This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.
Infoblox Threat Intel
@InfobloxThreatIntel@infosec.exchange
infosec.exchange
Season's Scammings 🔅 🎄
We've been tracking a cluster of personal loan phishing sites that work hard to look like independent lenders — different brands, different domains, even deliberately varied infrastructure.
Look closely enough, though, and the seams show. Similar underlying templates. The same technology stack. And passive DNS tying their thousands of domains back to the same operator.
The sites present as loan applications. Name, address, employment details, financial history. And then, at the final step: your Social Security Number. No real company name. No regulatory disclosure. Just a form — and your most sensitive personal data sent off to who-knows-where for who-knows-what.
A significant portion of the domains are seasonal — Christmas cash, Thanksgiving funds, Black Friday loans. Financially stretched consumers, at exactly the moment they're most likely to reach for a quick fix.
⛔ mychristmaswallet[.]com
⛔ cashzillaloans[.]com
⛔ personalreliefwallet[.]com
⛔ thanksgivingcash-5k[.]com
⛔ christmascashhelp-direct[.]com
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #scam
Possible Phishing 🎣
on: ⚠️hxxps[:]//chatgpt0005[.]eu[.]org/blog/making-it-easier-than-ever-to-connect-with-friends-in-league-val
🧬 Analysis at: https://urldna.io/scan/6a7ac88c3b775000064d253a
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//whitepanda[.]info/48-1466-160526/?u=83C1466&e=renusz@c357e509cebb57753e2d4e8dba34fee948a7[.]net&s3=&s4=&s5=&s6=&s7=&s8=
🧬 Analysis at: https://urldna.io/scan/6a794ccf3b775000083c3f99
#cybersecurity #phishing #infosec #urldna #scam #infosec
🤖 Valve notifies Steam hardware customers in Europe after breach at shipping partner CEVA Logistics. Attackers accessed CEVA servers July 29-Aug 1, taking names, addresses, phones, emails and order details. No payment or Steam account data exposed; phishing risk remains.
🔗 https://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/
#DataBreach #InfoSec #Phishing
Possible Phishing 🎣
on: ⚠️hxxps[:]//hsbc[.]dev
🧬 Analysis at: https://urldna.io/scan/6a78f8903b775000083c379b
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxp[:]//hassank10[.]github[.]io/Apple-Clone
🧬 Analysis at: https://urldna.io/scan/6a7954823b775000083c4054
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//losospl[.]github[.]io/
🧬 Analysis at: https://urldna.io/scan/6a78ce583b775000083c3385
#cybersecurity #phishing #infosec #urldna #scam #infosec
Daily CyberSecurity
@DailyCyberSecurity@infosec.exchange
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
infosec.exchange
Researchers expose the Greatness PhaaS platform, an AiTM phishing kit sold on Telegram that steals Microsoft 365 tokens past MFA.
#Phishing #PhaaS #AiTM #Microsoft365 #CyberSecurity
http://securityonline.info/greatness-phaas-aitm-phishing/?utm_source=mastodon&utm_medium=jetpack_social
Possible Phishing 🎣
on: ⚠️hxxps[:]//mnbu-9gjwu07k13q4[.]s3[.]dualstack[.]us-east-1[.]amazonaws[.]com/index[.]html
🧬 Analysis at: https://urldna.io/scan/6a78d61c3b775000083c3439
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//gmxupgradesection[.]weebly[.]com/
🧬 Analysis at: https://urldna.io/scan/6a7888083b77500008a372eb
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxp[:]//japi-trust[.]github[.]io/Apple-Boostrap-Clone-Master
🧬 Analysis at: https://urldna.io/scan/6a7857923b77500008a36ea5
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//secure-meta-business[.]start[.]page/
🧬 Analysis at: https://urldna.io/scan/6a77cad33b77500008a3611a
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//unitedreflections[.]com
🧬 Analysis at: https://urldna.io/scan/6a78259e3b77500008a369fe
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//dwb097[.]webwave[.]dev
🧬 Analysis at: https://urldna.io/scan/6a781f2c3b7750000217898b
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//meta-verify-accounts[.]start[.]page
🧬 Analysis at: https://urldna.io/scan/6a7825793b77500008a369b9
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//appengine[.]google[.]com[.]drive[.]pratham[.]vincacybertechltd[.]myshn[.]net
🧬 Analysis at: https://urldna.io/scan/6a778ae03b77500008a35af9
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//987854916892426775[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a78113a3b77500008a367d0
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//bexmb23[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a78176a3b77500008a36825
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//cloud-233f9[.]firebaseapp[.]com
🧬 Analysis at: https://urldna.io/scan/6a7752943b775000088f9da2
#cybersecurity #phishing #infosec #urldna #scam #infosec
Possible Phishing 🎣
on: ⚠️hxxps[:]//shawdonotreply[.]weebly[.]com
🧬 Analysis at: https://urldna.io/scan/6a774c473b77500002263087
#cybersecurity #phishing #infosec #urldna #scam #infosec