Credicorp Bank Phishing Kit Du47YO

Detects a different phishing kit targeting Credicorp Bank. This was found as a result of this kit being deployed on Replit.

References

IOK Rule (edit)

title: Credicorp Bank Phishing Kit Du47YO
description: |
    Detects a different phishing kit targeting Credicorp Bank.
    This was found as a result of this kit being deployed on Replit.


references:
    - https://urlscan.io/result/b916a5de-739a-4937-ae66-b1769b95cbd9/

detection:

    title:
      html|contains:
        - <title>CREDICORP</title>

    css:
      requests|contains|all:
        - fisaDesertAll.css
        - fisaDesertLogin.css
        - fisaDesertLoginCustom.css

    image:
      html|contains:
        - img src="./sonlosarchis/logo.png"


    condition: title and css and image

tags:
  - kit
  - target.credicorp_bank
  - target_country.panama