id: winscp-phish info: name: winscp phishing Detection author: rxerium severity: info description: | A winscp phishing website was detected reference: - https://winscp.net metadata: max-request: 1 tags: phishing,winscp,osint http: - method: GET path: - "{{BaseURL}}" host-redirects: true max-redirects: 2 matchers-condition: and matchers: - type: word words: - 'WinSCP :: Official Site :: Free SFTP and FTP client for Windows' - type: status status: - 200 - type: dsl dsl: - '!contains(host,"winscp.net")' # digest: 4a0a00473045022100bfc9e4ea7b5a7e01ca72368fae195ea18fcad7d383e1ccd87976c0da776fc2d702200aca5de24e07b27c62937a77339edd992250eeb756885ec43ef0ab5d17211b9f:922c64590222798bb761d5b6d8e72950