SUCURILABS
SUCURILABS
BlogAbout us

Threat Insights 0x27: A Smuggler’s Tale

September 18, 2024

Smuggling credentials out

Email 1

  • Rating: ★★★☆☆
  • Date: 2024-09-18
  • Objective: Credential harvesting
  • Analyst: José Morim

This phishing email aims to masquerade as a sales contract that a client has supposedly requested. It pressures the recipient to make necessary corrections and verify all details prior to processing the payment, creating a sense of urgency to entice the recipient into opening the attached files.

Page 1

When opened, the HTML attachment builds a "Adobe Cloud Storage" credential harvesting form hosted on the recipient’s local machine. Entering a password and clicking “View” will send the login credentials to a third-party server controlled by bad actors.

Password expiration

Email 2

  • Rating: ★★☆☆☆
  • Date: 2024-09-19
  • Objective: Credential harvesting
  • Analyst: José Morim

This email deceptively claims to originate from the recipient's email service provider, urging them to click a link to prevent their mailbox from being deactivated within 48 hours due to an expired password.

Page 2

However, the link actually directs them to a phishing site aimed at stealing their credentials.

DocuSign impersonation

Email 3

  • Rating: ★★★☆☆
  • Date: 2024-09-21
  • Objective: Credential harvesting
  • Analyst: José Morim

This deceptive email is crafted to look like it’s from DocuSign, suggesting that the recipient has a document that is ready for their examination.

Page 3

However, clicking the "Preview Document" button leads them to a malicious site designed to harvest their login information.

IOCs

TYPEIOC
FILE15c45b0f142cb6cf415aeed88c8b74c0dfe796a6e9ac5da2528f46c77d4dc9ad
URLhxxps[://]online[.]advancements[.]best/communication[.]aspx
URLhxxps[://]ipfs[.]io/ipfs/bafkreih3s4d2n2b74vd6zmfvebu2w3rxvb4x7r7awqxte55sf47kzt446m
URLhxxps[://]a[.]edic[.]blog/wbb/pdfz[.]php

Keep up with threat insights

Threat Insights is a weekly series where we present you with analysis from samples we collect. Follow us on social media for the latest feed and cybersecurity content. Stay informed and stay safe!


Get more insights like this

  • Follow us on social media to get a weekly update of our latest content, and don't worry—we won't spam your feed ;)
  • Join our private beta and have a sneak peek at how your team will improve their security posture.


Copyright © 2024-2025 SUCURILABS Lda. All rights reserved.