# PigButcher Credential Phish Landing Page Rules Error on Suricata 7

**URL:** <https://community.emergingthreats.net/t/pigbutcher-credential-phish-landing-page-rules-error-on-suricata-7/1939>\
**Category:** Feedback & Support\
**Tags:** etopen\
**Created:** [September 4, 2024, 3:51am UTC](https://community.emergingthreats.net/t/pigbutcher-credential-phish-landing-page-rules-error-on-suricata-7/1939 "2024-09-04T03:51:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ar3s](https://avatars.discourse-cdn.com/v4/letter/a/ad7895/32.png) [@ar3s](https://community.emergingthreats.net/u/ar3s)\
**Post date:** [September 4, 2024, 3:51am UTC](https://community.emergingthreats.net/t/pigbutcher-credential-phish-landing-page-rules-error-on-suricata-7/1939/1 "2024-09-04T03:51:34Z")

</div>

Hi All,

3 Rules from [Ruleset Update Summary - 2024/08/28 - v10676] are causing errors on suricata version 7 due to http\_content\_type misplacement.  
sid:2055541  
sid:2055542  
sid:2055543

Current rule:  
alert http $EXTERNAL\_NET any → $HOME\_NET any (msg:“ET CURRENT\_EVENTS PigButcher Credential Phish Landing Page M2 2024-08-05”; flow:established,to\_client; content:“200”; http\_stat\_code; content:“application/javascript”; http\_content\_type; file\_data; content:“/home”; content:“/login”; distance:0; content:“/register”; distance:0; content:“/registrationAgreement”; fast\_pattern; distance:0; content:“/customerServices”; distance:0; content:“backgroundImage”; distance:0; content:“logo”; distance:0; content:“popUpImage”; content:“copyright”; content:“currencyUnit”; content:“name”; classtype:trojan-activity; sid:2055541; rev:1; metadata:attack\_target Client\_Endpoint, tls\_state TLSDecrypt, created\_at 2024\_08\_28, deployment Perimeter, deployment SSLDecrypt, confidence High, signature\_severity Major, tag Phishing, updated\_at 2024\_08\_28, mitre\_tactic\_id TA0001, mitre\_tactic\_name Initial\_Access, mitre\_technique\_id T1566, mitre\_technique\_name Phishing;)

Proposed fix  
alert http $EXTERNAL\_NET any → $HOME\_NET any (msg:“ET CURRENT\_EVENTS PigButcher Credential Phish Landing Page M2 2024-08-05”; flow:established,to\_client;   
content:“200”; http\_stat\_code;   
http\_content\_type; content:“application/javascript”;   
file\_data; content:“/home”; content:“/login”; distance:0; content:“/register”; distance:0; content:“/registrationAgreement”; fast\_pattern; distance:0; content:“/customerServices”; distance:0; content:“backgroundImage”; distance:0; content:“logo”; distance:0; content:“popUpImage”; content:“copyright”; content:“currencyUnit”; content:“name”;   
classtype:trojan-activity; sid:2055541; rev:1; metadata:attack\_target Client\_Endpoint, tls\_state TLSDecrypt, created\_at 2024\_08\_28, deployment Perimeter, deployment SSLDecrypt, confidence High, signature\_severity Major, tag Phishing, updated\_at 2024\_08\_28, mitre\_tactic\_id TA0001, mitre\_tactic\_name Initial\_Access, mitre\_technique\_id T1566, mitre\_technique\_name Phishing;)

---

<div class="post-metadata">

**Author:** ![bingohotdog](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/bingohotdog/32/42_2.png) [@bingohotdog](https://community.emergingthreats.net/u/bingohotdog)\
**Post date:** [September 5, 2024, 5:53pm UTC](https://community.emergingthreats.net/t/pigbutcher-credential-phish-landing-page-rules-error-on-suricata-7/1939/2 "2024-09-05T17:53:37Z")

</div>

Hi @ar3s, I’ll look into this and provide an update accordingly. 🌭

---

<div class="post-metadata">

**Author:** ![bingohotdog](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/bingohotdog/32/42_2.png) [@bingohotdog](https://community.emergingthreats.net/u/bingohotdog)\
**Post date:** [September 5, 2024, 10:48pm UTC](https://community.emergingthreats.net/t/pigbutcher-credential-phish-landing-page-rules-error-on-suricata-7/1939/3 "2024-09-05T22:48:58Z")

</div>

Hi @ar3s,

I’ve reviewed this query and here are my notes:

- The sids (2055541, 2055542, 2055543) were internally validated against suricata-7.0.3 and they did not cause Suricata 7 syntax errors.

- In your query, the provided rule (2055541) appears to use Suricata 4 syntax and not Suricata 7. For example, Suricata 4 and older uses sticky buffers with underscores (http\_content\_type). Suricata 5 and above uses dots (http.content\_type).

If you try running Suricata 4 rules against a Suricata 7 engine, errors are expected for not only (2055541, 2055542, 2055543) but for **all Suricata 4 rules** provided.

As an initial troubleshooting step, could you please check which ruleset version was used against your Suricata 7 engine? If it’s Suricata 4, then the errors were caused by a ruleset mismatch. Else, we can dig into this a bit more.

Cheers,  
🌭

---

<div class="post-metadata">

**Author:** ![ar3s](https://avatars.discourse-cdn.com/v4/letter/a/ad7895/32.png) [@ar3s](https://community.emergingthreats.net/u/ar3s)\
**Post date:** [September 9, 2024, 2:52am UTC](https://community.emergingthreats.net/t/pigbutcher-credential-phish-landing-page-rules-error-on-suricata-7/1939/4 "2024-09-09T02:52:19Z")

</div>

Hi @bingohotdog,

Sorry I just got back on work today.

I am using Suricata 7.0.5 to test the rules.

Kind Regards,  
ar3s

---

<div class="post-metadata">

**Author:** ![ar3s](https://avatars.discourse-cdn.com/v4/letter/a/ad7895/32.png) [@ar3s](https://community.emergingthreats.net/u/ar3s)\
**Post date:** [September 9, 2024, 4:25am UTC](https://community.emergingthreats.net/t/pigbutcher-credential-phish-landing-page-rules-error-on-suricata-7/1939/5 "2024-09-09T04:25:12Z")

</div>

[290] Notice: suricata: This is Suricata version 7.0.5 RELEASE running in USER mode  
[290] Error: detect: previous sticky buffer has no matches  
[290] Error: detect: error parsing signature “alert http $EXTERNAL\_NET any → $HOME\_NET any (msg:“ET CURRENT\_EVENTS PigButcher Credential Phish Landing Page M2 2024-08-05”; flow:established,to\_client; content:“200”; http\_stat\_code; content:“application/javascript”; http\_content\_type; file\_data; content:”/home"; content:“/login”; distance:0; content:“/register”; distance:0; content:“/registrationAgreement”; fast\_pattern; distance:0; content:“/customerServices”; distance:0; content:“backgroundImage”; distance:0; content:“logo”; distance:0; content:“popUpImage”; content:“copyright”; content:“currencyUnit”; content:“name”; classtype:trojan-activity; sid:2055541; rev:1; metadata:attack\_target Client\_Endpoint, tls\_state TLSDecrypt, created\_at 2024\_08\_28, deployment Perimeter, deployment SSLDecrypt, confidence High, signature\_severity Major, tag Phishing, updated\_at 2024\_08\_28, mitre\_tactic\_id TA0001, mitre\_tactic\_name Initial\_Access, mitre\_technique\_id T1566, mitre\_technique\_name Phishing;)" from file /mnt/c/TW-Tools/Projects/CVE/CVE-2024-28987/cve-2024-28987.rules at line 1

Kind Regards,  
ar3s

---

<div class="post-metadata">

**Author:** ![ar3s](https://avatars.discourse-cdn.com/v4/letter/a/ad7895/32.png) [@ar3s](https://community.emergingthreats.net/u/ar3s)\
**Post date:** [September 9, 2024, 4:29am UTC](https://community.emergingthreats.net/t/pigbutcher-credential-phish-landing-page-rules-error-on-suricata-7/1939/6 "2024-09-09T04:29:14Z")

</div>

Just to add we are testing the signatures in 4 Suricata versions  
9/9/2024 – 12:26:25 - - This is Suricata version 4.0.7 RELEASE  
9/9/2024 – 12:27:30 - - This is Suricata version 5.0.3 RELEASE running in USER mode  
9/9/2024 – 12:28:08 - - This is Suricata version 6.0.18 RELEASE running in USER mode  
[290] Notice: suricata: This is Suricata version 7.0.5 RELEASE running in USER mode

---

<div class="post-metadata">

**Author:** ![bingohotdog](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/bingohotdog/32/42_2.png) [@bingohotdog](https://community.emergingthreats.net/u/bingohotdog)\
**Post date:** [September 9, 2024, 5:33pm UTC](https://community.emergingthreats.net/t/pigbutcher-credential-phish-landing-page-rules-error-on-suricata-7/1939/7 "2024-09-09T17:33:46Z")

</div>

Nice, so the engine used is Suricata 7.0.5.

The rule you shared appears to be a Suricata 4.0 formatted rule. This rule and other Suricata 4.0 rules are expected to error against Suricata 5+ engines.

Could you try downloading the [suricata-7.0.3/](https://rules.emergingthreatspro.com/open/suricata-7.0.3/) ruleset and see if your errors resolve?
