ithint=file%2cxlsx&page=survey&wdformid=8786a7d4-f24e-494d-a981-ec4d7be22b99"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007183; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view.aspx?resid=165bfee39105d588!1450&\;wdo=2&\;authkey=!ahdxqiyo1wxtypa"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007184; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view.aspx?resid=2ccda0f55e51c04d!1056&\;authkey=!ahvxdmahsk9xqic"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007185; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view.aspx?resid=357cf596b048e521!68171&\;ithint=onenote%2c&\;authkey=!agrjg_pgegj6peq"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007186; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view.aspx?resid=90561ad0721456e9!179&\;authkey=!ahrd9gzrypfctci"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007187; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view.aspx?resid=a4bcf14ca21628ff!191&\;authkey=!an2xfvvmx9d0ypk"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007188; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view.aspx?resid=b116b3793040630b!5852&\;ithint=onenote%2c&\;authkey=!altmjf-4bzb1ygu"; http_uri; nocase; content:"onedrive.live.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007189; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"online-cancel-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007190; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/halifax"; http_uri; nocase; content:"onlinehalifax-account.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007191; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/halifax/login.php"; http_uri; nocase; content:"onlinehalifax-account.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007192; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?m=1"; http_uri; nocase; content:"optusnet-com.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007193; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/tanja_kuusela_ouraring_com/_layouts/15/doc.aspx?sourcedoc"; http_uri; nocase; content:"ouraring-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007194; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/tanja_kuusela_ouraring_com/_layouts/15/doc.aspx?sourcedoc={6dfd36f7-86e9-46d3-b9cc-33ba7e8a7540}&\;action=default&\;slrid=4a49409f-2030-2000-55c3-0f6b60771e27&\;originalpath=ahr0chm6ly9vdxjhcmluzy1tes5zagfyzxbvaw50lmnvbs86bzovcc90yw5qyv9rdxvzzwxhl0v2yzjfvznwahror3vjd3p1bjzlzfvbqm9nd1yxegftx05ly3h6ekxkbvhruue_cnrpbwu9ylp0ujd2tewxmgc&\;cid=18ed1537-8fab-4a88-9a51-f62af2ba3e85"; http_uri; nocase; content:"ouraring-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007195; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/tanja_kuusela_ouraring_com/_layouts/15/doc.aspx?sourcedoc={6dfd36f7-86e9-46d3-b9cc-33ba7e8a7540}&\;action=default&\;slrid=7448409f-907f-2000-55b9-8b3856a492d0&\;originalpath=ahr0chm6ly9vdxjhcmluzy1tes5zagfyzxbvaw50lmnvbs86bzovcc90yw5qyv9rdxvzzwxhl0v2yzjfvznwahror3vjd3p1bjzlzfvbqm9nd1yxegftx05ly3h6ekxkbvhruue_cnrpbwu9bjdxazvqrewxmgc&\;cid=17aea50f-0cad-4a24-8ca6-2b3aba94e944"; http_uri; nocase; content:"ouraring-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007196; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/tanja_kuusela_ouraring_com/_layouts/15/doc.aspx?sourcedoc={6dfd36f7-86e9-46d3-b9cc-33ba7e8a7540}&\;action=default&\;slrid=e3083d9f-70d3-2000-e93a-b2a109d8122f&\;originalpath=ahr0chm6ly9vdxjhcmluzy1tes5zagfyzxbvaw50lmnvbs86bzovcc90yw5qyv9rdxvzzwxhl0v2yzjfvznwahror3vjd3p1bjzlzfvbqm9nd1yxegftx05ly3h6ekxkbvhruue_cnrpbwu9mnjsznrbteuxmgc&\;cid=ce3f6183-644d-4c2c-b9c5-e59d8ec48d03"; http_uri; nocase; content:"ouraring-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007197; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/tanja_kuusela_ouraring_com/_layouts/15/doc.aspx?sourcedoc={6dfd36f7-86e9-46d3-b9cc-33ba7e8a7540}&\;action=default&\;slrid=e5083d9f-a047-2000-523d-f23a7ab7042b&\;originalpath=ahr0chm6ly9vdxjhcmluzy1tes5zagfyzxbvaw50lmnvbs86bzovcc90yw5qyv9rdxvzzwxhl0v2yzjfvznwahror3vjd3p1bjzlzfvbqm9nd1yxegftx05ly3h6ekxkbvhruue_cnrpbwu9tvlqc3r3teuxmgc&\;cid=06a207b4-652a-4300-9385-5d89a890e4fe"; http_uri; nocase; content:"ouraring-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007198; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secure.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"outstanding-package-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007199; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/verifylogin.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"outstanding-package-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007200; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lcqx30cdfcg"; http_uri; nocase; content:"ow.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007201; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/9kyr30pxocn"; http_uri; nocase; content:"owl.li"; content:"Host"; http_header; classtype:attempted-recon; sid:200007202; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/attachment/1296018/0lp7dnjq1b05nsxcj1esqcmjv?token=eyjhbgcioijkaxiilcjlbmmioijbmti4q0jdluhtmju2in0..7inwiztegjukxh5ggxiwaq.y_7wjbrs9ezo9es89pe2xwdkz3p9mejoznq646dc43bwrl2vwaez6zpdwkukzb2ki-lnkyawjdk6ixedrm09k2en70tpnnnbibjs9oie963wonzjj85s8rlptzlmlcuh-audetfbluc_cpgo-zewhokdq_tbkfamicbljl33rfq0pjhkloxonneyqcedpmrb4wwmvazqdt4_5pagec6otyjgtpypwa1dbra3izgqmxelg_wmmvgf1c7dw4hyto9avh0k5-nnjvxqk58rbjqdfrkdtsow_1ucsz5aqxz7i_4.ntjuez-act1w6a4somchhq"; http_uri; nocase; content:"p17.zdusercontent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007203; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/610964646/d0a82b340ac6b4eb2fed334399fe2e84/palad.html"; http_uri; nocase; content:"padlet-uploads.storage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007204; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/exchange328e91ec88ae4615bbc38ab6ce41107e/audio/msgs/index.php?08a3ea=alessandro.aspesi@columbiathreadneedle.com"; http_uri; nocase; content:"paksarhadgoods.duskypot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007205; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gileadzp.php?utm_source=google&\;amp\;utm_medium=adwords&\;amp\;utm_campaign=fsyoolp"; http_uri; nocase; content:"panjaabias.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007206; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secure.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"parcel-confirmation-settlement.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007207; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/julie_belzanne_parisandco_com/ellpb_qygw9mmv02jxqltmwbnwu6lexv1b7hmfhmuoacia?e=ccvecg"; http_uri; nocase; content:"parislab-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007208; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/rosee_parmacityschools_org/_layouts/15/wopiframe.aspx?guestaccesstoken=amgmrypee2b3%2fq5mcsf%2bmqat2vaamt9idaj1njxwdpe%3d&\;docid=1_1514e14043e894d289ec8998e5536118b&\;wdformid=%7beb853daf%2d5ba6%2d40dd%2dbf99%2d970f5cf41327%7d&\;action=formsubmit"; http_uri; nocase; content:"parmacityschooldistrict-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007209; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/index.php"; http_uri; nocase; content:"parnamg.info"; content:"Host"; http_header; classtype:attempted-recon; sid:200007210; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mt/%c4%a7anut/el-salvador/woocommerce-el-salvador/woocommerce-credix-plugin-pasarela-de-pago-multisite/"; http_uri; nocase; content:"pasarelasdepagos.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007211; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/25qk2"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007212; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/26c30"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007213; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/26dcc"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007214; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/26e8w"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007215; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/278zi"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007216; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/27tk1"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007217; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2884c"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007218; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/28eek"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007219; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/28j3g"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007220; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2980b"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007221; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/29igl"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007222; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/29jzn"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007223; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/29n5y"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007224; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/29vnj"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007225; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2a9kr"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007226; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2ae9m"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007227; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2ae9x"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007228; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2amyg"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007229; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2btlc"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007230; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2bxht"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007231; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2c1g8"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007232; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2c396"; http_uri; nocase; content:"pastelink.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007233; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/patrick_kestens_kepa_be/ek6ptmfi3rbpl0okvukyovobz5voxh1dgbqr66js29e06w?e=zytfn9"; http_uri; nocase; content:"patrickkestens-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007234; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/patrick_kestens_kepa_be/_layouts/15/doc.aspx?sourcedoc={c74ca94e-dee2-4fb0-9743-a4bd4932395a}&\;action=default&\;slrid=53537f9f-8020-2000-6402-9094cd7180b6&\;originalpath=ahr0chm6ly9wyxryawnra2vzdgvucy1tes5zagfyzxbvaw50lmnvbs86bzovzy9wzxjzb25hbc9wyxryawnrx2tlc3rlbnnfa2vwyv9izs9fazzwve1matnyqlbsme9rdlvreu9wb0janvzvwggxredicvi2nkptmjllmdz3p3j0aw1lpun2vwfidhbsmkvn&\;cid=3dd22632-4961-431e-befd-a875d08cde81"; http_uri; nocase; content:"patrickkestens-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007235; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/patrick_kestens_kepa_be/_layouts/15/doc2.aspx?sourcedoc={c74ca94e-dee2-4fb0-9743-a4bd4932395a}&\;action=default&\;slrid=53537f9f-8020-2000-6402-9094cd7180b6&\;originalpath=ahr0chm6ly9wyxryawnra2vzdgvucy1tes5zagfyzxbvaw50lmnvbs86bzovzy9wzxjzb25hbc9wyxryawnrx2tlc3rlbnnfa2vwyv9izs9fazzwve1matnyqlbsme9rdlvreu9wb0janvzvwggxredicvi2nkptmjllmdz3p3j0aw1lpun2vwfidhbsmkvn&\;cid=3dd22632-4961-431e-befd-a875d08cde81"; http_uri; nocase; content:"patrickkestens-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007236; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/paxful/login.php"; http_uri; nocase; content:"paxful.client-protect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007237; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"payee-management-verify-request.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007238; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"payee-validationsupport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007239; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2021/02/blog-post.html"; http_uri; nocase; content:"paypal-inc-userupdatenuber7925570844.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007240; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/keyu_paypal_com/documents/delivering%20certainty%20presentation/delivering%20certainty%20roadmap%20presentation%204.18.19%20v11%20(shared).pptx"; http_uri; nocase; content:"paypal-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007241; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/h/login"; http_uri; nocase; content:"paypal.ufcontent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007242; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/countries"; http_uri; nocase; content:"paypalvsgooglecheckout.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007243; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/countries/"; http_uri; nocase; content:"paypalvsgooglecheckout.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007244; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-login.php"; http_uri; nocase; content:"paypalvsgooglecheckout.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007245; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secure.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"pending-shipping-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007246; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/verifylogin.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"pending-shipping-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007247; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/rmutyaba_pepsi-cola_co_ug/_layouts/15/wopiframe.aspx?guestaccesstoken=q1xrx9cq6omueu0gw5ech36jcmrq7yl45zuzcxjws54%3d&\;docid=1_182d7ec9b7ef240e7b33e879a44314f92&\;wdformid=%7b0692719f%2d1981%2d4f26%2db7cd%2da0e252746cb1%7d&\;action=formsubmit"; http_uri; nocase; content:"pepsicola1-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007248; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ahogan@zookfarmequipment.com_invoice104603_open_onedriveportal/updated_drive_shared_securely_online%20-%20copy"; http_uri; nocase; content:"permajacktulsa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007249; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ahogan@zookfarmequipment.com_invoice104603_open_onedriveportal/updated_drive_shared_securely_online%20-%20copy/"; http_uri; nocase; content:"permajacktulsa.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007250; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-messages/css/login.htm?email=&\;email&\;"; http_uri; nocase; content:"pinkoliveentertainment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007251; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-messages/passport%20alibaba/index.html"; http_uri; nocase; content:"pinkoliveentertainment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007252; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-messages/passport%20alibaba/index.html?email=&\;email&\;flag=isle&\;tracelog=edmfooter&\;biz_type=&\;crm_mtn_tracelog_template=200412047&\;crm_mtn_tracelog_task_id=a72ad2ca-ce11-4a70-b2e8-76fb3ff77ddc&\;crm_mtn_tracelog_from_sys=service_feedback&\;crm_mtn_tracelog_log_id=15532788161"; http_uri; nocase; content:"pinkoliveentertainment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007253; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-messages/passport%20alibaba/index.html?email=&\;email&\;tracelog=notification20160310&\;biz_type=&\;crm_mtn_tracelog_template=200412047&\;crm_mtn_tracelog_task_id=a72ad2ca-ce11-4a70-b2e8-76fb3ff77ddc&\;crm_mtn_tracelog_from_sys=service_feedback&\;crm_mtn_tracelog_log_id=15532788161"; http_uri; nocase; content:"pinkoliveentertainment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007254; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-messages/passport%20alibaba/index.html?email=&\;email&\;tracelog=notificationpipelines2016310&\;biz_type=&\;crm_mtn_tracelog_template=200412047&\;crm_mtn_tracelog_task_id=a72ad2ca-ce11-4a70-b2e8-76fb3ff77ddc&\;crm_mtn_tracelog_from_sys=service_feedback&\;crm_mtn_tracelog_log_id=15532788161"; http_uri; nocase; content:"pinkoliveentertainment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007255; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-messages/passport%20alibaba/index.html?email=&\;email&\;tracelog=notificationtips2016310&\;biz_type=&\;crm_mtn_tracelog_template=200412047&\;crm_mtn_tracelog_task_id=a72ad2ca-ce11-4a70-b2e8-76fb3ff77ddc&\;crm_mtn_tracelog_from_sys=service_feedback&\;crm_mtn_tracelog_log_id=15532788161"; http_uri; nocase; content:"pinkoliveentertainment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007256; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-messages/passport%20alibaba/index.html?email=&\;email&\;url_type=footer_privacy&\;biz_type=&\;crm_mtn_tracelog_template=200412047&\;crm_mtn_tracelog_task_id=a72ad2ca-ce11-4a70-b2e8-76fb3ff77ddc&\;crm_mtn_tracelog_from_sys=service_feedback&\;crm_mtn_tracelog_log_id=15532788161"; http_uri; nocase; content:"pinkoliveentertainment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007257; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-messages/passport%20alibaba/index.html?email=&\;email&\;url_type=footer_term&\;biz_type=&\;crm_mtn_tracelog_template=200412047&\;crm_mtn_tracelog_task_id=a72ad2ca-ce11-4a70-b2e8-76fb3ff77ddc&\;crm_mtn_tracelog_from_sys=service_feedback&\;crm_mtn_tracelog_log_id=15532788161"; http_uri; nocase; content:"pinkoliveentertainment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007258; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-messages/passport%20alibaba/index.html?url_type=header_homepage&\;biz_type=&\;crm_mtn_tracelog_template=200412047&\;crm_mtn_tracelog_task_id=a72ad2ca-ce11-4a70-b2e8-76fb3ff77ddc&\;crm_mtn_tracelog_from_sys=service_feedback&\;crm_mtn_tracelog_log_id=15532788161"; http_uri; nocase; content:"pinkoliveentertainment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007259; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:b:/g/personal/kmulligan_pinnaclepiping_com/esmihwwc101pulhh79v-dccbja_-5jpiysxlhrwjsn-gzg?e=4:6wmuun"; http_uri; nocase; content:"pinnaclepipingandservice-my.sharepoint.com:443"; content:"Host"; http_header; classtype:attempted-recon; sid:200007260; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/index.php/?email=bob@example.com"; http_uri; nocase; content:"planetaesportivo.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200007261; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"plconlinesupport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007262; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"plcsystemsupport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007263; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/pasi_puumalainen_plytec_fi/eviubi-o5_rgorvtg1ptinyb5th9mqv-2ev_l8ujkorojg?e=5%3a8603ib&at=9"; http_uri; nocase; content:"plytecfi-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007264; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/pasi_puumalainen_plytec_fi/eviubi-o5_rgorvtg1ptinyb5th9mqv-2ev_l8ujkorojg?e=5:8603ib&\;at=9"; http_uri; nocase; content:"plytecfi-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007265; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/pasi_puumalainen_plytec_fi/_layouts/15/wopiframe.aspx?sourcedoc={8f0414f2-e7a8-46f4-a2bb-d38353ed20d6}&\;action=default&\;originalpath=ahr0chm6ly9wbhl0zwnmas1tes5zagfyzxbvaw50lmnvbs86bzovzy9wzxjzb25hbc9wyxnpx3b1dw1hbgfpbmvux3bsexrly19mas9fdklvqkktbzvfukdvcnzuzzfqdelowui1vgg5bxf2ltjlvl9mohvka09sb2pnp3j0aw1lpxvysjgtvnb2mtbn"; http_uri; nocase; content:"plytecfi-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007266; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/b6c84/homepage"; http_uri; nocase; content:"pointlinebillingreport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007267; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/b6c84/homepage/"; http_uri; nocase; content:"pointlinebillingreport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007268; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ec391/homepage"; http_uri; nocase; content:"pointlinebillingreport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007269; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/polityka-prywatnosci"; http_uri; nocase; content:"pomoc.o2.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200007270; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/comic/fashionable/"; http_uri; nocase; content:"poorlydrawnlines.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007271; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2021/03/blog-post.html"; http_uri; nocase; content:"post-swis.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007272; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2021/03/blog-post.html"; http_uri; nocase; content:"post-swiszland.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007273; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/index"; http_uri; nocase; content:"posteallert.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007274; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/form-builder/i/27476566#page"; http_uri; nocase; content:"powr.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200007275; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/form-builder/i/27476655#page"; http_uri; nocase; content:"powr.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200007276; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/form-builder/i/27476680#page"; http_uri; nocase; content:"powr.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200007277; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/form-builder/i/27476783#page"; http_uri; nocase; content:"powr.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200007278; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/e-bay.freelistings-offers-today-10000listings-28323d.prettypugpuppies.com"; http_uri; nocase; content:"prettypugpuppies.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007279; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/e-bay.freelistings-offers-today-10000listings-28323d.prettypugpuppies.com/"; http_uri; nocase; content:"prettypugpuppies.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007280; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/dallas_profab-tx_com/_layouts/15/wopiframe.aspx?guestaccesstoken=zzchaiolamqsl2s1hkyuny81zdqrmrfihcsymqjloky%3d&docid=1_1c1e697af1a45427a9aa5269bfae2d689&wdformid=%7bffb3b837%2d02f5%2d4bea%2da341%2de2d3c817901d%7d&action=formsubmit"; http_uri; nocase; content:"profabtxtest-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007281; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/album.asp?id=61737"; http_uri; nocase; content:"progarchives.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007282; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url?k=1d4614ec17334d4a.1d465a2d-45b66b5f372e82c4&\;u=http://www.standrew.co.kr/bluead/editor/uploaded/img/caslog1/cas.auth.sc.edu/uofsc.html"; http_uri; nocase; content:"protect2.fireeye.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007283; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/0193/webscr"; http_uri; nocase; content:"proxima-net.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007284; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/0193/webscr/"; http_uri; nocase; content:"proxima-net.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007285; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/emailfwd/show.php?usernum=3669541711&\;formid=3811"; http_uri; nocase; content:"pub43.bravenet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007286; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/#justin.randall@aviva.com"; http_uri; nocase; content:"pxrnblpajwxjmhjukfkfkrwaww-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007287; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/0/?i=i&\;0=info@google.com"; http_uri; nocase; content:"qare.nl"; content:"Host"; http_header; classtype:attempted-recon; sid:200007288; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/acsvc"; http_uri; nocase; content:"qps.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200007289; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/lrodriguez_qualita_es/_layouts/15/wopiframe.aspx?guestaccesstoken=x6egjunw ncgnemfdqjrmoajqkuc9c41sq13edqfoeu=&\;docid=1_16dc35173dd06466fa8c37e332833f0bd&\;wdformid={67d0feef-08d4-4d0a-8a25-0d2c9b0a2eed}/&\;action=formsubmit"; http_uri; nocase; content:"qualitasc-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007290; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/lrodriguez_qualita_es/_layouts/15/wopiframe.aspx?guestaccesstoken=x6egjunw%2bncgnemfdqjrmoajqkuc9c41sq13edqfoeu%3d&docid=1_16dc35173dd06466fa8c37e332833f0bd&wdformid=%7b67d0feef%2d08d4%2d4d0a%2d8a25%2d0d2c9b0a2eed%7d%2f&action=formsubmit"; http_uri; nocase; content:"qualitasc-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007291; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/lrodriguez_qualita_es/_layouts/15/wopiframe.aspx?guestaccesstoken=x6egjunw%2bncgnemfdqjrmoajqkuc9c41sq13edqfoeu%3d&docid=1_16dc35173dd06466fa8c37e332833f0bd&wdformid=%7b67d0feef%2d08d4%2d4d0a%2d8a25%2d0d2c9b0a2eed%7d%3e%2f&action=formsubmit"; http_uri; nocase; content:"qualitasc-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007292; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/lrodriguez_qualita_es/_layouts/15/wopiframe.aspx?guestaccesstoken=x6egjunw%2bncgnemfdqjrmoajqkuc9c41sq13edqfoeu%3d&docid=1_16dc35173dd06466fa8c37e332833f0bd&wdformid=%7b67d0feef%2d08d4%2d4d0a%2d8a25%2d0d2c9b0a2eed%7d&action=formsubmit"; http_uri; nocase; content:"qualitasc-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007293; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/qv7malu8n7cz/you-have-some-messages-pending"; http_uri; nocase; content:"quip.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007294; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/c?u=https://yanamholidays.com/b00-b26n5-82m-c04b-o84v-13h-e66-t38e-c90?m5=eric.stockland@iextrading.com"; http_uri; nocase; content:"r.smore.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007295; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2020/05"; http_uri; nocase; content:"rabofree.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007296; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2020/05/blog-post.html"; http_uri; nocase; content:"rabofree.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007297; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2020/05?m=1"; http_uri; nocase; content:"rabofree.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007298; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2020?m=1"; http_uri; nocase; content:"rabofree.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007299; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fmo8ditspgnkniqpf82vyln71lojfpeubd2ovwhkc4uqnlp2usy2emaghyzmnohprkengv7sacj"; http_uri; nocase; content:"railcarpatient.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007300; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fmo8ditspgnkniqpf82vyln71lojfpeubd2ovwhkc4uqnlp2usy2emaghyzmnohprkengv7sacj/"; http_uri; nocase; content:"railcarpatient.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007301; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ilw885esfasfjbqvydtutkr6say02mvlhsuqxiimtb2cmsiv5cpzwgfyhezjaufhm97tsqgl2iy"; http_uri; nocase; content:"railcarpatient.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007302; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ilw885esfasfjbqvydtutkr6say02mvlhsuqxiimtb2cmsiv5cpzwgfyhezjaufhm97tsqgl2iy/"; http_uri; nocase; content:"railcarpatient.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007303; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/qwyrwhmqaxuwiqi6ag3klus2gooavk4lhcmdjzeu7yqpyzw9patb5ldlk2vfmz1tcnhwnlquuhu"; http_uri; nocase; content:"railcarpatient.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007304; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/qwyrwhmqaxuwiqi6ag3klus2gooavk4lhcmdjzeu7yqpyzw9patb5ldlk2vfmz1tcnhwnlquuhu/"; http_uri; nocase; content:"railcarpatient.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007305; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2idafk?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007306; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/7fzdj9?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007307; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/7wnpy8?costumer_service_facebook"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007308; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/8oxsb2?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007309; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/asmisi"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007310; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eyltiv"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007311; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fevxt7?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007312; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/j4dlom?confirmation"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007313; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lknt5i?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007314; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lljvgs?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007315; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lsenqd?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007316; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lugdzr?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007317; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/md5ssz?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007318; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/nazgke?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007319; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ndehti/"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007320; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p0jcx2?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007321; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/piw36n?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007322; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/qpyb2e?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007323; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/qqupv0?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007324; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rhrxnc?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007325; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rv7acm?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007326; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/sekcct"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007327; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/t1r97k?confirmation"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007328; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/t4dcgl?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007329; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ugymlt"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007330; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v75v1u?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007331; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wkt0v0?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007332; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/xdko3t"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007333; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yzuh50?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007334; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zfnooy?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007335; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zihm3f?facebook_update"; http_uri; nocase; content:"rb.gy"; content:"Host"; http_header; classtype:attempted-recon; sid:200007336; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/payback/"; http_uri; nocase; content:"real-markt.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200007337; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/0k8bltd"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007338; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/3ads20"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007339; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/4yc7w4o"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007340; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/668b5"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007341; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/8k8kt"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007342; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/8x687fo"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007343; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/96s871"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007344; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/a7n4y3x"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007345; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/adobefileshare"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007346; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ahcz51u"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007347; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gl7lnie"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007348; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/iejlmfn#ansonj@prepaidlegal.com"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007349; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/iejlmfn#charleswood@prepaidlegal.com"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007350; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/iejlmfn#stanlennard@pplsi.com"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007351; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s4aowlb#notices@itau-unibanco.com.br"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007352; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tracking-pack"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007353; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/w1lrupp"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007354; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zikqv8f?email=eimaste@stinpriza.org&\;domain=stinpriza.orgwebapp*"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007355; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zitln6v"; http_uri; nocase; content:"rebrand.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007356; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/drwxe/customer_center/customer-idpp00c129/myaccount/signin"; http_uri; nocase; content:"receptfritt-cialis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007357; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/drwxe/customer_center/customer-idpp00c129/myaccount/signin/"; http_uri; nocase; content:"receptfritt-cialis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007358; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/drwxe/customer_center/customer-idpp00c514/myaccount/signin"; http_uri; nocase; content:"receptfritt-cialis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007359; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/drwxe/customer_center/customer-idpp00c514/myaccount/signin/"; http_uri; nocase; content:"receptfritt-cialis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007360; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/drwxe/customer_center/customer-idpp00c644/myaccount/signin"; http_uri; nocase; content:"receptfritt-cialis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007361; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/drwxe/customer_center/customer-idpp00c644/myaccount/signin/"; http_uri; nocase; content:"receptfritt-cialis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007362; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/drwxe/customer_center/customer-idpp00c654/myaccount/signin"; http_uri; nocase; content:"receptfritt-cialis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007363; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?u=mm.1und1.de//dereferrer?target=ahr0chm6ly9maxjlymfzzxn0b3jhz2uuz29vz2xlyxbpcy5jb20vdjavyi9xdwu2lte4n2yzlmfwchnwb3quy29tl28vzg9tywlums5odg1sp2fsdd1tzwrpyszza29sdmvya2v0lnnlymvuz3quagfyanumdg9rzw49mdnhmdmxyzytzte1ms00otg4ltlhytqtmdhmzdjjotawmdizjnnrb2x2zxjrzxquc2vizw5ndc5oyxjqdsnizw5ndc5oyxjqdubza29sdmvya2v0lnnl&\;key=fd5de1d096b38be9fffd6ddc1948df4f"; http_uri; nocase; content:"redirect.viglink.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007364; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p-351075-95303b56fd8597a1946dc433811ae477-239262-78/?cl=1&\;n=39&\;l=o&\;u=https%3a%2f%2fwww.google.com%2furl%3fsa%3dt%26rct%3dj%26q%3d%26esrc%3ds%26source%3dweb%26cd%3d%26cad%3drja%26uact%3d8%26ved%3d2ahukewiz1pcljixqahweoxekhqkhbggqfjacegqiarab%26url%3dhttps%253a%252f%252fwww.lab4rent.it%252fofferte%252fhonda-sh-150-abs-bauletto-e-parabrezza%252f%26usg%3daovvaw0uufychhtdy_ozq1pxdtip"; http_uri; nocase; content:"redirect.voici-news.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007365; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cr/redirec/?und=marden08@optusnet.com.au"; http_uri; nocase; content:"redlinegym.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007366; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/beverley_latham_redlinerecruitment_com/elyngikq5ufbqvwgcsqwtt4b1njgntt_lj45lr_y-735iw?e=5%3ajitv78&\;at=9"; http_uri; nocase; content:"redlinerecruitment353-my.sharepoint.com:443"; content:"Host"; http_header; classtype:attempted-recon; sid:200007367; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/beverley_latham_redlinerecruitment_com/elyngikq5ufbqvwgcsqwtt4b1njgntt_lj45lr_y-735iw?e=5:jitv78&\;at=9"; http_uri; nocase; content:"redlinerecruitment353-my.sharepoint.com:443"; content:"Host"; http_header; classtype:attempted-recon; sid:200007368; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ro/"; http_uri; nocase; content:"redredget.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007369; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"registerpayee-support.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007370; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"remove-unauthorised-lloydspayee-connect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007371; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"remove-unauthorised-payee-connect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007372; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/1xrr1y"; http_uri; nocase; content:"reurl.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200007373; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/brkoqe"; http_uri; nocase; content:"reurl.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200007374; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/gvjolp?co=muj3e"; http_uri; nocase; content:"reurl.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200007375; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/jdegy2"; http_uri; nocase; content:"reurl.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200007376; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/oleeqj"; http_uri; nocase; content:"reurl.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200007377; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/qd7na2"; http_uri; nocase; content:"reurl.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200007378; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"review-authorised-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007379; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"review-flagged-payment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007380; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2021/02/blog-post.html"; http_uri; nocase; content:"riderctposten.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007381; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secure.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"rm-parcel6297.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007382; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/user.php?&sessionid=f01f18eaec89816094bc3868f662d236&securessl=true"; http_uri; nocase; content:"rm-parcel6297.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007383; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/verifylogin.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"rm-parcel6297.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007384; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/srichlin_rmact_com/_layouts/15/wopiframe.aspx?guestaccesstoken=492wqqtzlbznzq7qdpemrme%2bi%2bhghqqnqlo250fbc9i%3d&docid=1_10c4e2ffbd9ec47cbbc6f0253baa7b64d&wdformid=%7b914c12ed%2d68e0%2d4419%2db8b0%2ded5f7e09de29%7d&action=formsubmit"; http_uri; nocase; content:"rmact-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007385; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/comercial1_rolcoshipping_com1/eruuxky76yxlk7vzdfzrfzybicm0kmv7-914pwcpo9g4mq?e=ppogt"; http_uri; nocase; content:"roldanlogistica2-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007386; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2020/10/roni-gelo.html"; http_uri; nocase; content:"ronigelo.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007387; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:b:/g/personal/enebelitsky_rcc_mass_edu/er4mnitiqezdprvsiljksn4bexpjqkfwl8c3bunhudv4ww?e=4%3a2anva6&at=9"; http_uri; nocase; content:"roxburycommunitycolleg798-my.sharepoint.com:443"; content:"Host"; http_header; classtype:attempted-recon; sid:200007388; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secure.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"royalmail.redeliverysupport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007389; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/verifylogin.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"royalmail.redeliverysupport.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007390; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/9ff05980?billingid=ahmutkmttd"; http_uri; nocase; content:"rplg.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200007391; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eed3e76c0?action=resetpassword&\;code="; http_uri; nocase; content:"rplg.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200007392; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mijn-ing-sca"; http_uri; nocase; content:"rplg.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200007393; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/spka21"; http_uri; nocase; content:"rplg.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200007394; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/web-ve"; http_uri; nocase; content:"rplg.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200007395; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/includes/.login/gmail/serviceloginauth/index.php?service=loginauth0"; http_uri; nocase; content:"russianamericanballet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007396; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2019conta"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007397; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/abngeleid"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007398; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/amr2019caixa"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007399; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/awbert"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007400; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dispositivocaixa"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007401; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eelog"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007402; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fx9xc"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007403; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ingincasso"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007404; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kpkkpkkpk"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007405; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login-fb"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007406; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mijnrakker400"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007407; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/onlnedesk"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007408; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rabobank-bericht"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007409; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rabonl"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007410; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rzsxp"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007411; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/sparka-de"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007412; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/szm8g"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007413; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/woning"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007414; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/woning-web"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007415; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wpyih"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007416; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wv5xj"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007417; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/x02-m"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007418; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/xpfio"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007419; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/xsdbx"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007420; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/xzod5"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007421; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ykzim"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007422; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yqnun"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007423; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ytk-r"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007424; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yw5o-"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007425; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yz3zs"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007426; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zce-h"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007427; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zfq3j/"; http_uri; nocase; content:"s.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007428; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?m=0"; http_uri; nocase; content:"sajkd12.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007429; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/la-banque-postale.html"; http_uri; nocase; content:"sandert12.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007430; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/backup/wp-content/plugins/dude/configuration/themes/mak/index.php?email=&\;amp"; http_uri; nocase; content:"sanjoaquinvalleybrewfest.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007431; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/backup/wp-content/plugins/dude/configuration/themes/mak/index.php?email=contact@ironscales.com&\;id=432526cfdsd6567656dgvdhytdfbhjgff4536365353"; http_uri; nocase; content:"sanjoaquinvalleybrewfest.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007432; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/sbot"; http_uri; nocase; content:"sateegourmet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007433; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/connection/direct.php"; http_uri; nocase; content:"satkaniaiit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007434; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/m_qasim_saudidiesel_com_sa/_layouts/15/wopiframe.aspx?guestaccesstoken=%2bvewh1hxilmjxjegf03nplmtt44vsijjfo4rv6tv3tw%3d&docid=1_151563f3f0c0f4a81b32bd7e4b29534f5&wdformid=%7b7d9c12b3%2d74c6%2d45d0%2d9376%2d8ababcf7821d%7d&action=formsubmit"; http_uri; nocase; content:"saudidiesel-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007435; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mailbox_upgrade/index.php?email="; http_uri; nocase; content:"savageconquest.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007436; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/maint/index.html"; http_uri; nocase; content:"savana-restaurant.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007437; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/maint/rs/outlook-rd114/login.html"; http_uri; nocase; content:"savana-restaurant.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007438; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/index2.php"; http_uri; nocase; content:"schoolkoet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007439; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/macros/s/akfycbwc6y7yuxmti0kr8e5d3m62ucmsuhkihk-zzxby7xngxeopneyy/exec"; http_uri; nocase; content:"script.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007440; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/halifax/login.php"; http_uri; nocase; content:"secure-authoriserequest.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007441; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"secure-halifaxaccount.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007442; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/halifax"; http_uri; nocase; content:"secure-online-payeemagement.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007443; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/halifax/login.php"; http_uri; nocase; content:"secure-online-payeemagement.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007444; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/admin"; http_uri; nocase; content:"securecustomer-connect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007445; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login.php"; http_uri; nocase; content:"securehalifaxonline-account.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007446; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/vendor/phpunit/phpunit/src/util/php/logs.php"; http_uri; nocase; content:"securematicsrecruitment.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200007447; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal"; http_uri; nocase; content:"securepayeerequest.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007448; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/postenno_9.html"; http_uri; nocase; content:"seonewsservic.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007449; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2020/04/blog-post_10.html"; http_uri; nocase; content:"servicefacture.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007450; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/hnffkjptnl.html?hvtewzrdxtfcvgvbhjinikomjibhuvgfcdgxsexrrdcfgvhbjninuhygv"; http_uri; nocase; content:"sfhiit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007451; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/track/1602830813431.png?eid=-526912765"; http_uri; nocase; content:"sgndr.online"; content:"Host"; http_header; classtype:attempted-recon; sid:200007452; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?ss"; http_uri; nocase; content:"sgunapsslgnincnt.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007453; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/1fni_ent2sao6wqv0vzdn7g8nl9d"; http_uri; nocase; content:"share.hsforms.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007454; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/1owoqghkbqdo-dfbltgexeq4g63f"; http_uri; nocase; content:"share.hsforms.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007455; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/1vmfcedqbthgdtbhvllcluw4jjqt?email=abuse@chem.uzh.ch"; http_uri; nocase; content:"share.hsforms.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007456; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/assabetindustries/priv8/priv8/index.html"; http_uri; nocase; content:"shithut.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007457; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/so/29nxdzhlu/c?w=6cqhoe6cvp5sgmmsaghxgp5ym3iyanqygauqwdhnqmi.eyj1ijoiahr0chm6ly93yxrhc2lpcmpyawjoys5ibg9ilmnvcmuud2luzg93cy5uzxqvdgvzdgluzy9tcgxuynzjegrmlmh0bwwilcjyijoinzewowuwzgitnjy5mi00ngrhltuzm2qtnjaynzk1zje0ymuxiiwibsi6im1hawwilcjjijoimdawmdawmdatmdawmc0wmdawltawmdatmdawmdawmdawmdawin0#qs=r-agikbadkfkgdhdjaehfdidgafgccdigaehkkdaehkkdababaibadccaccaccjhackcjaibjfhacb"; http_uri; nocase; content:"shoutout.wix.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007458; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/a6ysa"; http_uri; nocase; content:"shrunken.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007459; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/url_redirector.php?url=a6yt8"; http_uri; nocase; content:"shrunken.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007460; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/jh_silitrade_com/_layouts/15/wopiframe.aspx?guestaccesstoken=8vzaur%2f5gb%2fwmmsfdszlpfueeb0ml%2fzkiljmp9hfa0o%3d&\;docid=1_14a3d3f238b844155b59bb08023697365&\;wdformid=%7b3395edb6%2d941b%2d49a6%2dbd04%2dc039ca27bb2b%7d&\;action=formsubmit"; http_uri; nocase; content:"silitrade-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007461; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/3cd35d"; http_uri; nocase; content:"simp.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007462; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/gs1cq9"; http_uri; nocase; content:"simp.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007463; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/h45c89"; http_uri; nocase; content:"simp.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007464; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/hqtfwb"; http_uri; nocase; content:"simp.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007465; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/jwj7gr"; http_uri; nocase; content:"simp.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007466; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/jylrtp"; http_uri; nocase; content:"simp.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007467; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/wlgtvw"; http_uri; nocase; content:"simp.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007468; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/publish/xhrdvc"; http_uri; nocase; content:"simp.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007469; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/e9d24c72/23524457"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007470; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/habbotuttogratis"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007471; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/habbotuttogratis/assignments"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007472; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/libretyreserve"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007473; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/libretyreserve/"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007474; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/privtacntpaqes4/"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007475; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/protectedinmprovmnt44/"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007476; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/verifycheckpointpaqes/"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007477; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/site/xempaqesrecover/"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007478; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/1bjpvhgsamfbdvkxs2jhoxopuwmz5n/"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007479; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/8756-jketf-7856ierft/home"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007480; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/andorra-correu111/accueil"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007481; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/bt-cloud-workk/home"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007482; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/btconnect-vm/btc0nnect-vm-weebly-com"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007483; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/espacemessagerieorangesms/accueil"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007484; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/hijadgvoivfeo/home"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007485; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/ligne-telephonique"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007486; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/nmcoxcc"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007487; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/paypal-customer-services"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007488; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/paypal-customer-services/"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007489; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/paypal-loginn/"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007490; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/paypalloginns/"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007491; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/paypalloginsignin"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007492; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/paypalloginsignin/"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007493; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/paypalloginusa"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007494; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/paypalloginusa/"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007495; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/post-ecoute-vocale/accueil"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007496; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/rcgvhjy-fxcgvhbjhb/?ectrans=1"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007497; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/service-orange/accueil"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007498; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/sfdfsdfbay/home"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007499; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/view/taquetti/p%c3%a1gina-inicial"; http_uri; nocase; content:"sites.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007500; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/alorusso_sixpointpartners_com/_layouts/15/wopiframe.aspx?guestaccesstoken=hxfp2bmr0ktabr59lyxka8q hfcrmcxgcfpopjkxljo=&\;docid=1_149595c6d19844cadb9e684de0672e5e4&\;wdformid={e23eb318-3dee-48ac-acb4-80fbe19c93a1}&\;action=formsubmit"; http_uri; nocase; content:"sixpointpartners-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007501; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/alorusso_sixpointpartners_com/_layouts/15/wopiframe.aspx?guestaccesstoken=hxfp2bmr0ktabr59lyxka8q%20hfcrmcxgcfpopjkxljo=&\;docid=1_149595c6d19844cadb9e684de0672e5e4&\;wdformid={e23eb318-3dee-48ac-acb4-80fbe19c93a1}&\;action=formsubmit"; http_uri; nocase; content:"sixpointpartners-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007502; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/alorusso_sixpointpartners_com/_layouts/15/wopiframe.aspx?guestaccesstoken=hxfp2bmr0ktabr59lyxka8q%2bhfcrmcxgcfpopjkxljo%3d&docid=1_149595c6d19844cadb9e684de0672e5e4&wdformid=%7be23eb318%2d3dee%2d48ac%2dacb4%2d80fbe19c93a1%7d&action=formsubmit"; http_uri; nocase; content:"sixpointpartners-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007503; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/link?url=http://taijishentie.com/js/index.htm?http://us.battle.net/login/en/?ref=http://xwnrssfus.battle.net/d3/en/index&\;app=com-d3"; http_uri; nocase; content:"slack-redir.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007504; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/link?url=https://bit.ly/3lefgwg"; http_uri; nocase; content:"slack-redir.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007505; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/link?url=https://dhtgfhxfgs.com/doc"; http_uri; nocase; content:"slack-redir.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007506; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/45454/next.php?ss=2&\;email=ywnjb3vudhnwyxlhymxlqgdjz2ftaw5nlmnvbq=="; http_uri; nocase; content:"smart2host.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007507; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/crossventure/ofc1"; http_uri; nocase; content:"smartblackout.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007508; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/crossventure/ofc1/s/?signin=d41d8cd98f00b204e9800998ecf8427e&\;auth=dd11bc9311e6d3e4aba05cafa1d6eee0b425154916ddc68567f8b8b1d015d789e99b7ece"; http_uri; nocase; content:"smartblackout.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007509; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dhlexpil/"; http_uri; nocase; content:"soicaulodechuan.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007510; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/info_solbjerg-maskinstation_dk/eofwmdvfi5jfirpoke71zacbvfoehvpo1ye_r6jsxti-hg?e=ekiser"; http_uri; nocase; content:"solbjerg-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007511; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v1/account/reset?plid=1&\;isc=gdbb3398&\;token=e4f8ae3b-ae47-4586-9555-2c4f7b23d136&\;realm=pass&\;user_id=dd90070c-aa0f-4a5d-b21b-ec96eb0208a0&\;app=email&\;username=richard.wang%40harmonia"; http_uri; nocase; content:"sso.secureserver.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007512; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bp/login.php?l=_jehfuq_vjoxk0qwhtogydw1774256418&\;fid.13inboxlight.aspxn.1774256418&\;fid.125289964252813inboxlight99642_product-email&\;email="; http_uri; nocase; content:"ssplsoft.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007513; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/p/vrm99k/giulio"; http_uri; nocase; content:"start.me"; content:"Host"; http_header; classtype:attempted-recon; sid:200007514; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/f.aspx?t=37"; http_uri; nocase; content:"startimes.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007515; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/sia/acrobat/error.php"; http_uri; nocase; content:"stmik-yadika.ac.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007516; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/update2021/update/webmail.php?userid=andrea.wykel@hp.com"; http_uri; nocase; content:"stmik-yadika.ac.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007517; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/update2021/update/yahoo.php"; http_uri; nocase; content:"stmik-yadika.ac.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007518; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-content/themes/twentyfifteen/css/read/chinavali/index.php?email=jsmith@imaphost.com"; http_uri; nocase; content:"stolizaparketa.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200007519; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/appspotv450i7r8h9vf9y6yt8uiuft58f7uf5yye36u0jtyf78uuyfyy/index.html"; http_uri; nocase; content:"storage.cloud.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007520; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/noomooonplotoon-ogt0098709lot/mlindex.html#user@domain.org"; http_uri; nocase; content:"storage.cloud.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007521; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/officpcpspbcncuser.appspot.com/index.htm#jbell@legalshield.com"; http_uri; nocase; content:"storage.cloud.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007522; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/prprhrhprc.appspot.com/index.htm#oncall-infra@eqiom.com"; http_uri; nocase; content:"storage.cloud.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007523; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rqraaqqax3xa.appspot.com/index.htm#memberservices@legalshield.com"; http_uri; nocase; content:"storage.cloud.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007524; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/rqraaqqax3xa.appspot.com/index.htm#no@nope.com"; http_uri; nocase; content:"storage.cloud.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007525; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/staging.maintainancecomponeta.appspot.com/bsnnindex.html"; http_uri; nocase; content:"storage.cloud.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007526; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/user517497679326978.appspot.com/index.html"; http_uri; nocase; content:"storage.cloud.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007527; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/user517497679326978.appspot.com/index.html#samsnow@tjsnow.com"; http_uri; nocase; content:"storage.cloud.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007528; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/user7773578ixh1092839.appspot.com/index.html"; http_uri; nocase; content:"storage.cloud.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007529; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/user7773578ixh1092839.appspot.com/index.html#estewart30@legalshield.com"; http_uri; nocase; content:"storage.cloud.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007530; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/user7773578ixh1092839.appspot.com/index.html#john.smith@gmail.com"; http_uri; nocase; content:"storage.cloud.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007531; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/xzrdzcdruerp.appspot.com/index.html#ricardo.rodriguez@cgexchange.org"; http_uri; nocase; content:"storage.cloud.google.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007532; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/1827435283/1827435283.html"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007533; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/allenrr-22/appclg.htm"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007534; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/awydjhabjcakucajjbhsa7.appspot.com/eafdcas/kakvajdbvkjdbadvujk.html"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007535; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/e6y1upwj2w0yjc/33b40ae10cd793a06ccea739938a42ce.html?res=ee5bb5653ddc24be4512dfe3c8cdcebb"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007536; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/navy/nfcu.htm"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007537; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/regularizeambiente/acesso.html"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007538; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/segurocomcliente/acesso.html"; http_uri; nocase; content:"storage.googleapis.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007539; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/topology/rest/1.0/file/get/8122054091/"; http_uri; nocase; content:"storage.ning.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007540; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/p_brouwer_structin_nl/ehu4nhcxmmlmrmou4we1fpsb5lqpufe4sslse_xjh33dea?e=9dtcpc"; http_uri; nocase; content:"structin-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007541; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/vcarrion_students_imperial_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=rvz44awzcpdubusreabukfouvj04snc94kmlpod04h4%3d&\;docid=1_1acb4510b85ac413f9ea166e72d4bbca4&\;wdformid=%7b3cad2e15%2d9297%2d423e%2d87b0%2db890b72dfaa2%7d&\;action=formsubmit"; http_uri; nocase; content:"studentsimperial-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007542; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/vcarrion_students_imperial_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=rvz44awzcpdubusreabukfouvj04snc94kmlpod04h4%3d&docid=1_1acb4510b85ac413f9ea166e72d4bbca4&wdformid=%7b3cad2e15%2d9297%2d423e%2d87b0%2db890b72dfaa2%7d&action=formsubmit"; http_uri; nocase; content:"studentsimperial-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007543; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/login/tanvalidate.php"; http_uri; nocase; content:"suchenm0bile.de"; content:"Host"; http_header; classtype:attempted-recon; sid:200007544; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/images/smilies/comfirme-compte-demande.php"; http_uri; nocase; content:"suitecred.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200007545; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/caniasj_potsdam_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=3iraoz5qrcw0w4%2frehotcj25mgvldlzenlokue%2bfudw%3d&docid=1_10850bdc012e8450fb8f3297a80b3ecbb&wdformid=%7b955fb703-afe5-44b1-b0ca-d52fccb3199c%7d&action=formsubmit&cid=5df7ddf9-38f3-4abe-b529-7a3c4779e246"; http_uri; nocase; content:"sunypotsdam-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007546; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/adrian_ramos_superpark_com_hk/_layouts/15/wopiframe.aspx?guestaccesstoken=vofjngnui%2fslbameorlq62qlg8mcdnpo1dizu6i%2bc1m%3d&\;docid=1_124bbb2f682ca4c7daba6cec6ee34dfb9&\;wdformid=%7ba85c8abe%2d68be%2d43dd%2d91f3%2db397386186be%7d&\;action=formsubmit"; http_uri; nocase; content:"superpark-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007547; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/index"; http_uri; nocase; content:"supportpersonalcredit.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007548; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/opwc"; http_uri; nocase; content:"surl.li"; content:"Host"; http_header; classtype:attempted-recon; sid:200007549; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s3/6092349/royal-mail-royal-mail-group-ltd"; http_uri; nocase; content:"survey.alchemer.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007550; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/form/5e23c40fb533f62621f5252d#form/0"; http_uri; nocase; content:"surveyheart.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007551; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/form/5e5b8d772e417841d96ee7af#form/0"; http_uri; nocase; content:"surveyheart.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007552; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/form/5f7840827687c759eed006a1#welcome"; http_uri; nocase; content:"surveyheart.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007553; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/s/2vze"; http_uri; nocase; content:"surveylegend.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007554; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/pranjali_chandurkar_nmims_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=668cyp4s%2fwcmx8rj223bvjfwdvtryffzfpyarbrueha%3d&\;docid=1_1916b69db182644fead12e874cad930c4&\;wdformid=%7bcd4093b9%2ddfae%2d49f1%2dadde%2df32fbe93b271%7d&\;action=formsubmit"; http_uri; nocase; content:"svkmmumbai-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007555; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pritchard_steve@btconnect.com"; http_uri; nocase; content:"swamitradingcompany.in"; content:"Host"; http_header; classtype:attempted-recon; sid:200007556; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/.kw"; http_uri; nocase; content:"switch.com.kw"; content:"Host"; http_header; classtype:attempted-recon; sid:200007557; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/.kw/"; http_uri; nocase; content:"switch.com.kw"; content:"Host"; http_header; classtype:attempted-recon; sid:200007558; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/.si/"; http_uri; nocase; content:"switch.com.kw"; content:"Host"; http_header; classtype:attempted-recon; sid:200007559; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ht"; http_uri; nocase; content:"switch.com.kw"; content:"Host"; http_header; classtype:attempted-recon; sid:200007560; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dhl/dhl/"; http_uri; nocase; content:"sydprinting.com.au"; content:"Host"; http_header; classtype:attempted-recon; sid:200007561; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/sylvia_sylviamclain_com/_layouts/15/wopiframe.aspx?guestaccesstoken=upb1crnmnypljdqqckkarbjkn2rlitq4otpljlyysoe%3d&docid=1_1c137d9cfdf0c4518a86e6db683563e30&wdformid=%7b79c56373%2d6e2c%2d4f1c%2d9679%2d6c47534174d5%7d&action=formsubmit"; http_uri; nocase; content:"sylviamclain-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007562; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/sylvia_sylviamclain_com/_layouts/15/wopiframe.aspx?guestaccesstoken=upb1crnmnypljdqqckkarbjkn2rlitq4otpljlyysoe=&\;docid=1_1c137d9cfdf0c4518a86e6db683563e30&\;wdformid={79c56373-6e2c-4f1c-9679-6c47534174d5}&\;action=formsubmit"; http_uri; nocase; content:"sylviamclain-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007563; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dgd6k2bvte"; http_uri; nocase; content:"t.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200007564; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fnywthirp9?amp=1"; http_uri; nocase; content:"t.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200007565; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/xl4n3av7rl?amp=1"; http_uri; nocase; content:"t.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200007566; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/7gqqzu8txmqgtkd4zyah"; http_uri; nocase; content:"t.ly"; content:"Host"; http_header; classtype:attempted-recon; sid:200007567; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/r/?id=h3f33892b,21cd8ca0,1feaf465&\;p1=dataconso%20-%20clients%20annuels%20sans%20remensu&\;p2=0102925082"; http_uri; nocase; content:"t.mails.total.direct-energie.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007568; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/r/?id=h4b503239,418a056e,416f6e60"; http_uri; nocase; content:"t.marketing1.william-reed.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007569; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-admin/js//sbhds/sbc/sbc/sbcglobal.net.htm"; http_uri; nocase; content:"talkingflight.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007570; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/de/kontrolle/spark/"; http_uri; nocase; content:"tan-geraet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007571; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/accueil/review_rating.php?huge=gfpt11na1kpwu00&add=red&taken=possible"; http_uri; nocase; content:"taozhupipi.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007572; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/v/1mxfdc7ty112vxsv"; http_uri; nocase; content:"taskade.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007573; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:w:/g/personal/covid_tcta_co_za1/ebjxoc27czhhowhytqdp-3ibzjxhp5dd9_a-vm8e5vzs0a?e=tehygt"; http_uri; nocase; content:"tcta-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007574; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:u:/g/personal/nongluck_m_attconsult_com/eumhzaoxwpngi0mled8_gs0blnumsbrsk_gjzqcnte543g?download=1&\;utm_content=newclient&\;utm_campaign=website&\;utm_source=julywazepromo&\;utm_medium=email"; http_uri; nocase; content:"teamgrouppcl-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007575; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cargando....html"; http_uri; nocase; content:"tecnicsupportdsd.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007576; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/inicio.html"; http_uri; nocase; content:"tecnicsupportdsd.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007577; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/files/system32/procesosdeseguridadhb/170.51.165.16679791/agregar/telefono/contacto/logonoperacionservlet.html"; http_uri; nocase; content:"tecsuport.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200007578; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/files/system32/procesosdeseguridadhb/170.51.165.16679791/agregar/telefono/contacto/operacion-exitosa.html"; http_uri; nocase; content:"tecsuport.com.br"; content:"Host"; http_header; classtype:attempted-recon; sid:200007579; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bk18xy"; http_uri; nocase; content:"tek.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200007580; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mqp9"; http_uri; nocase; content:"tek.link"; content:"Host"; http_header; classtype:attempted-recon; sid:200007581; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/facebook-06-28"; http_uri; nocase; content:"telegra.ph"; content:"Host"; http_header; classtype:attempted-recon; sid:200007582; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wrtyt5433yhuyr-08-30"; http_uri; nocase; content:"telegra.ph"; content:"Host"; http_header; classtype:attempted-recon; sid:200007583; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eur/login?id=qlfml2nuuxhkrkewz1zos3dirfvnzzzxddzzvc9jzvj0vdfpafdxejfrdzldrlhhd0luvew1mmtwmghamfpgsdvkutc4v0uvatjpudexdgphq1ffy28rdkfjzllzrdjhnzrauu5tbuxwdggxznvnyuxvv08wv24xzgmzrdn2ohfswstxb29uce04ajhkazf5vgn4dufytwrjwly3elbpewrqsefibwnobgpxynvrnjf3mlbfzctntg5wytj2vuczrtnvtupvnjvra1pmou5rmuteyzbtsjfor2vua0ntzdfnyktgumovcwlxk1drwgs4umfzsevrtvm3r3ywmth0de1snlirauzzk1htc1ivckdon3izdfhmamttc0o1axbeyvdxwjdubzrneuvqvlftadnut2q3s05nl0zoagz1ehc"; http_uri; nocase; content:"templatent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007584; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/nam/login?id=uvzmvjvieum4alvzmujneffxmuy3agwvbgzxndbba2rwdhy1qnzut2m1offcvktqqulidjvvzg42nwxuautkk2lcb2d4sxnttzlsqvr6rfdxcld0ruvxodlpshvsbwhebu5gdnpos2xreepkmdbhaudoci9yzy9yvufswegwbkh5mfp0su9rcxcztzdbz1fnundxwnvakzviqng5ddi4ofzntdl4tstoyuhqumpxqugzwfnor1pqnfjut3vysg5fawfyzg1jc0tzsnzynuw2vkzowmz0mmtzmjfpwuszqkgyvud5twf2m21xthfeourydnjiu2vtdvzmref3ritzchb6elzjn09rvmrsbgdlcmztbxl2dkxpzm1ss0fjqnlsttjmr1q1r3p5zvhyq3a2txhwt2rnaffrzm1asgvqa2g"; http_uri; nocase; content:"templatent.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007585; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/at&t-login.htm"; http_uri; nocase; content:"test102760.test-account.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007586; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/at&t-login.htm"; http_uri; nocase; content:"test103126.test-account.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007587; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/sistance/sfr20/"; http_uri; nocase; content:"the-ly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007588; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wp-includes/sistance/sfr20/?clic="; http_uri; nocase; content:"the-ly.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007589; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/derek_theatrewinterhaven_com/_layouts/15/wopiframe.aspx?guestaccesstoken=nhy1d882gounuk%2bbap1r%2ffp5arte1egvbtjj6mysuce%3d&docid=1_1f0ab3a7dcdec411eb8812066a6069734&wdformid=%7beea09244%2d37af%2d4aac%2d88eb%2d422c6c252377%7d&action=formsubmit"; http_uri; nocase; content:"theatrewh-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007590; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/.mang/att3/"; http_uri; nocase; content:"thehiphoppublicist.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007591; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/.ming/att3/"; http_uri; nocase; content:"thehiphoppublicist.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007592; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/_layouts/15/wopiframe.aspx?guestaccesstoken=b0tjq7uw13ohhsvlvr6vq189xb2ed7p3yoiuxgzs5xu%3d&\;docid=1_127b97513b5664db7a2c23beec6cbdf50&\;wdformid=%7b8bd84c70-967f-4172-8b3b-973c5f74f5a8%7d&\;action=formsubmit&\;cid=18e6e320-2aeb-4aa0-befe-ed946b2e8bd0"; http_uri; nocase; content:"themarbleshop.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007593; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/index2.html"; http_uri; nocase; content:"thermandcondpcha.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007594; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/#jon.doe@example.com"; http_uri; nocase; content:"tifwcrqlrzyhugaazbuicveaum-dot-gle39404049.rj.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007595; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2fy7tz"; http_uri; nocase; content:"tiny.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200007596; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/98f3nz"; http_uri; nocase; content:"tiny.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200007597; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/btinternet56"; http_uri; nocase; content:"tinyurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007598; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/r8dt5vk"; http_uri; nocase; content:"tinyurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007599; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/sd9t35n/?cliente=multiconexoes@terra.com.br/jhyyw8hlac3s5ao9r7mr22fe/imprimir.cgi"; http_uri; nocase; content:"tinyurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007600; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/toqjl4j/?email=firstregistration6@dvla.gov.uk"; http_uri; nocase; content:"tinyurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007601; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/y2czr3ag"; http_uri; nocase; content:"tinyurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007602; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/y3xk7mt7/"; http_uri; nocase; content:"tinyurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007603; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ycx25yp7"; http_uri; nocase; content:"tinyurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007604; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yxb48kqj"; http_uri; nocase; content:"tinyurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007605; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yxry9vf5"; http_uri; nocase; content:"tinyurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007606; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yxvpdevz"; http_uri; nocase; content:"tinyurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007607; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/yyvm8qr5"; http_uri; nocase; content:"tinyurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007608; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/zmmcc9vk/"; http_uri; nocase; content:"tinyurl.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007609; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/#abuse@ionos.com"; http_uri; nocase; content:"tksjunjpdsbqqnpg-dot-asonapa-swesesa.uc.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007610; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/accounts_tomsarros_com_au/_layouts/15/authenticate.aspx"; http_uri; nocase; content:"tomsarroscomau-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007611; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/parevalo_tong464_org/_layouts/15/onedrive.aspx?id=/personal/parevalo_tong464_org/documents/northgate.pdf&\;parent=/personal/parevalo_tong464_org/documents&\;originalpath=ahr0chm6ly90b25nndy0lw15lnnoyxjlcg9pbnquy29tlzpioi9nl3blcnnvbmfsl3bhcmv2ywxvx3rvbmc0njrfb3jnl0vvq0nhshlxmflkrxa5cm1ravlyzklnqjfiz2jsvghqowroel9evvbxumvvngc_cnrpbwu9q0lkatrhlveyrwc"; http_uri; nocase; content:"tong464-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007612; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/clients/connexion?redirect_code=k630oas6mxfmegukzpgajq%3d%3d&chash=83fa1c812d374fe28cde0d5248012d4a"; http_uri; nocase; content:"total.direct-energie.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007613; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/clients/connexion?redirect_code=k630oas6mxfmegukzpgajq==&\;chash=83fa1c812d374fe28cde0d5248012d4a"; http_uri; nocase; content:"total.direct-energie.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007614; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/office/index2.php"; http_uri; nocase; content:"totoboswap.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007615; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/htfdavi.html"; http_uri; nocase; content:"tpglenwinsosel.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007616; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/alertaslbcp"; http_uri; nocase; content:"tr.im"; content:"Host"; http_header; classtype:attempted-recon; sid:200007617; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2244a1c9-108c-45b8-954c-faeb2543a00e?click_id=tnrxber&var2=50008&var3=d5ee0e47de3d24&var4=gil+morlanes.+local+numero+6&var5=40&var6=zaragoza&var7=sanz&var8=lorena&var9=34653831930&var10=rurututururu%40gmail.com"; http_uri; nocase; content:"track.simstricksclicks.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007618; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2b44de4f-dbf4-4e97-9daf-f05b8293ddcd?click_id=jpe0de8&var2=50008&var3=j5ee360d8ae0d8&var4=gil+morlanes.+local+numero+6&var5=40&var6=zaragoza&var7=sanz&var8=lorena&var9=34653831930&var10=rurututururu%40gmail.com"; http_uri; nocase; content:"track.simstricksclicks.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007619; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/6d4bf2a2-feaf-4726-9513-64b44eb219fe?click_id=ffeukz7&var2=50008&var3=m5ee360818cad0&var4=gil+morlanes.+local+numero+6&var5=40&var6=zaragoza&var7=sanz&var8=lorena&var9=34653831930&var10=rurututururu%40gmail.com"; http_uri; nocase; content:"track.simstricksclicks.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007620; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/8ffd5473-a65a-41c3-868a-b0160dee57ee?click_id=k_mskde&var2=&var3=g5eeba7d023b22&var4=&var5=58&var6=&var7=&var8=leticia&var9=34661988661&var10="; http_uri; nocase; content:"track.simstricksclicks.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007621; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pcvtsnapshotorigin?_t=1527230263291&\;from=en&\;notrans=0&\;query=&\;tabmode=1&\;tfr=englishpc&\;to=zh-chs&\;url=https://www.wellsfargo.com"; http_uri; nocase; content:"translate.sogoucdn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007622; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pcvtsnapshotorigin?_t=1572026205262%20open_in_new%20add%20link&\;from=en&\;notrans=0&\;query=paypal%20account&\;tabmode=2&\;tfr=englishpc&\;to=zh-chs&\;url=https://www.paypal.com/us/signin"; http_uri; nocase; content:"translate.sogoucdn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007623; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pcvtsnapshotorigin?url=https://www.paypal.com/us/signin&\;query=paypal%20account&\;tabmode=2&\;n"; http_uri; nocase; content:"translate.sogoucdn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007624; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/pcvtsnapshotorigin?url=https://www.paypal.com/us/signin&\;query=paypal%20account&\;tabmode=2&\;notrans=0&\;tfr=englishpc&\;from=en&\;to=zh-chs&\;securl=&\;_t=1572026205262%20open_in_new%20add%20link"; http_uri; nocase; content:"translate.sogoucdn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007625; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/ihood_travisusd_org/_layouts/15/wopiframe.aspx?guestaccesstoken=zsuakfphpjylf9fg6uxx49zwnr0tpm%2f8b6wulueebvw%3d&docid=1_166c8899f6aa54678b020c248f3a09a4e&wdformid=%7b39a1d55c%2d6106%2d4326%2d98e5%2d931be1666db9%7d&action=formsubmit"; http_uri; nocase; content:"travisusd-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007626; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/dbullen_tregolls_cornwall_sch_uk/_layouts/15/wopiframe.aspx?guestaccesstoken=4w7nbxyv%2be5q5h6ifvqsvt%2ba0azuzpfgpywxpwtq6mu%3d&\;docid=1_1114d83a63e0f489b93e746d8b241db70&\;wdformid=%7bfff4536c%2d404d%2d410d%2da3b7%2d4cc8a8841296%7d&\;action=formsubmit"; http_uri; nocase; content:"tregollsschool-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007627; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/ed_triathlonontario_com/_layouts/15/wopiframe.aspx?guestaccesstoken=tx4pjpe6j3l456dw6h5p4rjclnpql4gy3umalpcsbgc%3d&docid=1_15c1c05a0348c406b917721edd22b400e&wdformid=%7b743b2d9a-465e-4a2d-a672-3b480e7184ff%7d&action=formsubmit&cid=2b766ac1-60f6-4883-8ff0-3a53524a1f1c"; http_uri; nocase; content:"triathlonontario-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007628; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/ed_triathlonontario_com/_layouts/15/wopiframe.aspx?guestaccesstoken=tx4pjpe6j3l456dw6h5p4rjclnpql4gy3umalpcsbgc%3d&docid=1_15c1c05a0348c406b917721edd22b400e&wdformid=%7b743b2d9a-465e-4a2d-a672-3b480e7184ff%7d&action=formsubmit&cid=2b766ac1-60f6-4883-8ff0-3a53524a1f1c"; http_uri; nocase; content:"triathlonontario-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007629; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/george_mann_trsresourcing_com/_layouts/15/wopiframe.aspx?guestaccesstoken=keq4zzm9j808bogb0lhmlk/fmttnrk/im742ummqyoc=&\;docid=1_1589713bad63748a5b18ff3da49058f47&\;wdformid={60ec57bb-9aae-4cd2-94e0-11f3079f6a7b}&\;action=formsubmit&\;cid=ffde5aca-d137-4ec0-92dd-9feb7426e112"; http_uri; nocase; content:"trsresourcing-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007630; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/vendor/phpunit/phpunit/src/util/account/sugnin/id-6670332/customer_center/customer-idpp00c547/myaccount/signin/"; http_uri; nocase; content:"ts.hust.edu.vn"; content:"Host"; http_header; classtype:attempted-recon; sid:200007631; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/agricolelogin/agricolefrance/"; http_uri; nocase; content:"tvoi-vrach.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200007632; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/deutch/weiter/"; http_uri; nocase; content:"tvoi-vrach.ru"; content:"Host"; http_header; classtype:attempted-recon; sid:200007633; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/32megq"; http_uri; nocase; content:"u.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200007634; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/isx3gg?notification-identity-office"; http_uri; nocase; content:"u.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200007635; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/umxggg"; http_uri; nocase; content:"u.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200007636; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/unrpgg"; http_uri; nocase; content:"u.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200007637; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/wsddga"; http_uri; nocase; content:"u.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200007638; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/es127759_umconnect_umt_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=e%2f5p4lmr7oxtbuuzst9ihpacebtz%2bhbogl5i950bhau%3d&docid=1_151b39d9e7dd54cfba500875349d3beb6&wdformid=%7bda6fcad9%2d9684%2d43af%2db959%2de2fa774eaba6%7d&action=formsubmit"; http_uri; nocase; content:"umconnectumt-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007639; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/es127759_umconnect_umt_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=h2b5qkvlooc%2bfvhpo6qkbxdfdzwzpa7doqhaikfrj08%3d&docid=1_1cab74931edec4bf39e6f4768e7830a02&wdformid=%7b6a702647%2db560%2d40c5%2d8890%2d109ec5ad9bc5%7d&action=formsubmit"; http_uri; nocase; content:"umconnectumt-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007640; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/es127759_umconnect_umt_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=inau9tsjk5bvaoypx%2fgfkvgo0iz4rq47kvts4tkb8yq%3d&docid=1_19c7a48ea3a0448c78765a480857920f0&wdformid=%7bd8f70a7d%2d4204%2d4a87%2da88e%2dbad6b0e4129e%7d&action=formsubmit"; http_uri; nocase; content:"umconnectumt-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007641; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/es127759_umconnect_umt_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=inau9tsjk5bvaoypx/gfkvgo0iz4rq47kvts4tkb8yq=&\;docid=1_19c7a48ea3a0448c78765a480857920f0&\;wdformid={d8f70a7d-4204-4a87-a88e-bad6b0e4129e}&\;action=formsubmit"; http_uri; nocase; content:"umconnectumt-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007642; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/es127759_umconnect_umt_edu/_layouts/15/wopiframe.aspx?guestaccesstoken=uh9hjveaooebgqolme%2f5qft71pw2stg2ojiiqxebzce%3d&docid=1_11e28ca5d86c6416f926736ea3e8ad885&wdformid=%7b70256f91%2df178%2d4e5f%2d847a%2df748294a79c9%7d&action=formsubmit"; http_uri; nocase; content:"umconnectumt-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007643; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/tansen_umn_org_np/_layouts/15/wopiframe.aspx?guestaccesstoken=gvehtuwubrvu5rhmt%2fm%2bhtc1njien%2bm61cz2itvk%2ffm%3d&docid=1_1da3de5eab0d94e15be3d9b5e4713727d&wdformid=%7bff79b283%2d5cae%2d4953%2da3ef%2dd7e3dea04eb6%7d&action=formsubmit"; http_uri; nocase; content:"umnnp-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007644; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/perpustakaan/digilib/files/tmp/posting/information-compte.php"; http_uri; nocase; content:"umpalangkaraya.ac.id"; content:"Host"; http_header; classtype:attempted-recon; sid:200007645; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lloyds"; http_uri; nocase; content:"unauthorised-request.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007646; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lloyds/"; http_uri; nocase; content:"unauthorised-request.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007647; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lloyds/login.php"; http_uri; nocase; content:"unauthorised-request.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007648; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lloyds"; http_uri; nocase; content:"unauthorisedpayeerequest.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007649; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lloyds/login.php"; http_uri; nocase; content:"unauthorisedpayeerequest.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007650; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cgi-bin/atc/out.cgi?id=19&u=http:/www.experiencebrettjackson.dreamhosters.com/wp-content/plugins/inc/.b6a0e0f97b98509200cbe8dc8a90813a/96478879526111436369212b881ee965/5efe4ee1cde8b3df84ef4dea939aa5b0/e4e1205f7238e90b308e29077e32e81a473fe78d/db43c8397d81b9af8eeefc39b3ce1d77aa6e7ad9/e3f74ab593863dfc0ac6cd4216b662149754a5ab/1c51f70a771f31724e803a541e6aa7ad1f412527/e4458c837adb31b10124b969de4c8f73b5be8c01/"; http_uri; nocase; content:"uniquesexygirls.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007651; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/secure.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"unpaidfee-shipment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007652; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/verifylogin.php?&\;sessionid=$hash&\;securessl=true"; http_uri; nocase; content:"unpaidfee-shipment.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007653; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/banks/online.citi.eu"; http_uri; nocase; content:"unrecognisable-payee-request.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007654; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/banks/online.citi.eu/"; http_uri; nocase; content:"unrecognisable-payee-request.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007655; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/banks/online.citi.eu/login.php"; http_uri; nocase; content:"unrecognisable-payee-request.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007656; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/tsb"; http_uri; nocase; content:"unrecognised-payee-connect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007657; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lloyds"; http_uri; nocase; content:"unrecognisedpayeerequest.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007658; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lloyds/login.php"; http_uri; nocase; content:"unrecognisedpayeerequest.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007659; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:b:/g/personal/arnuv_mayank1_ucalgary_ca/evgtz_pcletgonwkwyagc0wbkezwceoq_0hzi8h3ezxpnw"; http_uri; nocase; content:"uofc-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007660; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/l4ucvi"; http_uri; nocase; content:"upscri.be"; content:"Host"; http_header; classtype:attempted-recon; sid:200007661; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kr14?userid=1401523827"; http_uri; nocase; content:"uqr.to"; content:"Host"; http_header; classtype:attempted-recon; sid:200007662; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/bum9"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007663; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cbmp?0y=s0xwgzdgw1nekhohrmkkptrgjtjiijcootj1eujadhcpb7e5q8vbdox0zh6gjqgbbwl6pe007o3iylvjb9zluudsm0ohckjcxgf1xwwrzx33yf6"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007664; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cbmp?b0y=ixziezoedgqp4x3dcttiovfvlgvwz5pyjnrk6zldj5qsbahkcalxkmrp4hg66nl0oegdhzbwkauqqpsasbddvvqhzzbm0pzkqtnzhwetosybf6z"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007665; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cbmp?fu3r=nvmnwugybw81iq7gfcqsr29jfvkd4aeesnz8tdsiuzjlzkilseboqx3zu2r7sm8zew71keo2ugtmvjdv0t5sw6wek7o33xlhep3qonwegbfuiql"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007666; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cbmp?fu3r=wm4t5uyjeet6oo1ozwzpitubvacmjwwdeybfawgqfrwddsmxp5d1yqmlqvohd2xys4cajrea6vgwl6642z3qlpdxfhmzyshpshc7o8pirofmlse"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007667; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cbmp?h4y=zciuatbl6m1yd0mrsy1qkitv6y1hq1xlowqg822ktvavdjsnthvv7sukag28obpvrnp9v74xlgxnqqiee8b893tloh4bccmzsgpxnarulbsd3ah"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007668; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cbmp?lfd=djaslon8mlsyflzsegjpghhzikih86eiyhhoxrhjhs74e4bhhgbltmcwg0s1plbgettxgg1btiksqb7fbqipcgknazqohtchqlnwpkxaduml0am"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007669; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cfxw?znqq?tco=w3a8wkqu"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007670; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cj9i"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007671; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/cwbb?brmsvk?tco=e5zh4sas"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007672; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dagj"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007673; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dfdu"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007674; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dfoa"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007675; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dfsg"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007676; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dhi5"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007677; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dhwq"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007678; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dhxo"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007679; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dqoq"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007680; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dr7v"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007681; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dwzw"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007682; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dya0"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007683; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/dzin"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007684; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eclu"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007685; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ef6b"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007686; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ef96"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007687; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ejhy"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007688; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ekkz"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007689; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eruz"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007690; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eu9x"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007691; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ev3x"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007692; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/evyg"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007693; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/excc"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007694; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/exvb"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007695; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/f0cd"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007696; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/f9nb"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007697; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/fbqd"; http_uri; nocase; content:"urlz.fr"; content:"Host"; http_header; classtype:attempted-recon; sid:200007698; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/www.myredirect.com/btwede/start-1.html"; http_uri; nocase; content:"uz9zoiz9vqbutkpvdyp0tg-on.drv.tw"; content:"Host"; http_header; classtype:attempted-recon; sid:200007699; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/eoauyu"; http_uri; nocase; content:"v.gd"; content:"Host"; http_header; classtype:attempted-recon; sid:200007700; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/mjmecr"; http_uri; nocase; content:"v.gd"; content:"Host"; http_header; classtype:attempted-recon; sid:200007701; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ymvvn6"; http_uri; nocase; content:"v.gd"; content:"Host"; http_header; classtype:attempted-recon; sid:200007702; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/karin_strand_vellinge_se/egyldcpw7zzet71gx887vwobrnhahqfmwqw5rejh4cib9a?e=sdoqrc"; http_uri; nocase; content:"vellingekommun-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007703; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/drupal-7.56/scripts/bp"; http_uri; nocase; content:"velvet.by"; content:"Host"; http_header; classtype:attempted-recon; sid:200007704; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/drupal-7.56/scripts/bp/"; http_uri; nocase; content:"velvet.by"; content:"Host"; http_header; classtype:attempted-recon; sid:200007705; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/drupal-7.56/scripts/bp/2277e0f3c4c5c98e848c0e64d76d6fb5/"; http_uri; nocase; content:"velvet.by"; content:"Host"; http_header; classtype:attempted-recon; sid:200007706; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/drupal-7.56/scripts/bp/d03ef074f8887403b084d613916df607/"; http_uri; nocase; content:"velvet.by"; content:"Host"; http_header; classtype:attempted-recon; sid:200007707; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/drupal-7.56/scripts/bp/d4810797ed4ec28eeb047934428f14a1/"; http_uri; nocase; content:"velvet.by"; content:"Host"; http_header; classtype:attempted-recon; sid:200007708; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lloyds"; http_uri; nocase; content:"verify-advanceconnect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007709; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lloyds/"; http_uri; nocase; content:"verify-advanceconnect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007710; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/lloyds/login.php"; http_uri; nocase; content:"verify-advanceconnect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007711; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/htmls/payal.html"; http_uri; nocase; content:"veronikastringquartet.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007712; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/2021/03/blog-post.html"; http_uri; nocase; content:"viamobte.blogspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007713; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/confirm-billing/login/68a64c1e5639454c3185e7ea2db9fc48"; http_uri; nocase; content:"viewinstaprivate.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007714; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/vipps2519"; http_uri; nocase; content:"vipps-sikkerhet.co"; content:"Host"; http_header; classtype:attempted-recon; sid:200007715; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/adpadpsecurity/adp/"; http_uri; nocase; content:"vivianegibert.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007716; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/9mjize"; http_uri; nocase; content:"vk.cc"; content:"Host"; http_header; classtype:attempted-recon; sid:200007717; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/away.php?to=http%3a%2f%2frajeshkhanal.com.np%2fwp-config.php&\;post=521188519_100&\;cc_key="; http_uri; nocase; content:"vk.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007718; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/account"; http_uri; nocase; content:"vodafone.billing-incorrect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007719; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/account/"; http_uri; nocase; content:"vodafone.billing-incorrect.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007720; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/banks/firstdirect.com/"; http_uri; nocase; content:"vodafonenotice.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007721; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/8jdu/sb6/index.php?_"; http_uri; nocase; content:"wallieget.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007722; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/8jdu/sb6/index.php?_&\;_"; http_uri; nocase; content:"wallieget.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007723; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/upgrade/"; http_uri; nocase; content:"webmail.serviceunit.co.uk"; content:"Host"; http_header; classtype:attempted-recon; sid:200007724; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/.well-known/pki-validation/pki-validation/login/login.php"; http_uri; nocase; content:"weeniecat.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007725; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/treseroediger_weiss-ins_com/_layouts/15/wopiframe.aspx?guestaccesstoken=8nmzieulbcr%2fxagq0wlchprk28nb06m5puyexbgyd8i%3d&docid=1_19eb9b67388834d93bfed541a6cdd50c3&wdformid=%7bd6ba9f5d%2d33ee%2d495a%2da933%2d2a865b19b6b6%7d&action=formsubmit"; http_uri; nocase; content:"weissins365-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007726; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/lynne_barron_eaglehouseschool_com/_layouts/15/wopiframe.aspx?guestaccesstoken=5r%2fl6nh%2bt0nfkb7xwynvz8n1wumz0wz%2fpwkgri5p6%2fs%3d&docid=1_192cb7c38faeb476cb58ce8f71598361c&wdformid=%7b3e42bd82%2db59e%2d403b%2d9998%2d0c2dd21bd5e6%7d&action=formsubmit"; http_uri; nocase; content:"wellingtoncloud-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007727; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/bwalters_lglk_com/_layouts/15/doc.aspx?sourcedoc={1d96cb1e-0031-41b8-8774-24bb2f7c4caa}&\;action=default&\;slrid=9ebb659f-7054-a000-b19b-7cb962889fc8&\;originalpath=ahr0chm6ly93agl0zwzvcmrrzw53b3j0ac1tes5zagfyzxbvaw50lmnvbs86bzovzy9wzxjzb25hbc9id2fsdgvyc19sz2xrx2nvbs9faddmbggweefmaejom1frdxk5ofrlb0jpn09poghoxzd0dfzfcw56wwr1yknbp3j0aw1lpvn3cwtevjhumkvn&\;cid=2ae6d679-a1b4-4b0f-a76a-46e32d437c42"; http_uri; nocase; content:"whitefordkenworth-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007728; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/brian_wilsonvaluation_com/evgzsh2f49natji6i_lnklcbz46ledpzwpckxs6jgi7zmw?e=un6z"; http_uri; nocase; content:"wilsonvaluation602-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007729; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:o:/g/personal/brandon_wincodc_com/esxchyyuht1diztxkz0fzm8boma-_ssknhdzjbh7xexnxa?e=vapt5b"; http_uri; nocase; content:"winfreyandco-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007730; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/?i=1"; http_uri; nocase; content:"wmzhlieremguv.tonohost.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007731; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/:x:/r/personal/pklewis_k12_wv_us/_layouts/15/wopiframe.aspx?guestaccesstoken=tqintdtuii%2bam%2fbqmtnjkenggs2dptoi8hs2jqftjkq%3d&docid=1_1446052cffa4c4871bd24bb98fe86ed6d&wdformid=%7bdf30d25d%2d0b59%2d47e5%2d956e%2dc601397ea4d7%7d&action=formsubmit&cid=57cdb8ab-426b-4eff-a51f-903ee3684f96"; http_uri; nocase; content:"wvk12-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007732; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/personal/pklewis_k12_wv_us/_layouts/15/wopiframe.aspx?guestaccesstoken=tqintdtuii%2bam%2fbqmtnjkenggs2dptoi8hs2jqftjkq%3d&docid=1_1446052cffa4c4871bd24bb98fe86ed6d&wdformid=%7bdf30d25d%2d0b59%2d47e5%2d956e%2dc601397ea4d7%7d&action=formsubmit&cid=57cdb8ab-426b-4eff-a51f-903ee3684f96"; http_uri; nocase; content:"wvk12-my.sharepoint.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007733; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/kindeditor/attached/file/20170522/20170522162056_82594.html"; http_uri; nocase; content:"xjgyedu.cn"; content:"Host"; http_header; classtype:attempted-recon; sid:200007734; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/go/url=http:/tiny.cc/p9bd7y"; http_uri; nocase; content:"xn--80aaa0a0avl4b6b.xn--p1ai"; content:"Host"; http_header; classtype:attempted-recon; sid:200007735; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/#abuse@ionos.com"; http_uri; nocase; content:"xoegikfzrjewfmnh-dot-asonapa-swesesa.uc.r.appspot.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007736; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/l0f93"; http_uri; nocase; content:"xurl.es"; content:"Host"; http_header; classtype:attempted-recon; sid:200007737; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/awaps-ad-sdk-js-bundles/1.0-3871/bundles-es2017/inpage.bundle.js"; http_uri; nocase; content:"yastatic.net"; content:"Host"; http_header; classtype:attempted-recon; sid:200007738; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/click-dqkla3al-hfdqch9w?bt=25&\;tl=1&\;url=http://www.microsoft.com/&\;sa=k4cph5afjt010fz50ihbd"; http_uri; nocase; content:"ytthn.com"; content:"Host"; http_header; classtype:attempted-recon; sid:200007739; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redirect?sig=4201f8abbbef87a92f1fda2709ee3c1f3e0533d1cad081abd7805fcfb32440cb&\;url=ahr0chm6ly9yzwjyyw5klmx5l2gwamzpag==&\;platform=app_android&\;brand=o2"; http_uri; nocase; content:"zasobygwp.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200007740; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/redirect?sig=793123fbb1cb8c452a99d6ca1cb34c67fd40f3d7df8ee9d72955f1bf7461b1ec&\;url=ahr0chm6ly9yzwjyyw5klmx5l2zqb2flbg==&\;platform=app_android&\;brand=o2"; http_uri; nocase; content:"zasobygwp.pl"; content:"Host"; http_header; classtype:attempted-recon; sid:200007741; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/ruttb"; http_uri; nocase; content:"zpr.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200007742; rev:1;)
|
|
|
|
alert tcp $HOME_NET any -> $EXTERNAL_NET [80,443] (msg:"phishing-filter phishing website detected"; flow:established,from_client; content:"GET"; http_method; content:"/twq3f"; http_uri; nocase; content:"zpr.io"; content:"Host"; http_header; classtype:attempted-recon; sid:200007743; rev:1;)
|