TTPs: Impersonation of European law enforcement, fake government domains, cross-border SMS/iMessage ...
show moreTTPs: Impersonation of European law enforcement, fake government domains, cross-border SMS/iMessage delivery from Southeast Asia, and escalation threats.
IoCs: https://otx.alienvault.com/pulse/6a0c40
show less
The domain ashoo[.]buzz operates as a fraudulent impersonation site that copies and misuses the bran ...
show moreThe domain ashoo[.]buzz operates as a fraudulent impersonation site that copies and misuses the brand, name, and visual elements of the legitimate adult platform Ashoo. The site blocks direct access and only opens when the browserβs Referer header shows it was reached via Google or Yandex search results.
show less
The domain b[.]prostitutki24[.]su is operating as a fraudulent impersonation site that deliberately ...
show moreThe domain b[.]prostitutki24[.]su is operating as a fraudulent impersonation site that deliberately copies and misuses the brand, name, and elements of the legitimate adult entertainment platform Ashoo
https://otx.alienvault.com/pulse/69ea517a5f0bd47c01d88fd6
show less
The domain ashoo-znakomstva[.]ru hosted on this IP address is operating as a fraudulent impersonatio ...
show moreThe domain ashoo-znakomstva[.]ru hosted on this IP address is operating as a fraudulent impersonation site that deliberately copies and misuses the brand, name, and elements of the legitimate adult entertainment platform Ashoo. Threat Pulse on OTX: https://otx.alienvault.com/pulse/69e8e20bb9e91dec5330e3b4
show less
The domain ashoo-znakomstva[.]ru hosted on this IP address is operating as a fraudulent impersonatio ...
show moreThe domain ashoo-znakomstva[.]ru hosted on this IP address is operating as a fraudulent impersonation site that deliberately copies and misuses the brand, name, and elements of the legitimate adult entertainment platform Ashoo. Threat Pulse on OTX: https://otx.alienvault.com/pulse/69e8e20bb9e91dec5330e3b4
show less
The domain ashoomoskva.[]com on this IP address is operating as a fraudulent impersonation site that ...
show moreThe domain ashoomoskva.[]com on this IP address is operating as a fraudulent impersonation site that deliberately copies and misuses the brand, name, and elements of the legitimate adult entertainment platform Ashoo.
Threat Pulse on OTX: https://otx.alienvault.com/pulse/69e26f6cb2397ab9987a36f5
show less
Specified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting ...
show moreSpecified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting individuals in the Baltics. The threat actor is using the same exact payload as UNC6748, except for a different C2 endpoint (presumably because the old one is already present in threat intelligence feeds).
https://otx.alienvault.com/pulse/69c5ad2cc15ddbc70c30c4fe
show less
Specified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting ...
show moreSpecified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting individuals in the Baltics. The threat actor is using the same exact payload as UNC6748, except for a different C2 endpoint (presumably because the old one is already present in threat intelligence feeds).
https://otx.alienvault.com/pulse/69c5ad2cc15ddbc70c30c4fe
show less
Specified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting ...
show moreSpecified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting individuals in the Baltics. The threat actor is using the same exact payload as UNC6748, except for a different C2 endpoint (presumably because the old one is already present in threat intelligence feeds).
https://otx.alienvault.com/pulse/69c5ad2cc15ddbc70c30c4fe
show less
Specified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting ...
show moreSpecified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting individuals in the Baltics. The threat actor is using the same exact payload as UNC6748, except for a different C2 endpoint (presumably because the old one is already present in threat intelligence feeds).
https://otx.alienvault.com/pulse/69c5ad2cc15ddbc70c30c4fe
show less
Specified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting ...
show moreSpecified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting individuals in the Baltics. The threat actor is using the same exact payload as UNC6748, except for a different C2 endpoint (presumably because the old one is already present in threat intelligence feeds).
https://otx.alienvault.com/pulse/69c5ad2cc15ddbc70c30c4fe
show less
Listed as DNS record for domain 1ashooo[.]com β phishing website impersonating authentic Ashoo adult ...
show moreListed as DNS record for domain 1ashooo[.]com β phishing website impersonating authentic Ashoo adult entertainment platform.
show less
Listed as DNS record for domain 1ashooo[.]com β phishing website impersonating authentic Ashoo adult ...
show moreListed as DNS record for domain 1ashooo[.]com β phishing website impersonating authentic Ashoo adult entertainment platform.
show less
Listed as DNS record for domain 1ashooo[.]com β phishing website impersonating authentic Ashoo adult ...
show moreListed as DNS record for domain 1ashooo[.]com β phishing website impersonating authentic Ashoo adult entertainment platform.
show less
Listed as DNS record for domain 1ashooo[.]com β phishing website impersonating authentic Ashoo adult ...
show moreListed as DNS record for domain 1ashooo[.]com β phishing website impersonating authentic Ashoo adult entertainment platform.
show less
Listed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo ad ...
show moreListed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo adult entertainment platform.
show less
Listed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo ad ...
show moreListed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo adult entertainment platform.
show less
Listed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo ad ...
show moreListed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo adult entertainment platform.
show less
Listed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo ad ...
show moreListed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo adult entertainment platform.
show less
Listed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo ad ...
show moreListed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo adult entertainment platform.
show less
Listed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo ad ...
show moreListed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo adult entertainment platform.
show less
Listed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo ad ...
show moreListed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo adult entertainment platform.
show less
Listed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo ad ...
show moreListed as DNS record for domain ashoodubai[.]com β phishing website impersonating authentic Ashoo adult entertainment platform.
show less
Phishing
By clicking βAccept allβ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.