Cisco.Smart.Install.Feature.Enable.Scanner
This IP address has been observed in the wild attempti ...
show moreCisco.Smart.Install.Feature.Enable.Scanner
This IP address has been observed in the wild attempting to exploit CVE-2018-0171
CVE-2018-0171 is a remote code execution vulnerability in Cisco IOS and IOS XE Software, specifically in the Smart Install client feature. An unauthenticated, remote attacker can send crafted Smart Install messages to trigger a buffer overflow, allowing them to execute arbitrary code or cause a denial of service (DoS) on vulnerable devices.
Further information available here:
https://nvd.nist.gov/vuln/detail/CVE-2018-0171
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2
https://www.tenable.com/blog/proof-of-concept-and-patch-for-critical-cisco-ios-vulnerability-cve-2018-0171
IP addresses involved in this activity:
198.58.109.179
165.22.141.51
show less
Cisco.Smart.Install.Feature.Enable.Scanner
This IP address has been observed in the wild attempti ...
show moreCisco.Smart.Install.Feature.Enable.Scanner
This IP address has been observed in the wild attempting to exploit CVE-2018-0171
CVE-2018-0171 is a remote code execution vulnerability in Cisco IOS and IOS XE Software, specifically in the Smart Install client feature. An unauthenticated, remote attacker can send crafted Smart Install messages to trigger a buffer overflow, allowing them to execute arbitrary code or cause a denial of service (DoS) on vulnerable devices.
Further information available here:
https://nvd.nist.gov/vuln/detail/CVE-2018-0171
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180328-smi2
https://www.tenable.com/blog/proof-of-concept-and-patch-for-critical-cisco-ios-vulnerability-cve-2018-0171
IP addresses involved in this activity:
198.58.109.179
show less
This IP address is involved in a mass sextortion scam leveraging intimidation and fake spyware claim ...
show moreThis IP address is involved in a mass sextortion scam leveraging intimidation and fake spyware claims to coerce Bitcoin payment. No evidence suggests compromise; all technical “proof” is fabricated. The campaign infrastructure (ColoCrossing VPS, spoofed mail.com, BTC wallet) indicates low sophistication but broad targeting. Immediate mitigation is through IOC blocklisting and user awareness training.
show less
Cyber Intelligence Assessment – spotmat.com & tapisio.com:
Both domains lack ties to legitimate bus ...
show moreCyber Intelligence Assessment – spotmat.com & tapisio.com:
Both domains lack ties to legitimate businesses and were likely registered as disposable assets using privacy protection and short terms. They passed SPF, DKIM, and DMARC, indicating setup by actors skilled in email evasion. Email content mimicked “LogoMats Ireland,” leveraging brand impersonation to build trust. TTPs include mass phishing followed by pivoting victims to queenmats.com for fraud escalation. Clean infrastructure hygiene, multi-stage lures, and centralised email control suggest a financially motivated, low–mid sophistication group capable of deploying multiple domains, configuring authentication, and executing staged impersonation. Defences: blocklist domains/IPs, monitor anomalous replies, track similar brand-stem registrations.
show less
Cyber Intelligence Assessment – spotmat.com & tapisio.com:
Both domains lack ties to legitimate bus ...
show moreCyber Intelligence Assessment – spotmat.com & tapisio.com:
Both domains lack ties to legitimate businesses and were likely registered as disposable assets using privacy protection and short terms. They passed SPF, DKIM, and DMARC, indicating setup by actors skilled in email evasion. Email content mimicked “LogoMats Ireland,” leveraging brand impersonation to build trust. TTPs include mass phishing followed by pivoting victims to queenmats.com for fraud escalation. Clean infrastructure hygiene, multi-stage lures, and centralised email control suggest a financially motivated, low–mid sophistication group capable of deploying multiple domains, configuring authentication, and executing staged impersonation. Defences: blocklist domains/IPs, monitor anomalous replies, track similar brand-stem registrations.
show less
Spam email - Initial contact to confirm email address is alive for potentially further attacks down ...
show moreSpam email - Initial contact to confirm email address is alive for potentially further attacks down the line.
This message is part of a synchronized multi-domain phishing or BEC-style campaign. By using multiple unrelated domains (e.g., vintagelacephotography.com and gaosuji.com) with identical subjects, the adversary increases the likelihood that at least one message will bypass filters. SPF, DKIM, and DMARC passes help the emails appear authentic, while vague subject/content (“LogoMat - IE”) is designed to trigger recipient curiosity and elicit a reply, setting the stage for malicious follow-up. The sending IP is from a low-trust hosting range often used for spam operations.
show less
Spam email - Initial contact to confirm email address is active - Potentially used for initial conta ...
show moreSpam email - Initial contact to confirm email address is active - Potentially used for initial contact for follow up attacks.
This message is part of a synchronized multi-domain phishing or BEC-style campaign. By using multiple unrelated domains (e.g., vintagelacephotography.com and gaosuji.com) with identical subjects, the adversary increases the likelihood that at least one message will bypass filters. SPF, DKIM, and DMARC passes help the emails appear authentic, while vague subject/content (“LogoMat - IE”) is designed to trigger recipient curiosity and elicit a reply, setting the stage for malicious follow-up. The sending IP is from a low-trust hosting range often used for spam operations
show less
Fraud OrdersPhishingSpoofing
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.