Phishing email, which lures the user to download an Adobe Updater .js file. This script then downloa ...
show morePhishing email, which lures the user to download an Adobe Updater .js file. This script then downloads other files, and communicates with https://reporter9128.s3.us-east-1.amazonaws.com/base46.txt to extract and execute a b64 encoded batch script, which then executes a nasa.exe file on the target.
show less
One of our users received a phishing email from this domain ([email protected]).
The campai ...
show moreOne of our users received a phishing email from this domain ([email protected]).
The campaign leveraged a Cisco's SEG address, which would forward users to https://ct44648218iv5n2pzz4qublvko83bymu3v6fq5yjrck[.]grubmarkets[.]com
IoCs:
- 23[.]227[.]38[.]32
- 64[.]29[.]17[.]65
- 216[.]198[.]79[.]1
- ct44648218iv5n2pzz4qublvko83bymu3v6fq5yjrck[.]grubmarkets[.]com
- dedicatedaudio[.]com
show less
PhishingEmail Spam
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.