Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 24 additions & 0 deletions indicators/sledgehammer-bookmark-scam-kit.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
title: Sledgehammer Bookmark Scam Kit
description: |
Detects a phishing kit that impersonates a Discord bot called Sledgehammer. These sites have a bookmark scam that steals Discord accounts.

references:
- https://urlscan.io/result/fda3fbfe-673b-4ce4-baff-086cc29f43ed/
- https://urlscan.io/result/001f4298-d4a8-475a-bf88-2caa820d2376/
- https://urlscan.io/search/#page.url%3A%22%2Fverify%2Fguild%2F%22
- https://urlscan.io/search/#page.title%3A%22Sledgehammer%20-%20Homepage%22

detection:

pageTitle:
title: "Sledgehammer - Homepage"

pageHTML:
html|contains|all:
Comment thread
LightningDev23 marked this conversation as resolved.
- "Community Verification"

condition: pageTitle and pageHTML

tags:
- kit
- target.discord