Pošta phishing via Viber
#1
Obavešten sam da se phishing kampanje sa brendom Pošte Srbije i dalju kreću Viberom. Domen vaxvjhjxd.cyou je kupljen preko registra u Kini (2022-07-25), a nalazi se iza CloudFlare.

[Image: attachment.php?aid=428]


Attached Files Image(s)
   
“If you think you are too small to make a difference, try sleeping with a mosquito.” - Dalai Lama XIV
Reply
#2
Još jedan primer:

[Image: attachment.php?aid=431]


Attached Files Image(s)
   
“If you think you are too small to make a difference, try sleeping with a mosquito.” - Dalai Lama XIV
Reply
#3
Jedan od linkova je w[.]circulationirritate[.]cn/1975fnFcdX9RRVhKe2lmAxNgdAl-LkAMUyIIXnEDP1wtDwkdUzYiPzgpPgFuQAE2TB4VCRFUEhhyGRZ5PAJLPg1GBEgLbzs&p=mnnzvb (izvor: https://twitter.com/jetmi787/status/1613279211938107397, arhivirano: https://archive.ph/dSCJI). Međutim izgleda da radi samo jednom. Stranica ima nagradna pitanja kao u u prošlim sličnim napadima (https://bezbedanbalkan.net/thread-299.html).

Verovatno stranica na kraju opet vodi na neku SMS (VAS) prevaru ili na preuzimanje malicioznog koda.

Izvorni kod ima Google Analytics skript i HTML komentare na kineskom jeziku.

U prilogu je HTML stranice u BASE64 formatu jer antivirusi markiraju ovu stranica kao SCAM.

[Image: attachment.php?aid=433]


Attached Files Image(s)
   

.txt   Posta_Viber_Phishing_Base64_HTML.txt (Size: 158.14 KB / Downloads: 115)
“If you think you are too small to make a difference, try sleeping with a mosquito.” - Dalai Lama XIV
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)