-
Notifications
You must be signed in to change notification settings - Fork 37
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
🚀 Create IOK: facebook-pl-5b1aed4d #244
Conversation
Create facebook-pl-5b1aed4d.yml
Hi IlluminatiFish, this seems like a great kit to detect these types of phishing sites. I did some testing with your current rule and did not find any false positives - that's a good thing haha. I would suggest to make one change by adding if the page has the request of the Facebook logo from Wikimedia (https://upload.wikimedia.org/wikipedia/commons/thumb/5/51/Facebook_f_logo_%282019%29.svg/2048px-Facebook_f_logo_%282019%29.svg.png). All of these sites have this request loaded. Adding this would help verify that a site is a type of Facebook phishing. Only having the YouTube video does not seem the best this rule could be. I hope you can get what I'm saying. IOK Rule with these changes:
|
Make changes suggested by Lightning
Rollback changes
If I recall correctly, not all of the phishing pages load their Facebook logo externally some host the logo image file itself internally. Thus the omission of this URL, and pure reliance on the embedded video found. |
🟢 Additions: