Phishing attack against Facebook users

This morning Matrix located a file containing Facebook user credentials stolen using a phishing attack. The malicious site is "ab-portalwiedza.xyz". 16 hours after the report of the attack, the site is still online even if the file containing the credentials is no longer visible, I imagine because the criminal changed its name. The site presents … Continue reading Phishing attack against Facebook users

Intesa San Paolo phishing kit

A few hours ago Matrix identified a phishing kit targeting customers of the Italian bank Intesa San Paolo (intesasanpaolo[.]com). This site is hosted on cprapid[.]com, the full url is weblntesasanpaolo[.]35-180-129-166[.]cprapid[.]com. I just report it as malicious on urlscan.io. The kit code is a mess 😦 I don't think the low quality indicates attempts at evasion, … Continue reading Intesa San Paolo phishing kit

Attack against Zoom

Today I'll tell you about an attack detected a few hours ago by Matrix and reported on urlscan.io. This is a fairly complex attack against Zoom. The attackers registered on Namecheap a domain (us06webzoomus[.]pro) reminiscent of Zoom subdomains and deployed a series of files. Here we find three malware (Android and Windows), static content (scripts, … Continue reading Attack against Zoom

Free RAT

A little while ago I came across this website: hxxps://domin-remote[.]online The domain was registered yesterday via hostinger. To date it has not been reported. Matrix reported it on urlscan.io 15 hours ago. Domain Name: DOMIN-REMOTE.ONLINERegistry Domain ID: D424887618-CNICRegistrar WHOIS Server: whois.hostinger.comRegistrar URL: https://www.hostinger.com/Updated Date: 2024-01-15T10:57:55.0ZCreation Date: 2024-01-15T10:57:50.0ZRegistry Expiry Date: 2025-01-15T23:59:59.0ZRegistrar: HOSTINGER operations, UABRegistrar IANA ID: … Continue reading Free RAT