home *** CD-ROM | disk | FTP | other *** search
/ ftp.f-secure.com / 2014.06.ftp.f-secure.com.tar / ftp.f-secure.com / support / hotfix / fsis / IS-SpamControl.fsfix / iufssc / rules / 96_fs-fraud.cf < prev    next >
Text File  |  2006-11-29  |  33KB  |  521 lines

  1. # 96_fs-fraud.cf -- era Wed Sep  7 03:31:05 PM 2005
  2. # Copyright (C) 2005-2006 F-Secure Corporation
  3. # $Id: 96_fs-fraud.cf 4149 2006-11-15 10:24:56Z eriker $
  4.  
  5. # Fraud victims:
  6. #  .com
  7. #    paypal
  8. #    ebay
  9. #    ebayrtm
  10. #    onlinebankofamerica
  11. #    bankofamerica
  12. #    bankofcastile
  13. #    bankofoklahoma
  14. #    bankofthewest
  15. #    bankone
  16. #    bancorpsouth
  17. #    bancorpsouthonline
  18. #    pcbancorp
  19. #    sbbt
  20. #    o2bancorp
  21. #    02bancorp
  22. #    bangor
  23. #    bok
  24. #    bbkonline
  25. #    bhf-bank
  26. #    comfedbank
  27. #    householdbank
  28. #    usbank
  29. #    royalbank
  30. #    rbc
  31. #    rbsdigital
  32. #    afbank
  33. #    northfork
  34. #    stfrancisbank
  35. #    tcfbank
  36. #    ameritrade
  37. #    citibank
  38. #    citibusinessonline
  39. #    citigroup
  40. #    citifinancial
  41. #    citizens
  42. #    citizensbank
  43. #    citizensbankonline
  44. #    skyfi
  45. #    star
  46. #    wamu
  47. #    providian
  48. #    providianservices
  49. #    flagstar
  50. #    fult
  51. #    fultonbank
  52. #    fultonfinancialadvisors
  53. #    unionplanters
  54. #    elizfed
  55. #    regionsbank
  56. #    regionsnet
  57. #    charterone
  58. #    chase
  59. #    lasallebank
  60. #    nationalcity
  61. #    national-city
  62. #    nationet
  63. #    cnb
  64. #    cnbwax
  65. #    aafcu
  66. #    ccfcu
  67. #    uofucu
  68. #    capitalone
  69. #    capital1
  70. #    goldenone
  71. #    golden1
  72. #    wachovia
  73. #    wellsfargo
  74. #    wells-fargo
  75. #    wf
  76. #    westernunion
  77. #    e-gold
  78. #    mastercard
  79. #    visa
  80. #    schwab
  81. #    egg
  82. #    epassporte
  83. #    columbusbankandtrust
  84. #    southtrust
  85. #    suntrust
  86. #    lloydstsb
  87. #    hsbc
  88. #    hsbc-us
  89. #    mbna
  90. #    mbnanetaccess
  91. #    barclays
  92. #    53
  93. #    firstmerit
  94. #    firsttennessee
  95. #    ohiosavings
  96. #    peoples
  97. #    comerica
  98. #    downeysavings
  99. #    machiassavings
  100. #    machiasavings
  101. #    anbtx
  102. #    anz
  103. #    iblogin
  104. #    desjardins
  105. #    bmo
  106. #    cibc
  107. #    canadianimperial
  108. #    td
  109. #    tdbank
  110. #    tdcanadatrust
  111. #    scotiabank
  112. #    santander
  113. #    banesto
  114. #    bancosantander
  115. #    gruposantander
  116. #    keybank
  117. #    key
  118. #    midamericabank
  119. #    midamerica
  120. #    pnc
  121. #    pncbank
  122. #    gesa
  123. #    fundsxpress
  124. #    amazon
  125. #    dell
  126. #    symantec
  127. #  .us
  128. #    mbna
  129. #  .ca
  130. #    ebay
  131. #    paypal
  132. #    desjardins
  133. #    bmo
  134. #    cibc
  135. #    tdbank
  136. #    tdcanadatrust
  137. #    scotiabank
  138. #  .de
  139. #    ebay
  140. #    deutsche-bank
  141. #    dresdner-bank
  142. #    postbank
  143. #    volksbank
  144. #    hypovereinsbank
  145. #    hvb
  146. #    vr-networld
  147. #    sparkasse
  148. #    paypal
  149. #  .at
  150. #    sparkasse
  151. #  .be
  152. #    abb-bvb
  153. #  .it
  154. #    ebay
  155. #    fineco
  156. #    sella
  157. #  .es
  158. #    banesto
  159. #    bancosantander
  160. #    gruposantander
  161. #  .com.es
  162. #    bancosantander
  163. #    gruposantander
  164. #  .com.mx
  165. #    santander
  166. #    bancosantander
  167. #    gruposantander
  168. #  .se
  169. #    enskilda
  170. #    seb
  171. #    sebank
  172. #    nordea
  173. #  .fi
  174. #    nordea
  175. #  .gr
  176. #    alpha
  177. #  .co.uk
  178. #    alliance-leicester
  179. #    bankofscotland
  180. #    barclays
  181. #    halifax
  182. #    halifax-online
  183. #    hsbc
  184. #    lloydstsb
  185. #    nationwide
  186. #    rbs
  187. #    co-operativebank
  188. #    sainsburysbank
  189. #  .co.za
  190. #    standardbank
  191. #  .co.nz
  192. #    trademe
  193. #  .com.au
  194. #    ebay
  195. #    citibank
  196. #    commbank
  197. #    national
  198. #  .com.br
  199. #    bradesco
  200. #  .gov
  201. #    ncua
  202. #    irs
  203. #  .org
  204. #    alaskausa
  205. #    americaneagle
  206. #    nafcu
  207. #    nafcunet
  208. #    ncleague
  209. #    redcross
  210. #    mtnamerica
  211. #    3riversfcu
  212. #    cafcu
  213. #    lacapfcu
  214. #    paragonfcu
  215. #    visionsfcu
  216. #    nymcu
  217. #    msgcu
  218. #    argonnecu
  219. #    dupagecu
  220. #    tdecu
  221. #    uofucu
  222. #    un
  223. #    unicef
  224. #
  225. # Proactively listed sites:
  226. #  Not necessarily fraudulent, but not really the real thing
  227. #  .com
  228. #    creditunion
  229. #    ebay2 (FRAUDULENT)
  230. #    lasalle
  231. #    paypai (FRAUDULENT)
  232. #    downey
  233. #  .us
  234. #    paypal (FRAUDULENT)
  235. #  .ca
  236. #    rbc
  237. #    td
  238. #    scotia
  239. #    canadianimperial (FRAUDULENT?)
  240. #  .co.uk
  241. #    lloyds
  242. #  .es
  243. #    santander
  244. #  .com.es
  245. #    santander
  246.  
  247. # rule: FS_PHISH_PAYPAL_PIXEL
  248. # added 2005-09-07
  249. # test: ######## TODO: provide sample
  250. # temp: /tmp/ph/00018.msg
  251.  
  252. uri __FS_PAYPAL_PIXEL m%^https?://(?:images\.paypal\.com|(?:www\.)?paypalobjects\.com)(?:[/?].*?)?[/?]pixel\.gif$%
  253.  
  254. header     __FS_FROM_EBAY        From:addr =~ /[@\.]ebay\.com$/i
  255. header     __FS_FROM_PAYPAL    From:addr =~ /[@\.]paypal\.com$/i
  256. meta     __FS_FROM_PAYBAY    (__FS_FROM_EBAY || __FS_FROM_PAYPAL)
  257.  
  258. meta     FS_PHISH_PAYPAL_PIXEL (__FS_PAYPAL_PIXEL && (! __FS_FROM_PAYBAY))
  259. describe FS_PHISH_PAYPAL_PIXEL Phish: Not PayPal/Ebay, but has PayPal pixel
  260. score     FS_PHISH_PAYPAL_PIXEL 9
  261.  
  262.  
  263.  
  264. # rule: FS_PHISH_VICTIM_FROM
  265. # added 2005-09-19
  266. # edit 2006-03-14: optional subdomain in realname part; minor regex tweaks
  267. # test: ######## TODO: provide sample
  268. # temp: phishing/1102018179.V802Ia7aca.localhost.localdomain
  269. # temp: phishing-samples/d-fence/virus-7-1r0Cz4dzfo.msg <- not!
  270.  
  271. header     FS_PHISH_VICTIM_FROM From =~ m/"(?:[^"@]+@)?(?:[^"@.]+\.)*((paypal|ebay|ban(?:corpsouth(?:online)?|k(?:one|of(?:america|castile|oklahoma|thewest))|gor)|onlinebankofamerica|sbbt|(?:02|o2|pc)bancorp|b(?:bkonline|ok)|(af|bhf-|comfed|household|northfork|royal|stfrancis|tcf|us)bank|rb(?:c|sdigital)|ameritrade|citi(?:bank|businessonline|group|financial|zens(bank(online)?)?)?|skyfi|star|wamu|paypai|providian(?:services)?|f(?:lagstar|ult(on(bank|financialadvisors)?)?)|unionplanters|elizfed|regions(?:bank|net)?|cha(rterone|se)|lasalle(bank)?|nation(?:al-?city|et)|(?:capital|golden)(?:1|one)|cnb(?:wax)?|(?:(?:aa|cc)f|uofu)cu|w(?:achovia|ells-?fargo|f|esternunion)|e-gold|mastercard|visa|schwab|e(?:bay2|gg|passporte)|(?:columbusbankand|s(?:outh|un))trust|lloydstsb|hsbc(?:-us)?|mbna(?:netaccess)?|53|barclays|first(merit|tennessee)|ohiosavings|peoples|comerica|downey(?:savings)?|(?:machias?)savings|an(?:btx|z)|iblogin|(?:key|pnc|midamerica)(?:bank)?|gesa|fundsxpress|creditunion|amazon|dell|symantec)\.com|(?:mbna|paypal)\.us|(?:desjardins|bmo|cibc|canadianimperial|td(?:bank|canadatrust)?|scotiabank)\.(?:com|ca)|(?:paypal|ebay)\.ca|(?:ebay|hvb|vr-networld|(?:d(?:eutsche|resdner)-|post|volks|hypovereins)bank|sparkasse|paypal)\.de|abb-bvb\.be|sparkasse\.at|(ebay|fineco|sella)\.it|(?:(?:banc|grup)o)?santander\.(?:com\.(?:es|mx)|com|es)|banesto\.es|nordea\.(se|fi)|(enskilda|seb(ank)?)\.se|alpha\.gr|(?:alliance-leicester|ba(?:nkofscotland|rclays)|halifax(?:-online)?|hsbc|lloyds(?:tsb)?|nationwide|rbs|(?:co-operative|sainsburys)bank)\.co\.uk|standardbank\.co\.za|trademe\.co\.nz|(?:ebay|c(?:iti|omm)bank|national)\.com\.au|bradesco\.com\.br|(?:ncua|irs)\.gov|(?:a(?:mericaneagle|laskausa)|n(?:afcu(?:net)?|nleague)|redcross|mtnamerica|(?:(?:3rivers|ca|lacap|paragon|visions)f|(?:argonn|dupag|td)e|msg|nym|uofu)cu|un(icef)?)\.org)" <[^<>@]*@([^<>@.]+\.)*(?!\1)[^@.]+\.[a-z]{2,5}>/i
  272.  
  273. describe FS_PHISH_VICTIM_FROM Phish: From "Fraudvictim.com" <other@ddress.tld>
  274. score     FS_PHISH_VICTIM_FROM 20
  275.  
  276.  
  277.  
  278.  
  279. # rule: FS_PHISH_VICTIM_URL
  280. # added 2005-09-19
  281. # edit 2006-02-13: permit <font> or <span> inside <a>, and attribs before href
  282. # edit 2006-03-03: permit newline before victim URL
  283. # edit 2006-03-06: yet more permissive about whitespace in <a href="...">
  284. # edit 2006-04-13: remove amazon.com from regex
  285. # edit 2006-04-19: fix regex for optional attributes; allow HTML comment in URL
  286. # edit 2006-04-21: split into full and rawbody sub-rules, essentially identical
  287. # edit 2006-09-20: prevent looping in href=("?)[^"]...
  288. # test: ######## TODO: provide sample
  289. # temp: phishing/1112090647.V802Ia7b4e.localhost.localdomain
  290. # temp: phishing/1107052552.V802Ia7ad8.localhost.localdomain
  291. # temp: phishing-samples/chase-eeera-2006-03-03.msg
  292. # temp: phishing-samples/pirkka-wells-fargo-2006-03-05.msg
  293. # temp: phishing-samples@fs/hermanni-2006-04-18/34
  294. # temp: phishing-samples@fs/hermanni-2006-04-18/36
  295. # test: phishing-samples@fs/d-fence/virus-0ykhRZCVGLs2.msg
  296. # fail: ham-samples@fs/elmeklev-2006-02-28/00014.msg
  297. # fail: reference-ham/0011cts41142.eml
  298.  
  299. ######## NOTE: amazon excluded from regular expression
  300. full     __FS_PHISH_VICTIM_URL_FULL m{<a[\s\n]+(?:[^\s<>]+[\s\n]+)?href=("?)([^\"<>]+)\1(?:[\s\n]+[^\s\n<>]+)*[\s\n]*>(?:[\s\n]*<(font|span)[^<>]+>)?[\n\s]*(?!\2)https?://(?:[^/.]+\.){0,2}?(?:<!-- [^<>]+ -->)?((paypal|ebay(?:rtm|static)?|ban(?:corpsouth(?:online)?|k(?:one|of(?:america|castile|oklahoma|thewest))|gor)|onlinebankofamerica|sbbt|(?:02|o2|pc)bancorp|b(?:bkonline|ok)|(af|bhf-|comfed|household|northfork|royal|stfrancis|tcf|us)bank|rb(?:c|sdigital)|ameritrade|citi(?:bank|businessonline|group|financial|zens(bank(online)?)?)?|skyfi|star|wamu|paypai|providian(?:services)?|f(?:lagstar|ult(on(bank|financialadvisors)?)?)|unionplanters|elizfed|regions(?:bank|net)?|cha(rterone|se)|lasalle(bank)?|nation(?:al-?city|et)|(?:capital|golden)(?:1|one)|cnb(?:wax)?|(?:(?:aa|cc)f|uofu)cu|w(?:achovia|ells-?fargo|f|esternunion)|e-gold|mastercard|visa|schwab|e(?:bay2|gg|passporte)|(?:columbusbankand|s(?:outh|un))trust|lloydstsb|hsbc(?:-us)?|mbna(?:netaccess)?|53|barclays|first(merit|tennessee)|ohiosavings|peoples|comerica|downey(?:savings)?|(?:machias?)savings|an(?:btx|z)|iblogin|(?:key|pnc|midamerica)(?:bank)?|gesa|fundsxpress|creditunion|dell|symantec)\.com|(?:mbna|paypal)\.us|(?:desjardins|bmo|cibc|canadianimperial|td(?:bank|canadatrust)?|scotiabank)\.(?:com|ca)|(?:paypal|ebay)\.ca|(?:ebay|hvb|vr-networld|(?:d(?:eutsche|resdner)-|post|volks|hypovereins)bank|sparkasse|paypal)\.de|abb-bvb\.be|sparkasse\.at|(ebay|fineco|sella)\.it|(?:(?:banc|grup)o)?santander\.(?:com\.(?:es|mx)|com|es)|banesto\.es|nordea\.(se|fi)|(enskilda|seb(ank)?)\.se|alpha\.gr|(?:alliance-leicester|ba(?:nkofscotland|rclays)|halifax(?:-online)?|hsbc|lloyds(?:tsb)?|nationwide|rbs|(?:co-operative|sainsburys)bank)\.co\.uk|standardbank\.co\.za|trademe\.co\.nz|(?:ebay|c(?:iti|omm)bank|national)\.com\.au|bradesco\.com\.br|(?:ncua|irs)\.gov|(?:a(?:mericaneagle|laskausa)|n(?:afcu(?:net)?|nleague)|redcross|mtnamerica|(?:(?:3rivers|ca|lacap|paragon|visions)f|(?:argonn|dupag|td)e|msg|nym|uofu)cu|un(icef)?)\.org)(?:[/?&][^<>]*)?<}i
  301. rawbody     __FS_PHISH_VICTIM_URL_BODY m{<a[\s\n]+(?:[^\s<>]+[\s\n]+)?href=("?)([^\"<>]+)\1(?:[\s\n]+[^\s\n<>]+)*[\s\n]*>(?:[\s\n]*<(font|span)[^<>]+>)?[\n\s]*(?!\2)https?://(?:[^/.]+\.){0,2}?(?:<!-- [^<>]+ -->)?((paypal|ebay(?:rtm|static)?|ban(?:corpsouth(?:online)?|k(?:one|of(?:america|castile|oklahoma|thewest))|gor)|onlinebankofamerica|sbbt|(?:02|o2|pc)bancorp|b(?:bkonline|ok)|(af|bhf-|comfed|household|northfork|royal|stfrancis|tcf|us)bank|rb(?:c|sdigital)|ameritrade|citi(?:bank|businessonline|group|financial|zens(bank(online)?)?)?|skyfi|star|wamu|paypai|providian(?:services)?|f(?:lagstar|ult(on(bank|financialadvisors)?)?)|unionplanters|elizfed|regions(?:bank|net)?|cha(rterone|se)|lasalle(bank)?|nation(?:al-?city|et)|(?:capital|golden)(?:1|one)|cnb(?:wax)?|(?:(?:aa|cc)f|uofu)cu|w(?:achovia|ells-?fargo|f|esternunion)|e-gold|mastercard|visa|schwab|e(?:bay2|gg|passporte)|(?:columbusbankand|s(?:outh|un))trust|lloydstsb|hsbc(?:-us)?|mbna(?:netaccess)?|53|barclays|first(merit|tennessee)|ohiosavings|peoples|comerica|downey(?:savings)?|(?:machias?)savings|an(?:btx|z)|iblogin|(?:key|pnc|midamerica)(?:bank)?|gesa|fundsxpress|creditunion|dell|symantec)\.com|(?:mbna|paypal)\.us|(?:desjardins|bmo|cibc|canadianimperial|td(?:bank|canadatrust)?|scotiabank)\.(?:com|ca)|(?:paypal|ebay)\.ca|(?:ebay|hvb|vr-networld|(?:d(?:eutsche|resdner)-|post|volks|hypovereins)bank|sparkasse|paypal)\.de|abb-bvb\.be|sparkasse\.at|(ebay|fineco|sella)\.it|(?:(?:banc|grup)o)?santander\.(?:com\.(?:es|mx)|com|es)|banesto\.es|nordea\.(se|fi)|(enskilda|seb(ank)?)\.se|alpha\.gr|(?:alliance-leicester|ba(?:nkofscotland|rclays)|halifax(?:-online)?|hsbc|lloyds(?:tsb)?|nationwide|rbs|(?:co-operative|sainsburys)bank)\.co\.uk|standardbank\.co\.za|trademe\.co\.nz|(?:ebay|c(?:iti|omm)bank|national)\.com\.au|bradesco\.com\.br|(?:ncua|irs)\.gov|(?:a(?:mericaneagle|laskausa)|n(?:afcu(?:net)?|nleague)|redcross|mtnamerica|(?:(?:3rivers|ca|lacap|paragon|visions)f|(?:argonn|dupag|td)e|msg|nym|uofu)cu|un(icef)?)\.org)(?:[/?&][^<>]*)?<}i
  302. meta     FS_PHISH_VICTIM_URL __FS_PHISH_VICTIM_URL_FULL || __FS_PHISH_VICTIM_URL_BODY
  303. describe FS_PHISH_VICTIM_URL Phish: URL displays victim.tld but links elsewhere
  304. score     FS_PHISH_VICTIM_URL 9
  305.  
  306.  
  307. # rule: FS_PHISH_VICTIM_URL_TITLE
  308. # added 2006-02-13
  309. # test: ######## TODO: provide sample
  310. ######## FIXME: handle case where title attribute follows after href attrib
  311. # temp: /var/tmp/phish-amazon-too.msg
  312.  
  313. full     FS_PHISH_VICTIM_URL_TITLE m{<a\s+(?:[^\s<>]+\s+)?\s+title="?(?!\2)https?://(?:[^/.]+\.){0,2}?((paypal|ebay(?:rtm|static)?|ban(?:corpsouth(?:online)?|k(?:one|of(?:america|castile|oklahoma|thewest))|gor)|onlinebankofamerica|sbbt|(?:02|o2|pc)bancorp|b(?:bkonline|ok)|(af|bhf-|comfed|household|northfork|royal|stfrancis|tcf|us)bank|rb(?:c|sdigital)|ameritrade|citi(?:bank|businessonline|group|financial|zens(bank(online)?)?)?|skyfi|star|wamu|paypai|providian(?:services)?|f(?:lagstar|ult(on(bank|financialadvisors)?)?)|unionplanters|elizfed|regions(?:bank|net)?|cha(rterone|se)|lasalle(bank)?|nation(?:al-?city|et)|(?:capital|golden)(?:1|one)|cnb(?:wax)?|(?:(?:aa|cc)f|uofu)cu|w(?:achovia|ells-?fargo|f|esternunion)|e-gold|mastercard|visa|schwab|e(?:bay2|gg|passporte)|(?:columbusbankand|s(?:outh|un))trust|lloydstsb|hsbc(?:-us)?|mbna(?:netaccess)?|53|barclays|first(merit|tennessee)|ohiosavings|peoples|comerica|downey(?:savings)?|(?:machias?)savings|an(?:btx|z)|iblogin|(?:key|pnc|midamerica)(?:bank)?|gesa|fundsxpress|creditunion|amazon|dell|symantec)\.com|(?:mbna|paypal)\.us|(?:desjardins|bmo|cibc|canadianimperial|td(?:bank|canadatrust)?|scotiabank)\.(?:com|ca)|(?:paypal|ebay)\.ca|(?:ebay|hvb|vr-networld|(?:d(?:eutsche|resdner)-|post|volks|hypovereins)bank|sparkasse|paypal)\.de|abb-bvb\.be|sparkasse\.at|(ebay|fineco|sella)\.it|(?:(?:banc|grup)o)?santander\.(?:com\.(?:es|mx)|com|es)|banesto\.es|nordea\.(se|fi)|(enskilda|seb(ank)?)\.se|alpha\.gr|(?:alliance-leicester|ba(?:nkofscotland|rclays)|halifax(?:-online)?|hsbc|lloyds(?:tsb)?|nationwide|rbs|(?:co-operative|sainsburys)bank)\.co\.uk|standardbank\.co\.za|trademe\.co\.nz|(?:ebay|c(?:iti|omm)bank|national)\.com\.au|bradesco\.com\.br|(?:ncua|irs)\.gov|(?:a(?:mericaneagle|laskausa)|n(?:afcu(?:net)?|nleague)|redcross|mtnamerica|(?:(?:3rivers|ca|lacap|paragon|visions)f|(?:argonn|dupag|td)e|msg|nym|uofu)cu|un(icef)?)\.org)(?:[/?&][^<>"]*)?(?:\s+[^\s<>]+)?href="?([^\"]+)["\s>]}i
  314. #meta     FS_PHISH_VICTIM_URL_TITLE (__FS_PHISH_VICTIM_URL_TITLE_BEFORE || __FS_PHISH_VICTIM_URL_TITLE_AFTER)
  315. describe FS_PHISH_VICTIM_URL_TITLE Phish: href title displays wrong victim URL
  316. score     FS_PHISH_VICTIM_URL_TITLE 9
  317.  
  318.  
  319.  
  320. # rule: FS_PHISH_VICTIM_URL_TAIL
  321. # added 2006-03-08
  322. # edit 2006-10-18: permit tail to be ccTLD
  323. # edit 2006-11-14: limit ccTLD tail to .com and .org TLDs
  324. # test: ######## TODO: provide sample
  325. ######## TODO: extend ccTLD exemption to .net .gov .mil etc as required
  326. # temp: phishing/pirkka-wells-fargo-2006-03-05.msg
  327. # fail: reference/ebay-era-2006-10-18_041.msg
  328. # fail: reference-spam/ebay-cn-era-2006-11-13_051.msg
  329.  
  330. uri     FS_PHISH_VICTIM_URL_TAIL m{^https?://(?:[^/.:]+\.){0,2}?(?![^/.:]+\.(?:com|org)\.[a-z]{2})((paypal|ebay|ban(?:corpsouth(?:online)?|k(?:one|of(?:america|castile|oklahoma|thewest))|gor)|onlinebankofamerica|sbbt|(?:02|o2|pc)bancorp|b(?:bkonline|ok)|(af|bhf-|comfed|household|northfork|royal|stfrancis|tcf|us)bank|rb(?:c|sdigital)|ameritrade|citi(?:bank|businessonline|group|financial|zens(bank(online)?)?)?|skyfi|star|wamu|paypai|providian(?:services)?|f(?:lagstar|ult(on(bank|financialadvisors)?)?)|unionplanters|elizfed|regions(?:bank|net)?|cha(rterone|se)|lasalle(bank)?|nation(?:al-?city|et)|(?:capital|golden)(?:1|one)|cnb(?:wax)?|(?:(?:aa|cc)f|uofu)cu|w(?:achovia|ells-?fargo|f|esternunion)|e-gold|mastercard|visa|schwab|e(?:bay2|gg|passporte)|(?:columbusbankand|s(?:outh|un))trust|lloydstsb|hsbc(?:-us)?|mbna(?:netaccess)?|53|barclays|first(merit|tennessee)|ohiosavings|peoples|comerica|downey(?:savings)?|(?:machias?)savings|an(?:btx|z)|iblogin|(?:key|pnc|midamerica)(?:bank)?|gesa|fundsxpress|creditunion|amazon|dell|symantec)\.com|(?:mbna|paypal)\.us|(?:desjardins|bmo|cibc|canadianimperial|td(?:bank|canadatrust)?|scotiabank)\.(?:com|ca)|(?:paypal|ebay)\.ca|(?:ebay|hvb|vr-networld|(?:d(?:eutsche|resdner)-|post|volks|hypovereins)bank|sparkasse|paypal)\.de|abb-bvb\.be|sparkasse\.at|(ebay|fineco|sella)\.it|(?:(?:banc|grup)o)?santander\.(?:com\.(?:es|mx)|com|es)|banesto\.es|nordea\.(se|fi)|(enskilda|seb(ank)?)\.se|alpha\.gr|(?:alliance-leicester|ba(?:nkofscotland|rclays)|halifax(?:-online)?|hsbc|lloyds(?:tsb)?|nationwide|rbs|(?:co-operative|sainsburys)bank)\.co\.uk|standardbank\.co\.za|trademe\.co\.nz|(?:ebay|c(?:iti|omm)bank|national)\.com\.au|bradesco\.com\.br|(?:ncua|irs)\.gov|(?:a(?:mericaneagle|laskausa)|n(?:afcu(?:net)?|nleague)|redcross|mtnamerica|(?:(?:3rivers|ca|lacap|paragon|visions)f|(?:argonn|dupag|td)e|msg|nym|uofu)cu|un(icef)?)\.org)\.(?![a-z]{2}[:/])[a-z0-9]}i
  331.  
  332. describe FS_PHISH_VICTIM_URL_TAIL Phish: URL points to victim.tld.what.ever
  333. score     FS_PHISH_VICTIM_URL_TAIL 9
  334.  
  335.  
  336.  
  337. # rule: FS_PHISH_VICTIM_URL_PREFIX
  338. # added 2006-04-20
  339. # test: phishing-samples@fs/d-fence/virus-nZHIlSZwaKds.msg
  340.  
  341. uri     __FS_PHISH_VICTIM_URL_PREFIX m{^https?://(?:[^/.:]+\.){0,3}?([^/.:]+\.(?:[^/.:]{2,3}\.)?[^/.:]{2,5})(?:\:\d+)?[?/](?:.*[./])?(?!\1)((paypal|ebay|ban(?:corpsouth(?:online)?|k(?:one|of(?:america|castile|oklahoma|thewest))|gor)|onlinebankofamerica|sbbt|(?:02|o2|pc)bancorp|b(?:bkonline|ok)|(af|bhf-|comfed|household|northfork|royal|stfrancis|tcf|us)bank|rb(?:c|sdigital)|ameritrade|citi(?:bank|businessonline|group|financial|zens(bank(online)?)?)?|skyfi|star|wamu|paypai|providian(?:services)?|f(?:lagstar|ult(on(bank|financialadvisors)?)?)|unionplanters|elizfed|regions(?:bank|net)?|cha(rterone|se)|lasalle(bank)?|nation(?:al-?city|et)|(?:capital|golden)(?:1|one)|cnb(?:wax)?|(?:(?:aa|cc)f|uofu)cu|w(?:achovia|ells-?fargo|f|esternunion)|e-gold|mastercard|visa|schwab|e(?:bay2|gg|passporte)|(?:columbusbankand|s(?:outh|un))trust|lloydstsb|hsbc(?:-us)?|mbna(?:netaccess)?|53|barclays|first(merit|tennessee)|ohiosavings|peoples|comerica|downey(?:savings)?|(?:machias?)savings|an(?:btx|z)|iblogin|(?:key|pnc|midamerica)(?:bank)?|gesa|fundsxpress|creditunion|amazon|dell|symantec)\.com|(?:mbna|paypal)\.us|(?:desjardins|bmo|cibc|canadianimperial|td(?:bank|canadatrust)?|scotiabank)\.(?:com|ca)|(?:paypal|ebay)\.ca|(?:ebay|hvb|vr-networld|(?:d(?:eutsche|resdner)-|post|volks|hypovereins)bank|sparkasse|paypal)\.de|abb-bvb\.be|sparkasse\.at|(ebay|fineco|sella)\.it|(?:(?:banc|grup)o)?santander\.(?:com\.(?:es|mx)|com|es)|banesto\.es|nordea\.(se|fi)|(enskilda|seb(ank)?)\.se|alpha\.gr|(?:alliance-leicester|ba(?:nkofscotland|rclays)|halifax(?:-online)?|hsbc|lloyds(?:tsb)?|nationwide|rbs|(?:co-operative|sainsburys)bank)\.co\.uk|standardbank\.co\.za|trademe\.co\.nz|(?:ebay|c(?:iti|omm)bank|national)\.com\.au|bradesco\.com\.br|(?:ncua|irs)\.gov|(?:a(?:mericaneagle|laskausa)|n(?:afcu(?:net)?|nleague)|redcross|mtnamerica|(?:(?:3rivers|ca|lacap|paragon|visions)f|(?:argonn|dupag|td)e|msg|nym|uofu)cu|un(icef)?)\.org)(?:/|$)}i
  342.  
  343. meta     FS_PHISH_VICTIM_URL_PREFIX (__FS_PHISH_VICTIM_URL_PREFIX && __FS_PHISH_VICTIM_FROM)
  344. describe FS_PHISH_VICTIM_URL_PREFIX Phish: URL points to site.tld/...victim.tld
  345. score     FS_PHISH_VICTIM_URL_PREFIX 9
  346.  
  347.  
  348.  
  349.  
  350. # rule: FS_PHISH_SHOWLINKWARNING
  351. # added 2006-04-20
  352. # test: phishing-samples@fs/d-fence/virus-M5e7DGlQJ1zS.msg
  353.  
  354. full     __FS_HREF_SHOWLINKWARNING m{<a(?:[\s\n]+[^<>\s\n]+)*[\s\n]+on(?:(?:dbl)?click|mouse(?:down|move|o(?:ut|ver)|up))[\s\n]*=(?:3D)?[\s\n]*"[\s\n]*return[\s\n]+showlinkwarning\([\s\n]*\);?[\s\n]*"}i
  355.  
  356. meta     FS_PHISH_SHOWLINKWARNING __FS_PHISH_VICTIM_FROM && __FS_HREF_SHOWLINKWARNING
  357. describe FS_PHISH_SHOWLINKWARNING Phish: ShowLinkWarning() JavaScript in link
  358. score     FS_PHISH_SHOWLINKWARNING 9
  359.  
  360.  
  361.  
  362. # rule: FS_PHISH_VICTIM_MSGID
  363. # added 2005-09-19
  364. # edit 2006-03-14: optional subdomain in __FS_PHISH_VICTIM_FROM
  365. # edit 2006-05-02: add __FS_PHISH_VICTIM_FROM_NONORDEA
  366. # test: ######## TODO: provide sample
  367. # temp: phishing/1109596361.V802Ia7b10.localhost.localdomain
  368.  
  369. header     __FS_PHISH_VICTIM_FROM From:addr =~ m/^(?:[^"@]+@)(?:[^"@.]+\.)*((paypal|ebay|ban(?:corpsouth(?:online)?|k(?:one|of(?:america|castile|oklahoma|thewest))|gor)|onlinebankofamerica|sbbt|(?:02|o2|pc)bancorp|b(?:bkonline|ok)|(af|bhf-|comfed|household|northfork|royal|stfrancis|tcf|us)bank|rb(?:c|sdigital)|ameritrade|citi(?:bank|businessonline|group|financial|zens(bank(online)?)?)?|skyfi|star|wamu|paypai|providian(?:services)?|f(?:lagstar|ult(on(bank|financialadvisors)?)?)|unionplanters|elizfed|regions(?:bank|net)?|cha(rterone|se)|lasalle(bank)?|nation(?:al-?city|et)|(?:capital|golden)(?:1|one)|cnb(?:wax)?|(?:(?:aa|cc)f|uofu)cu|w(?:achovia|ells-?fargo|f|esternunion)|e-gold|mastercard|visa|schwab|e(?:bay2|gg|passporte)|(?:columbusbankand|s(?:outh|un))trust|lloydstsb|hsbc(?:-us)?|mbna(?:netaccess)?|53|barclays|first(merit|tennessee)|ohiosavings|peoples|comerica|downey(?:savings)?|(?:machias?)savings|an(?:btx|z)|iblogin|(?:key|pnc|midamerica)(?:bank)?|gesa|fundsxpress|creditunion|amazon|dell|symantec)\.com|(?:mbna|paypal)\.us|(?:desjardins|bmo|cibc|canadianimperial|td(?:bank|canadatrust)?|scotiabank)\.(?:com|ca)|(?:paypal|ebay)\.ca|(?:ebay|hvb|vr-networld|(?:d(?:eutsche|resdner)-|post|volks|hypovereins)bank|sparkasse|paypal)\.de|abb-bvb\.be|sparkasse\.at|(ebay|fineco|sella)\.it|(?:(?:banc|grup)o)?santander\.(?:com\.(?:es|mx)|com|es)|banesto\.es|nordea\.(se|fi)|(enskilda|seb(ank)?)\.se|alpha\.gr|(?:alliance-leicester|ba(?:nkofscotland|rclays)|halifax(?:-online)?|hsbc|lloyds(?:tsb)?|nationwide|rbs|(?:co-operative|sainsburys)bank)\.co\.uk|standardbank\.co\.za|trademe\.co\.nz|(?:ebay|c(?:iti|omm)bank|national)\.com\.au|bradesco\.com\.br|(?:ncua|irs)\.gov|(?:a(?:mericaneagle|laskausa)|n(?:afcu(?:net)?|nleague)|redcross|mtnamerica|(?:(?:3rivers|ca|lacap|paragon|visions)f|(?:argonn|dupag|td)e|msg|nym|uofu)cu|un(icef)?)\.org)$/i
  370. # the same without Nordea
  371. header     __FS_PHISH_VICTIM_FROM_NONORDEA From:addr =~ m/^(?:[^"@]+@)(?:[^"@.]+\.)*((paypal|ebay|ban(?:corpsouth(?:online)?|k(?:one|of(?:america|castile|oklahoma|thewest))|gor)|onlinebankofamerica|sbbt|(?:02|o2|pc)bancorp|b(?:bkonline|ok)|(af|bhf-|comfed|household|northfork|royal|stfrancis|tcf|us)bank|rb(?:c|sdigital)|ameritrade|citi(?:bank|businessonline|group|financial|zens(bank(online)?)?)?|skyfi|star|wamu|paypai|providian(?:services)?|f(?:lagstar|ult(on(bank|financialadvisors)?)?)|unionplanters|elizfed|regions(?:bank|net)?|cha(rterone|se)|lasalle(bank)?|nation(?:al-?city|et)|(?:capital|golden)(?:1|one)|cnb(?:wax)?|(?:(?:aa|cc)f|uofu)cu|w(?:achovia|ells-?fargo|f|esternunion)|e-gold|mastercard|visa|schwab|e(?:bay2|gg|passporte)|(?:columbusbankand|s(?:outh|un))trust|lloydstsb|hsbc(?:-us)?|mbna(?:netaccess)?|53|barclays|first(merit|tennessee)|ohiosavings|peoples|comerica|downey(?:savings)?|(?:machias?)savings|an(?:btx|z)|iblogin|(?:key|pnc|midamerica)(?:bank)?|gesa|fundsxpress|creditunion|amazon|dell|symantec)\.com|(?:mbna|paypal)\.us|(?:desjardins|bmo|cibc|canadianimperial|td(?:bank|canadatrust)?|scotiabank)\.(?:com|ca)|(?:paypal|ebay)\.ca|(?:ebay|hvb|vr-networld|(?:d(?:eutsche|resdner)-|post|volks|hypovereins)bank|sparkasse|paypal)\.de|abb-bvb\.be|sparkasse\.at|(ebay|fineco|sella)\.it|(?:(?:banc|grup)o)?santander\.(?:com\.(?:es|mx)|com|es)|banesto\.es|(enskilda|seb(ank)?)\.se|alpha\.gr|(?:alliance-leicester|ba(?:nkofscotland|rclays)|halifax(?:-online)?|hsbc|lloyds(?:tsb)?|nationwide|rbs|(?:co-operative|sainsburys)bank)\.co\.uk|standardbank\.co\.za|trademe\.co\.nz|(?:ebay|c(?:iti|omm)bank|national)\.com\.au|bradesco\.com\.br|(?:ncua|irs)\.gov|(?:a(?:mericaneagle|laskausa)|n(?:afcu(?:net)?|nleague)|redcross|mtnamerica|(?:(?:3rivers|ca|lacap|paragon|visions)f|(?:argonn|dupag|td)e|msg|nym|uofu)cu|un(icef)?)\.org)$/i
  372.  
  373. meta     FS_PHISH_VICTIM_MSGID __FS_PHISH_VICTIM_FROM && (MSGID_FROM_MTA_ID || MSGID_FROM_MTA_HEADER)
  374. describe FS_PHISH_VICTIM_MSGID Phish: From victim.tld but non-local Message-ID
  375. score     FS_PHISH_VICTIM_MSGID 9
  376.  
  377.  
  378.  
  379. # rule: FS_PHISH_VICTIM_DYNAMIC
  380. # added 2005-09-19
  381. # edit 2006-05-02: __FS_DYNAMIC_BAD filter, remove Nordea from victims
  382. # test: ######## TODO: provide sample
  383. # temp: phishing/1109596361.V802Ia7b10.localhost.localdomain
  384. # fail: ham-samples@fs/nordea-podrezov-2006-04-28/file.eml
  385.  
  386. meta     __FS_PHISH_DYNAMIC __RDNS_DYNAMIC_IP || ROUND_THE_WORLD || RCVD_NUMERIC_HELO || HELO_DYNAMIC_IPADDR
  387. meta    __FS_PHISH_DYNAMIC_GOOD    SPF_PASS || SPF_HELO_PASS
  388. meta    __FS_PHISH_DYNAMIC_BAD    __FS_PHISH_DYNAMIC && !__FS_PHISH_DYNAMIC_GOOD
  389.  
  390.  
  391.  
  392. meta     FS_PHISH_VICTIM_DYNAMIC __FS_PHISH_VICTIM_FROM_NONORDEA && __FS_PHISH_DYNAMIC_BAD
  393. describe FS_PHISH_VICTIM_DYNAMIC Phish: apparent dialup injection for Big Bank
  394. score     FS_PHISH_VICTIM_DYNAMIC 9
  395.  
  396.  
  397.  
  398.  
  399. # rule: FS_PHISH_VICTIM_FORGED
  400. # added 2005-09-20
  401. # edit 2005-12-20: __RATWARE meta rule: typo fix
  402. # edit 2006-10-18: remove RATWARE_ZERO_TZ from __RATWARE meta rule due to FPs
  403. # edit 2006-10-18: temporarily remove __DATE_IN_PAST from __RATWARE meta rule
  404. # edit 2006-10-26: disable 0-score dependent rules
  405. # edit 2006-10-26: fix obsolete name for FS_RATWARE_THEBAT_X15
  406. ######## TODO: maybe put back __DATE_IN_PAST eventually
  407. # test: ######## TODO: provide sample
  408. # temp: phishing/1102018179.V802Ia7aca.localhost.localdomain
  409. # fail: reference/ebay-era-2006-10-18_041.msg
  410.  
  411. # temp: /tmp/ph/00079.msg 80.msg (RATWARE_RCVD_PF && uri =~ /deutsche-bank.de/)
  412. # temp: /tmp/ph/00045.msg (FS_RATWARE_OPEN_PHP && VisionsFCU.org)
  413. # temp: /tmp/ph/00095.msg (FORGED_THEBAT_HTML && e-gold.com)
  414. # temp: /tmp/ph/00074.msg (FS_RATWARE_OPEN_PHP && wellsfargo.com)
  415. # temp: /tmp/ph/00020.msg (NORMAL_HHTP_TO_IP && ncua.gov)
  416.  
  417. meta __DATE_IN_FUTURE DATE_IN_FUTURE_03_06 || DATE_IN_FUTURE_06_12 || DATE_IN_FUTURE_12_24 || DATE_IN_FUTURE_24_48 || DATE_IN_FUTURE_48_96 || DATE_IN_FUTURE_96_XX
  418. meta __DATE_IN_PAST DATE_IN_PAST_03_06 || DATE_IN_PAST_06_12 || DATE_IN_PAST_12_24 || DATE_IN_PAST_24_48 || DATE_IN_PAST_48_96 || DATE_IN_PAST_96_XX
  419. meta __RATWARE RATWARE_EGROUPS || RATWARE_GECKO_BUILD || RATWARE_HASH_2 || RATWARE_HASH_2_V2 || RATWARE_JPFREE || RATWARE_MOZ_MALFORMED || RATWARE_NETIP || RATWARE_OE_MALFORMED || RATWARE_RCVD_AT || RATWARE_RCVD_LC_ESMTP || RATWARE_RCVD_PF || FS_RATWARE_FCC_XID || FS_RATWARE_MIME_PREAMBLE_SPACED_OUT || FS_RATWARE_THEBAT_X15 # || RATWARE_ZERO_TZ || RATWARE_HASH_DASH || RATWARE_STORM_URI
  420. meta __FORGED_RCVD FAKE_OUTBLAZE_RCVD || FORGED_AOL_RCVD || FORGED_EUDORAMAIL_RCVD || FORGED_GW05_RCVD || FORGED_HOTMAIL_RCVD2 || FORGED_HOTMAIL_RCVD || FORGED_JUNO_RCVD || FORGED_RCVD_HELO || FORGED_TELESP_RCVD || FORGED_YAHOO_RCVD || RCVD_AM_PM || RCVD_DOUBLE_IP_LOOSE || RCVD_DOUBLE_IP_SPAM || RCVD_FAKE_HELO_DOTCOM || RCVD_HELO_IP_MISMATCH || RCVD_ILLEGAL_IP || RCVD_NUMERIC_HELO # || RCVD_BONUS_SPC_DATE
  421. # RCVD_BY_IP
  422. meta __FORGED CONFIRMED_FORGED || FORGED_AOL_TAGS || FORGED_IMS_HTML || FORGED_IMS_TAGS || FORGED_MUA_AOL_FROM || FORGED_MUA_EUDORA || FORGED_MUA_IMS || FORGED_MUA_MOZILLA || FORGED_MUA_OIMO || FORGED_MUA_OUTLOOK || FORGED_MUA_THEBAT_BOUN || FORGED_MUA_THEBAT_CS || FORGED_OUTLOOK_HTML || FORGED_OUTLOOK_TAGS || FORGED_QUALCOMM_TAGS || FORGED_THEBAT_HTML || MULTI_FORGED
  423. ######## TODO: add FS_ forged rules here once they're in production
  424.  
  425. meta     FS_PHISH_VICTIM_FORGED __FS_PHISH_VICTIM_FROM && (__DATE_IN_FUTURE || __RATWARE || __FORGED_RCVD || __FORGED || FS_PHP_MAIL || FS_URL_IMAGE_DIR_NONIMAGE || FS_RATWARE_RECEIVED_IP_BIGINT) # (__DATE_IN_PAST ||
  426. describe FS_PHISH_VICTIM_FORGED Phish: Ostensibly From: phish victim; forged
  427. score     FS_PHISH_VICTIM_FORGED 5
  428.  
  429.  
  430.  
  431. # rule: FS_PHISH_VICTIM_BUGS
  432. # added 2005-09-20
  433. # edit 2006-10-26: replace 0-score dependent rules with __equivalents
  434. # test: ######## TODO: provide sample
  435. # temp: phishing/1102018179.V802Ia7aca.localhost.localdomain
  436. # temp: phishing-samples@fs/hermanni-2006-04-18/36
  437. # test: d-fence/virus-0TJiYpzmLasU.msg
  438.  
  439. # 20_html_tests.cf
  440. # HIDE_WIN_STATUS
  441. rawbody __HIDE_WIN_STATUS    /<[^>]+onMouseOver=[^>]+window\.status=/i
  442.  
  443. # 20_uri_tests.cf
  444. # WEIRD_PORT
  445. uri __WEIRD_PORT m{https?://[^/\s]+?:\d+(?<!:80)(?<!:443)(?<!:8080)(?:/|\s|$)}
  446.  
  447. meta __PHISHING_BUGS NUMERIC_HTTP_ADDR || NORMAL_HTTP_TO_IP || HTTP_ESCAPED_HOST || HTTP_CTRL_CHARS_HOST || HTTP_EXCESSIVE_ESCAPES || __WEIRD_PORT || HTTP_77 || __HIDE_WIN_STATUS || FS_MSGSTRUCT_HTML_NESTED_A_HREF || FS_HTML_JS_OBFU
  448. # URI_REDIRECTOR
  449.  
  450. meta     FS_PHISH_VICTIM_BUGS __FS_PHISH_VICTIM_FROM && __PHISHING_BUGS
  451. describe FS_PHISH_VICTIM_BUGS Phish: Ostensibly From: phish victim; web bug hit
  452. score     FS_PHISH_VICTIM_BUGS 9
  453.  
  454.  
  455.  
  456. # rule: FS_PHISH_VICTIM_IMAGE
  457. # added 2005-09-26
  458. # edit 2006-01-04: exclude amazon.com images
  459. # test: ######## TODO: provide sample
  460. # temp: /tmp/mau/00099.msg
  461. # fail: ham-samples@fs/m-muench-paypal-de-2006-09-04.msg
  462.  
  463. ######## NOTE: amazon excluded from regular expression
  464. uri __FS_PHISH_VICTIM_IMAGE m{^https?://(?:[^/.]+\.){0,2}?((paypal|ebay(?:rtm|static)?|ban(?:corpsouth(?:online)?|k(?:one|of(?:america|castile|oklahoma|thewest))|gor)|onlinebankofamerica|sbbt|(?:02|o2|pc)bancorp|b(?:bkonline|ok)|(af|bhf-|comfed|household|northfork|royal|stfrancis|tcf|us)bank|rb(?:c|sdigital)|ameritrade|citi(?:bank|businessonline|group|financial|zens(bank(online)?)?)?|skyfi|star|wamu|paypai|providian(?:services)?|f(?:lagstar|ult(on(bank|financialadvisors)?)?)|unionplanters|elizfed|regions(?:bank|net)?|cha(rterone|se)|lasalle(bank)?|nation(?:al-?city|et)|(?:capital|golden)(?:1|one)|cnb(?:wax)?|(?:(?:aa|cc)f|uofu)cu|w(?:achovia|ells-?fargo|f|esternunion)|e-gold|mastercard|visa|schwab|e(?:bay2|gg|passporte)|(?:columbusbankand|s(?:outh|un))trust|lloydstsb|hsbc(?:-us)?|mbna(?:netaccess)?|53|barclays|first(merit|tennessee)|ohiosavings|peoples|comerica|downey(?:savings)?|(?:machias?)savings|an(?:btx|z)|iblogin|(?:key|pnc|midamerica)(?:bank)?|gesa|fundsxpress|creditunion|dell|symantec)\.com|(?:mbna|paypal)\.us|(?:desjardins|bmo|cibc|canadianimperial|td(?:bank|canadatrust)?|scotiabank)\.(?:com|ca)|(?:paypal|ebay)\.ca|(?:ebay|hvb|vr-networld|(?:d(?:eutsche|resdner)-|post|volks|hypovereins)bank|sparkasse|paypal)\.de|abb-bvb\.be|sparkasse\.at|(ebay|fineco|sella)\.it|(?:(?:banc|grup)o)?santander\.(?:com\.(?:es|mx)|com|es)|banesto\.es|nordea\.(se|fi)|(enskilda|seb(ank)?)\.se|alpha\.gr|(?:alliance-leicester|ba(?:nkofscotland|rclays)|halifax(?:-online)?|hsbc|lloyds(?:tsb)?|nationwide|rbs|(?:co-operative|sainsburys)bank)\.co\.uk|standardbank\.co\.za|trademe\.co\.nz|(?:ebay|c(?:iti|omm)bank|national)\.com\.au|bradesco\.com\.br|(?:ncua|irs)\.gov|(?:a(?:mericaneagle|laskausa)|n(?:afcu(?:net)?|nleague)|redcross|mtnamerica|(?:(?:3rivers|ca|lacap|paragon|visions)f|(?:argonn|dupag|td)e|msg|nym|uofu)cu|un(icef)?)\.org)[/?&].*\.(?:jpe?g|gif|png)$}i
  465.  
  466. meta     FS_PHISH_VICTIM_IMAGE (! __FS_PHISH_VICTIM_FROM && __FS_PHISH_VICTIM_IMAGE)
  467. describe FS_PHISH_VICTIM_IMAGE Phish: Foreign sender uses image at victim site
  468. score     FS_PHISH_VICTIM_IMAGE 9
  469.  
  470.  
  471.  
  472. uri FS_PHISH_ALPHA_BANK /^https?:\/\/www\.(?:alphu\.com|alphe\.net|alphagr\.net)/i
  473. describe FS_PHISH_ALPHA_BANK Phish: Someone pretending to be alpha bank in Greece
  474. score FS_PHISH_ALPHA_BANK 9
  475.  
  476.  
  477. # Subject: VL: Nordea phishing-case - phishing www-palvelimien osoitteet
  478. # Date: Sat, 29 Oct 2005 13:09:02 +0300
  479.  
  480. uri FS_PHISH_NORDEA_FI m%^https?://(?:2(?:03\.94\.244\.173|10\.(?:83\.195\.195|90\.163\.11))|8(?:1\.(?:1(?:0\.143\.148|2\.(?:38\.13|5(?:0\.(?:14|8)|4\.254)|65\.35|8\.245))|4\.84\.66)|3\.(?:1(?:6\.(?:147\.42|47\.59|8\.138)|7\.26\.86)|2(?:16\.34\.18|2(?:3\.104\.48|7\.192\.48|8\.(?:10\.55|42\.58))))))[?:/]%i
  481. describe FS_PHISH_NORDEA_FI Phish: Someone pretending to be Nordea bank of Finland
  482. score FS_PHISH_NORDEA_FI 9
  483.  
  484. # Nordea phish mk II / mk III, 2005-12-09_02 2005-12-14_01
  485. # added 2005-12-09
  486. # edit 2005-12-14: Finnish-language variant URL, generalized
  487.  
  488. uri FS_PHISH_NORDEA_FI_TXT m%http://\d+\.\d+\.\d+\.\d+:8081//?nsp//?engine//?usecase=menu//?command=openmenu//?logon_topnavigation_view&fpid=[0-9A-Za-z]+&menuid=[0-9]+&hash=[0-9A-Za-z]+/%
  489. describe FS_PHISH_NORDEA_FI_TXT Phish: Someone pretending to be Nordea bank of Finland
  490. score FS_PHISH_NORDEA_FI_TXT 9
  491.  
  492. # rule: FS_PHISH_JHSBC_WMF
  493. # added 2006-01-19
  494. # WMF exploit site
  495. # See also weblog.f-secure.com / January 2006
  496.  
  497. uri     FS_PHISH_JHSBC_WMF m%^https?://(?:www\.)?jhsbc\.com(?:[/:]|$)%i
  498. describe FS_PHISH_JHSBC_WMF Phishing site with WMF exploit, reported Jan2006
  499. score     FS_PHISH_JHSBC_WMF 9
  500.  
  501. # rule: FS_PHISHING_TEST
  502. # added 2006-07-11
  503. # test: ######## TODO: provide sample
  504.  
  505. uri      FS_PHISH_TEST m%^https?://phishing.filter.test(?::80)?/general(?:$|/)%i
  506. describe FS_PHISH_TEST Phishing filter test
  507. score    FS_PHISH_TEST 7
  508.  
  509. ######## TODO: mibank.com / micorp.com (Marshall & Ilsley Bank) -- no SPF
  510. # http://anti-phishing.org/phishing_archive/04-27-05_M&I/04-27-05_M&I.html
  511. ######## TODO: associatedbank.com --
  512. # http://anti-phishing.org/phishing_archive/04-14-05_Associated/
  513. ######## TODO: comcast.com --
  514. # http://anti-phishing.org/phishing_archive/04-07-05_Comcast/
  515. ######## TODO: huntington.com --
  516. # http://anti-phishing.org/phishing_archive/03-30-05_Huntington/
  517. ######## TODO: pulse-eft.com --
  518. # http://anti-phishing.org/phishing_archive/03-22-05-Pulse/03-22-05-Pulse.html
  519. ######## TODO: e-bullion.com --
  520. # http://anti-phishing.org/phishing_archive/03-01-05_E-bullion/
  521.