Posts: 1,729
Threads: 665
Joined: Sep 2022
Reputation:
127
Obavešten sam da se phishing kampanje sa brendom Pošte Srbije i dalju kreću Viberom. Domen vaxvjhjxd.cyou je kupljen preko registra u Kini (2022-07-25), a nalazi se iza CloudFlare.
Attached Files
Image(s)
“If you think you are too small to make a difference, try sleeping with a mosquito.” - Dalai Lama XIV
Posts: 1,729
Threads: 665
Joined: Sep 2022
Reputation:
127
Još jedan primer:
Attached Files
Image(s)
“If you think you are too small to make a difference, try sleeping with a mosquito.” - Dalai Lama XIV
Posts: 1,729
Threads: 665
Joined: Sep 2022
Reputation:
127
Jedan od linkova je w[.]circulationirritate[.]cn/1975fnFcdX9RRVhKe2lmAxNgdAl-LkAMUyIIXnEDP1wtDwkdUzYiPzgpPgFuQAE2TB4VCRFUEhhyGRZ5PAJLPg1GBEgLbzs&p=mnnzvb (izvor:
https://twitter.com/jetmi787/status/1613279211938107397 , arhivirano:
https://archive.ph/dSCJI ). Međutim izgleda da radi samo jednom. Stranica ima nagradna pitanja kao u u prošlim sličnim napadima (
https://bezbedanbalkan.net/thread-299.html ).
Verovatno stranica na kraju opet vodi na neku SMS (VAS) prevaru ili na preuzimanje malicioznog koda.
Izvorni kod ima Google Analytics skript i HTML komentare na kineskom jeziku.
U prilogu je HTML stranice u BASE64 formatu jer antivirusi markiraju ovu stranica kao SCAM.
Attached Files
Image(s)
Posta_Viber_Phishing_Base64_HTML.txt (Size: 158.14 KB / Downloads: 279)
“If you think you are too small to make a difference, try sleeping with a mosquito.” - Dalai Lama XIV