id: anydesk-phish info: name: anydesk phishing Detection author: rxerium severity: info description: | An anydesk phishing website was detected reference: - https://anydesk.com metadata: max-request: 1 tags: phishing,anydesk,osint http: - method: GET path: - "{{BaseURL}}" host-redirects: true max-redirects: 2 matchers-condition: and matchers: - type: word words: - 'The Fast Remote Desktop Application – AnyDesk' - type: status status: - 200 - type: dsl dsl: - '!contains(host,"anydesk.com")' # digest: 4a0a00473045022100a34733799a13f24e239cb58bcace7290427d423386d64ec17b3a7632557c6c1f022065affca2eba5219fd28a196d5b41eb693ea5757f25eade7bb8060c4f595d92ed:922c64590222798bb761d5b6d8e72950