id: malwarebytes-phish info: name: malwarebytes phishing Detection author: rxerium severity: info description: | A malwarebytes phishing website was detected reference: - https://malwarebytes.com tags: phishing,malwarebytes,osint http: - method: GET path: - "{{BaseURL}}" host-redirects: true max-redirects: 2 matchers-condition: and matchers: - type: word words: - 'Cyber Security Software and Anti-Malware | Malwarebytes' - 'Protect your home and business PCs, Macs, iOS and Android devices from the latest cyber threats and malware, including ransomware.' condition: and - type: status status: - 200 - type: dsl dsl: - '!contains(host,"malwarebytes.com")' # digest: 4a0a00473045022100a5e6f466ba45aca3d6b02e53f9d262d4ee63a9d95e1c02c89bc4d9200c95b27702201c73deba1414cbd2329d61530de5dbebb4841e7f42608e2535a57b27066eece3:922c64590222798bb761d5b6d8e72950