Banco Pichincha Phishing Kit niUG0Z

Detects a phishing kit targeting Banco Pichincha. Banco Pichincha is the largest private-sector bank in Ecuador. This was detected as a result of this kit being deployed on Replit.

References

IOK Rule (edit)

title: Banco Pichincha Phishing Kit niUG0Z
description: |
    Detects a phishing kit targeting Banco Pichincha. Banco Pichincha is the largest private-sector bank in Ecuador.
    This was detected as a result of this kit being deployed on Replit.


references:
    - https://urlscan.io/result/0c5c87f6-0de1-4b69-bbcf-ebfec08241e6/
    - https://urlscan.io/result/db339903-08f1-4be6-9c55-47227d18f42e/
    - https://urlscan.io/result/473f8be9-a375-48d1-a6c5-cd07a9021d81/

detection:

    title:
      html|contains:
        - <title>Login</title>

    css:
      html|contains|all:
        - link rel="stylesheet" href="assets/css/explorer-message-05236.css"
        - link rel="stylesheet" href="assets/css/styles.05.css"
        - link rel="stylesheet" href="assets/css/styles.45fc6f0f.css"

    copyright:
      html|contains:
        - "© 2022 Banco Pichincha. Todos los derechos reservados"


    condition: title and css and copyright

tags:
  - kit
  - target.banco_pichincha
  - target.pichincha
  - target_country.ecuador