Skip to content

Update FlowerStormPaaS.csv#9

Open
Abdelrahman671 wants to merge 1 commit intosophoslabs:masterfrom
Abdelrahman671:new_ioc
Open

Update FlowerStormPaaS.csv#9
Abdelrahman671 wants to merge 1 commit intosophoslabs:masterfrom
Abdelrahman671:new_ioc

Conversation

@Abdelrahman671
Copy link

New C2 server has been discovered in a phishing campaign targeting an organization in Egypt.
The C2 server is undetected over virustotal and other cti platforms.
The phishing website used microlink service to capture a screenshot from the background of a legitmate website.
The phishing website used debugging/obfuscation techniques to complicate the analysis.
The phishing website used a custom javascript file to display the page based on the user language.
The phishing website related to FlowerStorm phishing as a service platform.
Related indicators:

  • hxxp://uq1xslfi7a[.]pages[.]dev/bqxrfiyo?ndbgrrclvp=

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant