Emails Impersonating Shipping Companies Distributed as 'Guide on Submitting Import Clearance Info' - ASEC BLOG
Tags
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Credentials - T1589.001 Malware - T1587.001 Malware - T1588.001 Phishing - T1660 Phishing - T1566 Server - T1583.004 Server - T1584.004 |
Common Information
Type | Value |
---|---|
UUID | 97e18d59-5176-4012-87cf-bd029b1d0c3e |
Fingerprint | 2e9b9d399bb76e0f |
Analysis status | DONE |
Considered CTI value | -2 |
Text language | |
Published | Feb. 24, 2023, 7:59 a.m. |
Added to db | Feb. 24, 2023, 1:21 a.m. |
Last updated | Sept. 4, 2024, 9:13 p.m. |
Headline | Emails Impersonating Shipping Companies Distributed as ‘Guide on Submitting Import Clearance Info’ |
Title | Emails Impersonating Shipping Companies Distributed as 'Guide on Submitting Import Clearance Info' - ASEC BLOG |
Detected Hints/Tags/Attributes | 20/2/9 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://asec.ahnlab.com/en/48304/ |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 17 | ✔ | ASEC | https://asec.ahnlab.com/en/feed/ | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 6 | lucent-fittings.000webhostapp.com |
|
Details | File | 6 | action.php |
|
Details | File | 6 | pdf.gz |
|
Details | md5 | 2 | c2b8db7362020b321870e649b05f12fb |
|
Details | md5 | 2 | e49967b8d499bb593cf44026aa79871b |
|
Details | md5 | 2 | 7739ebe59ba934f4887d70e4a4d31d6a |
|
Details | IPv4 | 2 | 31.42.184.26 |
|
Details | Url | 2 | https://lucent-fittings.000webhostapp.com/action.php |
|
Details | Url | 2 | http://31.42.184.26/pdf.gz |