The IP performed Brute-Force/Credential Stuffing attacks against VPN services. After gaining unautho ...
show moreThe IP performed Brute-Force/Credential Stuffing attacks against VPN services. After gaining unauthorized access, the attacker established a persistent tunnel, performed lateral movement scanning for internal servers and exfiltrated data.
show less
Source of a targeted phishing campaign delivering a multi-stage VBS loader malware. The attack vecto ...
show moreSource of a targeted phishing campaign delivering a multi-stage VBS loader malware. The attack vector involves a malicious link pointing to a ZIP file containing a script ("gsanb.vbs"). Upon execution, the script utilizes LOLBins (wscript, cmd, powershell, expand) to drop and execute a secondary credential stealer payload ("cinzabombeiro.exe"). Confirmed malicious behavior via sandbox analysis including evasion techniques and C2 communication.
show less
Source of a targeted phishing campaign delivering a multi-stage VBS loader malware. The attack vecto ...
show moreSource of a targeted phishing campaign delivering a multi-stage VBS loader malware. The attack vector involves a malicious link pointing to a ZIP file containing a script ("gsanb.vbs"). Upon execution, the script utilizes LOLBins (wscript, cmd, powershell, expand) to drop and execute a secondary credential stealer payload ("cinzabombeiro.exe"). Confirmed malicious behavior via sandbox analysis including evasion techniques and C2 communication.
show less
Source of a targeted phishing campaign delivering a multi-stage VBS loader malware. The attack vecto ...
show moreSource of a targeted phishing campaign delivering a multi-stage VBS loader malware. The attack vector involves a malicious link pointing to a ZIP file containing a script ("gsanb.vbs"). Upon execution, the script utilizes LOLBins (wscript, cmd, powershell, expand) to drop and execute a secondary credential stealer payload ("cinzabombeiro.exe"). Confirmed malicious behavior via sandbox analysis including evasion techniques and C2 communication.
show less
Source of a targeted phishing campaign delivering a multi-stage VBS loader malware. The attack vecto ...
show moreSource of a targeted phishing campaign delivering a multi-stage VBS loader malware. The attack vector involves a malicious link pointing to a ZIP file containing a script ("gsanb.vbs"). Upon execution, the script utilizes LOLBins (wscript, cmd, powershell, expand) to drop and execute a secondary credential stealer payload ("cinzabombeiro.exe"). Confirmed malicious behavior via sandbox analysis including evasion techniques and C2 communication.
show less
Source of a targeted phishing campaign delivering a multi-stage VBS loader malware. The attack vecto ...
show moreSource of a targeted phishing campaign delivering a multi-stage VBS loader malware. The attack vector involves a malicious link pointing to a ZIP file containing a script ("gsanb.vbs"). Upon execution, the script utilizes LOLBins (wscript, cmd, powershell, expand) to drop and execute a secondary credential stealer payload ("cinzabombeiro.exe"). Confirmed malicious behavior via sandbox analysis including evasion techniques and C2 communication.
show less
PhishingEmail SpamHackingSpoofing
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.