Facebook Phishing Kit 2b493308

Detects a Facebook phishing kit that uses a unique URL to host the banner image used in the fake login form.

References

IOK Rule (edit)

title: Facebook Phishing Kit 2b493308
description: | 
  Detects a Facebook phishing kit 
  that uses a unique URL to host 
  the banner image used in the fake
  login form.

references: 
  - https://urlscan.io/result/2b493308-d637-434e-9719-de252ccc9852
  - https://urlscan.io/result/27307d87-6ab2-4f62-b413-304edd021daa

detection: 

  companyBannerImage: 
    requests|contains: 'dc07b6ec287142c5519483f3d678b2d2.png'
    
  loginPageBannerImage: 
    requests|contains: 'www.pointstar.co.id/wp-content/uploads/2020/07/google-security.jpg' 

  condition: companyBannerImage and loginPageBannerImage


tags: 
  - kit
  - target.facebook