Searching for something else I found a notification for a malware detected months ago, the thing that struck me was the name of the file: FixInternet.exe The first thought was this:
Category: Security
How to use a Telegram token
In the following article I talk about some approaches to mitigate the damage from a criminal attack. I am not sure if what I am talking about is legal in all countries, so do your research first. Or use a VPS in Russia π Telegram is one of the main tools used by criminals to … Continue reading How to use a Telegram token
Phishing using SVG
Today I found an email with an SVG attachment in my secondary email account. The account is Office 365 and the email was not in spam, this is not good, especially considering how much 365 costs! Anyway, back to the email, it was clearly suspicious also considering the attachment, an svg file with the name … Continue reading Phishing using SVG
Artea and ING phishing kit
Yesterday I came back from a weekend in Latvia and now I have come across an attack on Artea, a Lithuanian bankβ¦ The Baltics are calling me π Matrix has identified a series of patterns that have allowed them to quickly identify the various domains involved: banklithuanial.net lithuaniabankasl.net arteasite-login.net arteabankslogin.net italyingbank.net One of the sites … Continue reading Artea and ING phishing kit
Correios phishing kit
In the last few weeks I have noticed that attacks on Correios are constant. I have studied the matter a bit: it is the Brazilian state company that manages shipments and payments related to them. The scam is always the same, attackers write to users saying that a shipment is blocked and that a small … Continue reading Correios phishing kit
Business breakfast with fraud
Looking at what ends up in the Matrix network I noticed a kit that targets Kraken customers. As usual, the victim is frightened with an alleged compromise of their account. The interesting aspect of this kit is that instead of asking the victim to enter their wallet details, the application suggests the victim to schedule … Continue reading Business breakfast with fraud
Why aren’t criminals’ email accounts closed?
Free time is less and less, nevertheless I try to dedicate at least a couple of hours every week to the analysis of the Matrix evidence. I dedicate some time to the analysis of phishing kits and to the sharing of the email and Telegram token indicators on my public ioc repo: https://github.com/ecarlesi/ioc.git From this … Continue reading Why aren’t criminals’ email accounts closed?
Phishing against Kraken
At the end of a pretty busy day, I finally found a few minutes to check out the incoming notifications from Matrix. I noticed a kit that targets Kraken customers because their icon reminds me of the ghost from Pacman, and just today I got the vintage Pacman console π The domain used for the … Continue reading Phishing against Kraken
Attack against Correios
This morning I came across a kit aimed at Brazilian taxpayers. The domain used for the attack is consultarencomeda[.]online The attack is currently in its initial phase, the domain was registered a few hours ago and the kit was copied to the hosting. Matrix intercepted these two activities, analyzed the archive containing the kit and … Continue reading Attack against Correios
An update on the Matrix project
Since Matrix has had its own blog for some time now, I'll just post the reference here. In this article I'll tell you about my experience with Elasticsearch and how one of its instances became part of Matrix. https://matrixproject.info/2024/12/14/lucene-has-finally-arrived-thanks-to-elastricsearch/









You must be logged in to post a comment.