Facebook Phishing Kit 9dda3b8f

IOK Rule (edit)

title: Facebook Phishing Kit 9dda3b8f
description: |
  A Facebook phishing kit displaying a login form
  
references:
  - https://urlscan.io/result/36b94762-6afb-40b5-9d7d-576656b97d57/
  - https://urlscan.io/result/cf1d63b6-a55f-4675-8925-6edfbf0027e2/
  - https://urlscan.io/result/8b88051f-5115-44cd-b9bf-452266997a0a/

detection:

  ogTags:
    html|contains: '<meta property="og:title" content="Log in to Facebook | Facebook">'
    
  piwik:
    requests|contains: 'danielhar.containers.piwik.pro/9dda3b8f-d3cd-49b0-9bab-fc06cb34f389'
    
  passwordField:
    html|contains: '<input type="password" name="pass" placeholder="Password" pattern=".{5,}" required="">'
    
  loginButton:
    html|contains: '<button type="submit" name="u_sprawdz">Log In</button>'
    
  condition: ogTags and piwik and passwordField and loginButton

tags:
  - kit
  - target.facebook