July 27, 2024
This email claims that the user has a due invoice. The goal is to get the recipient, unaware of what service does the invoice belong, to open a PDF document attached to the email:
The malicious actors trick the recipient to click on a link embedded in the PDF which sends the victim to a credential harvesting website.
This email is claiming to be from the recipient email service provider. It falsely claims impending account suspension due to suspicious activity and urges the recipient to login to their email by clicking on the "Verify your identity" button:
By clicking the button the victim is lured into a malicious website with the objective of stealing their credentials.
This email pretends to be a shared document notification informing the recipient about a shared file. There is no file name but instead the recipient is informed that is a secure and encrypted file, in order to arouse curiosity and trick the user into clicking the "View Your Message" button.
After they click the button, the user is served a credential harvesting page.
TYPE | IOC |
---|---|
FILE | fbfe3db50d4ae40307b66007715f3507f929dc4b7ea65583366313bb79d79f29 |
URL | hxxps[://]g3o9[.]short[.]gy/ct7TBn |
DOMAIN | pub-b148b1b4b9304dbd80461a366cda853c[.]r2[.]dev |
URL | hxxps[://]t[.]co/R6uQ3sOuOq |
URL | hxxps[://]sl[.]tij1111[.]za[.]com/[.]ex/index[.]html |
Threat insights is a weekly series were we present you with analysis from samples we collect. Follow us on social media for the latest feed and cybersecurity content. Stay informed and stay safe!