-
Notifications
You must be signed in to change notification settings - Fork 37
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Create: 3 IOKs for common Steam phishing kits #212
Conversation
Fixed detection field name
Remove overlapping reference
Remove invalid reference
Remove invalid reference
Remove invalid reference
Please resolve the issues identified by the workflow |
Fix failed to match (added case insensitive title check) https://urlscan.io/result/5c36ed3f-3efe-43a9-a669-f13f4ff0cdcb
Fix metrica.php request
Use (?i) instead of /i
Updated 'giftFromAuronplay' to regex ignoring "<span></span>"s between string.
Added new example
Should all be working now, not sure why 'steam-auronplay.yml' wasn't working for https://urlscan.io/result/23b2c035-4daa-405e-98cd-0f3cdddcd5ca as 'giftFromAuronplay' should have caught it but I've updated it to regex. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The reference scan you mention in your change does not appear to match either the original detection logic nor the updated logic with the regular expression. I believe this reference should be removed from this rule's reference list.
Update rule detection logic & name
Remove dynamic filename from sale banner GIF detection string
Simplify rule logic, fix rule and file name
Modify detection logic to use more robust flags
Remove redundant rule
Adds IOKs for common Steam phishing kits that get spammed in Steam groups:
Steam CSGO2 Beta Phishing Kit
Steam Phishing Kit getsiteconfig:
Steam Auronplay Gift Card Phishing Kit: