Fake crypto mining - ReceiveVoucher4

IOK Rule (edit)

title: Fake crypto mining - ReceiveVoucher4

description: |
    Detects a malicious DApp that pretends to be a liquidity mining platform
    while presenting fake audit reports and partners. AJAX call to receive
    other contents.

references:
    - https://urlscan.io/search/#hash%3A5218075e53acd18fdd4b8c92cb0dad377bffab9d072cc6205e51ee8e32514a14
    - https://urlscan.io/result/011814b3-f30a-4ac7-bac1-db62f71c29de/
    - https://urlscan.io/result/07c863ae-f341-4908-9686-2fc030c40a47/
    - https://urlscan.io/result/a43482f4-83ee-4f17-9928-f6c4bc437e2f/

related:
    - id: fake-crypto-mining-ReceiveVoucher

detection:

    jsKeywords:
      js|contains|all:
        - 'get_html'
        - 'php'
        - 'html'
        - 'user_ajax.'
        - 'body'
        - 'post'
        - 'type'
        
    jsRequest:
      js|contains: 'user_ajax.php'
        
    condition: jsKeywords and jsRequest

tags:
  - cryptocurrency