Amazon Phishing Kit 28bd59a

IOK Rule (edit)

title: Amazon Phishing Kit 28bd59a
description: |
    Detects an Amazon phishing kit targeting Japanese users.
    This kit is dynamically generated by Javascript.
    
references:
    - https://urlscan.io/result/62f94102-0ae5-4394-ac1e-b54dea1c14c6
    - https://urlscan.io/result/aaae4e63-afd3-4bde-ab10-096522e91e04/
    - https://urlscan.io/search/#filename:%22AmazonUIBaseCSS-sprite_1x-28bd59af93d9b1c745bb0aca4de58763b54df7cf._V2_.6a23b50.png%22
    - https://urlscan.io/search/#filename:%2211.8b1570ce205b9a0d5ecb.js%22

detection:

    randomString:
        js|contains: 'fsdffsdfsddsfsd123123'
        
    pageScript:
        requests|contains: '11.8b1570ce205b9a0d5ecb.js'
        
    imageName:
        requests|contains: 'AmazonUIBaseCSS-sprite_1x-28bd59af93d9b1c745bb0aca4de58763b54df7cf._V2_.6a23b50.png'
        
      
    condition: randomString and pageScript and imageName
    
tags:
  - kit
  - target.amazon
  - target_country.japan