Luno crypto exchange phishing kit beb8d53

Luno crypto exchange phishing kit that has a high entropy string set as the origin-trial value

References

Recent Detections

  • hxxps://lundevme[.]dt3svk49t5f2m[.]amplifyapp[.]com/
  • hxxp://lundevme[.]dt3svk49t5f2m[.]amplifyapp[.]com/verification1...
  • hxxp://lundevme[.]dt3svk49t5f2m[.]amplifyapp[.]com/emailverifica...
  • hxxp://lundevme[.]dt3svk49t5f2m[.]amplifyapp[.]com/2-factor_veri...
  • hxxp://lundevme[.]dt3svk49t5f2m[.]amplifyapp[.]com/2-factor_veri...
  • hxxps://dymlu[.]nttrans[.]cc/1/1/1/1/1/index.htm
  • hxxps://developlu[.]d2urtsqsb6eb1[.]amplifyapp[.]com/
  • hxxps://developlu[.]d231qui3ljdjkx[.]amplifyapp[.]com/2-factor_v...
  • hxxp://developlu[.]d231qui3ljdjkx[.]amplifyapp[.]com/verificatio...
  • hxxp://developlu[.]d231qui3ljdjkx[.]amplifyapp[.]com/validating_...

IOK Rule (edit)

title: Luno crypto exchange phishing kit beb8d53
description: |
  Luno crypto exchange phishing kit that has a high entropy string set as the `origin-trial` value
references:
  - https://urlscan.io/search/#hash%3Abeb8d53d9303a2e0a48b25798b83c677de595397e0e82b06ca43b89ed503c845
  
detection:
  originTrialToken:
    html|contains: 'A7dYd5kJpPZNPkzPzk/uHFiBHh1Vy63H7igyI2Dq4m+1d0no9YKaNYQNfAFW3Us09f1k/SiOQW/LKTSjGuLAXg0AAAB+eyJvcmlnaW4iOiJodHRwczovL3RlYWRzLnR2OjQ0MyIsImZlYXR1cmUiOiJDb252ZXJzaW9uTWVhc3VyZW1lbnQiLCJleHBpcnkiOjE2NDMxNTUxOTksImlzU3ViZG9tYWluIjp0cnVlLCJpc1RoaXJkUGFydHkiOnRydWV9'
  condition: originTrialToken

tags:
  - target.luno