SMBC Phishing Kit 10ddf87

IOK Rule (edit)

title: SMBC Phishing Kit 10ddf87
description: |
    Detects a SMBC phishing kit targeting Japanese users.
    
references:
  - https://urlscan.io/result/10ddf87d-8081-4148-8a8d-cc73a9ec6bde
  - https://urlscan.io/result/f0eec5ee-529d-489a-b8f5-89aeb5f0b670
  - https://urlscan.io/result/201221b9-091d-461a-b390-cd8e1cab0996
  
detection:

  hiddenToken: 
    html|contains: 
        - 'name="_TOKEN"' 
        - 'value="224727341138306"'

  mainPagePath:
    requests|contains: 'sanjin/client/index.html'

  condition: hiddenToken and mainPagePath

tags:
  - kit
  - target_country.japan
  - target.smbc