id: visual-studio-code-phish info: name: visual studio code phishing Detection author: rxerium severity: info description: | A visual studio code phishing website was detected reference: - https://visualstudio.com metadata: max-request: 1 tags: phishing,visual-studio-code,osint http: - method: GET path: - "{{BaseURL}}" host-redirects: true max-redirects: 2 matchers-condition: and matchers: - type: word words: - 'Visual Studio Code is a code editor redefined and optimized for building and debugging modern web and cloud applications. Visual Studio Code is free and available on your favorite platform - Linux, macOS, and Windows.' - 'Visual Studio Code - Code Editing. Redefined' condition: and - type: status status: - 200 - type: dsl dsl: - '!contains(host,"visualstudio.com")' # digest: 4a0a0047304502206389952a04cb771a897707a90dffb5230a152cb8163a5ba113cc264ea3101236022100ba78e42764b7359f8f2863f798099f1d42a60ce03fe366ef04d6825fef885968:922c64590222798bb761d5b6d8e72950