diff --git a/indicators/elon-youtube-b4e7a9c2 b/indicators/elon-youtube-b4e7a9c2 new file mode 100644 index 00000000..c0df61e8 --- /dev/null +++ b/indicators/elon-youtube-b4e7a9c2 @@ -0,0 +1,30 @@ +title: Elon Musk Crypto Giveaway Phishing Kit b4e7a9c2 +description: | + These phishing sites pretend to be Elon Musk-endorsed crypto giveaways, designed to deceive users into sending + cryptocurrency or revealing private keys, with false promises of greater returns. +references: + - https://urlscan.io/result/652a9d46-c012-42d1-a148-5bcf45174bf9 + - https://urlscan.io/result/3cf5b7c4-a5f9-455c-a387-fd73a010aa9f + - https://urlscan.io/result/2baed78f-44e1-4d8e-8943-971a470fa7d4 + - https://urlscan.io/result/e2c67e74-69f7-4ad2-8a25-3ea9a74be45c + - https://urlscan.io/result/c91ac187-9eb0-4168-93c6-ddf7e27e9e55 +detection: + muskCryptoPhrases: + html|contains|any: + - 'Elon Musk giveaway' + - 'biggest crypto giveaway of' + - 'the most global event' + - 'huge crypto giveaway during the launch' + - 'Elon Musk' + - 'Tesla' + - 'SpaceX' + chatDomain: + domain|contains: + - 'bootstrap.smartsuppchat.com' + condition: muskCryptoPhrases or chatDomain +tags: + - crypto_scam + - impersonation + - target.elon_musk + - target.tesla + - target.spacex