International Card Services Phishing Kit

IOK Rule (edit)

title: International Card Services Phishing Kit
description: |
    Detects a phishing kit for a creditcard processor which uses the same hidden value across various domains.
    
references:
- https://urlscan.io/result/5cea2922-3642-4dc0-b41b-89e914a70f94
- https://urlscan.io/result/44382989-2570-4b17-9fe8-962b6e341ddb
- https://urlscan.io/result/7d2a26cd-8307-46be-9991-e691c962c2ea
- https://urlscan.io/result/52ccdfe2-5af4-4b5b-a70c-73e2cd7b56e6

detection:

    didProxy:
      html|contains: <input id="did_proxy" name="did_proxy" type="hidden" value="1:zEUeQFVqXRrb1FthfkZ64ABdt_5GKQC5gxwQD8dmYXkPJuYmhQBLey8Rpq4xyTEU0FS3yivFtzoWrZDVqZEzXw">

    condition: didProxy

tags:
  - kit
  - target.international_card_services
  - target_country.netherlands