Discord Hypesquad Phishing Kit 9e6c4a9

IOK Rule (edit)

title: Discord Hypesquad Phishing Kit 9e6c4a9
description: |
  Discord Hypesquad phishing kit containing a comment 
  left behind by the supposed developer of the kit.
  As well as a unique nonce value that is present.
  
references:
  - https://urlscan.io/search/#hash%3Ae6054519e1271faf9134d92dc22e29fbba341275641596a9c32ed37a3c73905f
  - https://urlscan.io/search/#hash%3A5ee7eb3becab8cd3bf3cf095211f4d35041e9009bb1755771a3fa66aa3a75897
  - https://urlscan.io/search/#hash%3A0063c8ab81d88071cbe5d1ba5c49a36afd660cc0824e6fac1532c95d5dde1f6f
  - https://urlscan.io/result/9e6c4a9f-62b4-4b07-81f2-09f10be41cc7
  
detection:

  developerSignature:
    html|contains: '<!---By strolly#9548-->'
    
  nonceCSP:
    html|contains: 'nonce="MjE2LDE0MCwxNzgsMTgwLDY1LDEwOCwxNCwyMjQ="'
    
  condition: developerSignature and nonceCSP
  
tags:
  - kit
  - target.discord
  - threat_actor.strolly