alert tcp $HTTP_SERVERS $HTTP_PORTS -> any any (msg:"ET WEB_SERVER Phoenix Exploit Kit - Admin Login Page Detected Outbound"; flow:established,to_client; content:"Phoenix Exploit's Kit - Log In"; classtype:bad-unknown; sid:2011280; rev:2;)

Added 2011-10-12 19:31:43 UTC

This rule tends to trigger on itself, should the content:"<title>Phoenix Exploit's Kit - Log In</title>"; have http_client_body; or http_header; after it?

-- JimMcKibben - 2016-04-28


alert tcp $HTTP_SERVERS $HTTP_PORTS -> any any (msg:"ET WEB_SERVER Phoenix Exploit Kit - Admin Login Page Detected Outbound"; flow:established,to_client; content:"Phoenix Exploit's Kit - Log In"; classtype:bad-unknown; sid:2011280; rev:2;)

Added 2011-06-16 10:06:01 UTC


alert tcp $HTTP_SERVERS $HTTP_PORTS -> any any (msg:"ET WEB_SERVER Phoenix Exploit Kit - Admin Login Page Detected Outbound"; flow:established,to_client; content:"Phoenix Exploit's Kit - Log In"; classtype:bad-unknown; sid:2011280; rev:2;)

Added 2011-06-16 09:59:05 UTC


alert tcp $HTTP_SERVERS $HTTP_PORTS -> any any (msg:"ET WEB_CLIENT phoenix exploit kit - admin login page detected"; flow:established,to_client; content:"Phoenix Exploit's Kit - Log In"; classtype:bad-unknown; sid:2011280; rev:1;)

Added 2011-02-04 17:31:05 UTC


alert tcp $HTTP_SERVERS $HTTP_PORTS -> any any (msg:"ET WEB_SERVER Phoenix exploit kit - admin login page detected"; flow:established,to_client; content:"Phoenix Exploit's Kit - Log In"; classtype:bad-unknown; reference:url,doc.emergingthreats.net/2011280; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SERVER/WEB_Phoenix; sid:2011280; rev:2;)

Added 2010-08-01 20:38:14 UTC


Topic revision: r2 - 2016-04-28 - JimMcKibben
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats