Shopify phishing kit 89NDeg

Shopify phishing kit containing a high-entropy CSRF token which should be a high quality indicator.

References

IOK Rule (edit)

title: Shopify phishing kit 89NDeg
description: |
  Shopify phishing kit containing a high-entropy CSRF token which should be a high quality indicator.
references:
  - https://urlscan.io/result/fc8ed6de-dde5-449a-a5d2-937017b50fde

detection:
  csrfToken:
    # Extracted from: <meta name=csrf-token content="89NDeghGsvjoz3Rk9jMcgyWl4QJBtL6vJxeR1Y/DPNd+tD4dBWmr3ZfZG6g1RjlmbQ9nBIY7Q3utyP02D37MTA==">
    html|contains: '89NDeghGsvjoz3Rk9jMcgyWl4QJBtL6vJxeR1Y/DPNd+tD4dBWmr3ZfZG6g1RjlmbQ9nBIY7Q3utyP02D37MTA=='

  condition: csrfToken

tags:
  - kit
  - target.shopify