Create square-enix-ffxiv-gil-scam.yml #78
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
First time submitting here, I have some questions:
The phishing kit is two separate pages (example below), is it ok to include them in a single definition like this?
Examples:
https://urlscan.io/result/654111fb-82ac-4973-880f-bbaec82694b9/
https://urlscan.io/result/67b4fe92-f667-4201-a310-2cd2cf72af8a/
https://urlscan.io/result/9e171326-b335-498c-a68f-63e1e16a4499/
https://urlscan.io/result/e056ca66-5288-4fb6-8a47-06e03b0f1eba/
The only identifier on the login page is a randomly generated form action php file which is not present on the real page. I can't see any way to identify this other than using regex. Does the detection here support using regex? If so, is the format I've used ok? I couldn't find any documentation on this.
Examples of the login page form action:
https://urlscan.io/result/67b4fe92-f667-4201-a310-2cd2cf72af8a/
https://urlscan.io/result/e056ca66-5288-4fb6-8a47-06e03b0f1eba/
https://urlscan.io/result/74eb3b52-bfea-495a-87a7-1561fdd61c0c/
https://urlscan.io/result/37ca2ce7-337a-4ad9-9979-902e06268042/