diff --git a/indicators/smbc-acab82b5.yml b/indicators/smbc-acab82b5.yml new file mode 100644 index 00000000..faa2633c --- /dev/null +++ b/indicators/smbc-acab82b5.yml @@ -0,0 +1,24 @@ +title: SMBC Phishing Kit acab82b5 +description: | + Detects a SMBC phishing kit targeting Japanese users. + +references: + - https://urlscan.io/result/acab82b5-6182-4cab-96b1-7e2af19b668b + - https://urlscan.io/result/a8a41bab-97ed-43d8-85d8-d760161ab317 + - https://urlscan.io/result/607f6acb-1301-4ca5-9e33-0e0ca5b7c359 + - https://urlscan.io/result/6c29c34f-1dac-433c-b2d9-005bd8db3ee1 + +detection: + FormContains: + html|contains: + - 'method="post" id="tijiao" action="1.php"' + + iframeContains: + html|contains: + - 'id="aMpc0Wu2zFxeefIt" style="display: none;"' + + condition: FormContains and iframeContains + +tags: + - target.smbc + - target_country.japan \ No newline at end of file