SUCURILABS
SUCURILABS
BlogAbout us

Threat insights 0x1E: Credential harvesting

July 23, 2024

WeTransfer Impersonation

Logistics sent you the shipping documents

Email 1

  • Rating: ★★☆☆☆
  • Date: 2024-07-18
  • Objective: Credential harvesting
  • Analyst: José Morim

This email claims that some shipping documents were sent to the recipient via WeTransfer which is a popular file sharing service. In reality the link leads the victim to a malicious website with the objective of harvesting their credentials: Page 1 The threat actor claims that the documents will expire on the 24th of July, and this is intended to create a sense of urgency in the recipient to have them click on the various malicious links.

YOU RECEIVED A FILE FROM A CONTACT

Email 3

  • Rating: ★★★☆☆
  • Date: 2024-07-17
  • Objective: Credential harvesting
  • Analyst: José Morim

This email impersonates WeTransfer and claims that some files were shared with the recipient. It also states that the files will be deleted on April 29th, which is odd considering today is July 18th. Regardless, this was an attempt to create a sense of urgency to prompt the recipient to open the malicious link. Page 3 Upon opening the victim is served with a credential harvesting page.

IT Impersonation

Server victimdomain[.]com - Password recovery

Email 2

  • Rating: ★★☆☆☆
  • Date: 2024-07-17
  • Objective: Credential harvesting
  • Analyst: José Morim

This email is claiming to be from the IT administrator that manages the victim email services. The threat actor says that the victim credentials are expired and the email server will log them off and create new credentials in the next 24 hours, giving the victim a sense of urgency to click the button "Manter senha atual" so they can maintain their current credentials: Page 2 By clicking the button the victim is lured into a malicious website with the objective of stealing the users credentials.

IOCs

TYPEIOC
URLhxxps[://]ipfs[.]io/ipfs/QmUa3nCp4R4SqbGBFhGvW6pqoEViwFPtnhaa28EAX9thtv
DOMAINpub-25902d32074b459eb837a12ad320b79e.r2.dev
DOMAIN0i00045i0.cc
DOMAINsudsy-flannel-don.glitch.me

Keep up with threat insights

Threat insights is a weekly series were we present you with analysis from samples we collect. Follow us on social media for the latest feed and cybersecurity content. Stay informed and stay safe!


Get more insights like this
  • Follow us on social media to get a weekly update of our latest content.
  • Join our private beta and have a sneak peak of how your team will improve on their security posture.


Copyright © 2024-2025 SUCURILABS Lda. All rights reserved.