Skip to content

Commit

Permalink
Adds 2 new IOK rules for Santander kits (#55)
Browse files Browse the repository at this point in the history
* Create santander-85b6cae.yml

* Create santander-951d27d.yml
  • Loading branch information
IlluminatiFish authored Aug 10, 2022
1 parent 9e32c02 commit 691aa90
Show file tree
Hide file tree
Showing 2 changed files with 51 additions and 0 deletions.
24 changes: 24 additions & 0 deletions indicators/santander-85b6cae.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
title: Santander Phishing Kit 85b6cae
description: |
Detects a Santander phishing kit targeting Spanish speaking users.
references:
- https://urlscan.io/result/56fb9b2c-e078-4d1d-b8a6-e6e5147e90d3
- https://urlscan.io/result/5ccf3cfc-cc1a-432d-a6e2-575f80742672

detection:

usernameLabelID:
html|contains: 'EB8236264AE3C04429B8F46076848E7B'

passwordLabelID:
html|contains: '85B6CAE065D33FEEEB4297826ECB9B2D'

exfilDestination:
html|contains: 'database_setup/routes/process_login.php'


condition: usernameLabelID and passwordLabelID and exfilDestination

tags:
- target.santander
27 changes: 27 additions & 0 deletions indicators/santander-951d27d.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
title: Santander Phishing Kit 951d27d
description: |
Detects a Santander phishing kit targeting Spanish speaking users.
references:
- https://urlscan.io/result/d7f3f389-d10b-4b83-a45c-ba7f8ec54035
- https://urlscan.io/result/1c849740-38f2-4442-94f8-bf2147cc587e

detection:

cloneTimestamp:
requests|contains: '?v=1655293257536'

usernameLabelID:
html|contains: '47563B2825160654ADB2CC97CE152AF3'

passwordLabelID:
html|contains: '951D27D1CD8413E25C1D61149F928D85'

exfilDestination:
html|contains: '/atualiza'


condition: cloneTimestamp and usernameLabelID and passwordLabelID and exfilDestination

tags:
- target.santander

0 comments on commit 691aa90

Please sign in to comment.