2024-02-16 20:27:33 +00:00
id : iCloud-phish
2024-03-23 09:28:19 +00:00
info :
name : iCloud phishing Detection
author : rxerium
severity : info
description : |
A iCloud phishing website was detected
reference :
- https://icloud.com
metadata :
max-request : 1
2024-03-08 07:16:17 +00:00
tags : phishing,icloud,osint
2024-02-16 20:27:33 +00:00
http :
- method : GET
path :
- "{{BaseURL}}"
host-redirects : true
max-redirects : 2
matchers-condition : and
matchers :
- type : word
words :
- 'Log in to iCloud to access your photos, mail, notes, documents and more. Sign in with your Apple ID or create a new account to start using Apple services.'
- type : status
status :
- 200
- type : dsl
dsl :
2024-02-29 14:20:00 +00:00
- '!contains(host,"icloud.com")'
- '!contains(host,"apple.com")'
2024-09-04 15:35:24 +00:00
condition : and
# digest: 490a004630440220312858178acc1c1c0ce119c8a0b2b95d1512a5344c23450ade9f564c494121e0022058b2ff7e493b4549f1f959b50ed517941254eb7f6de09f4877aefd35f9e4f456:922c64590222798bb761d5b6d8e72950