Fake crypto mining - DeFi_Mining

IOK Rule (edit)

title: Fake crypto mining - DeFi_Mining

description: |
    Detects a malicious DApp that pretends to be a mining platform.

references:
    - https://urlscan.io/result/85f77270-8954-490c-bcd8-34e43fa716ce/
    - https://urlscan.io/result/dbca19cd-8b80-4bdc-bdc4-cea4bd6bdab3/
    - https://urlscan.io/result/246d60f9-492d-4c38-9a28-35c3a2101c7a/
    - https://urlscan.io/result/7b6cc9ee-7d48-4c64-8116-db67f73822e4/
    - https://urlscan.io/result/cfab21dc-cea4-4774-b347-ec6be555a979/

detection:

    identifier1:
      js|contains|all:
        - "DeFi_Mining"
        - "Referral"
        - "coin_Account"
        - "coinHome"
        - "coinReferral"
        - "coinAccount"
        - "coinDefi"
        - "coinjs"
        - "pokerOrder"
        - "Rechargepage"
        - "withdrawalrecord"
        - "UserMoneyOrder"
        - "javaCode"

    identifier2:
      js|contains|all:
        - "DeFi Mining Yield Balance"
        - "of DeFi protocols supported"
        - "You will get you friends"
        - "We don't have user accounts and instead work directly"
        - "Daily Yield Details"
        - "No more data"
        - "referral program allows you to create unique"

    identifier3:
      html|contains|all:
        - "Join in DeFi Mining from one place"
        - "DeFi Hub is the easiest way to build"
        - "Discover the world of decentralized"
        - "free and open to anyone"
        - "DeFi protocols supported"
        - "proven track record"

    condition: identifier1 or identifier2 or identifier3

tags:
  - cryptocurrency