[go: nahoru, domu]

Skip to content

Latest commit

 

History

History

PTI-252

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 

PTI-252 Group Indicators of Compromise (IOC)

These IOCs were released as part of PTI team research.

PTI-252 consists of an interactive phishing panel with fake DHL payment pages that allows the attacker to interact with the victim by manually redirecting the victim to a fake credit card payment page and verification code page. After the victim enters credit card information, attackers can show the victim fake payment error codes to force the victim to enter other card information.

Having received the victim's credit card details, the attackers use them to withdraw funds, and the victim gets a notification on their phone device with a verification code. Using the panel, threat actors redirect the victim to a fake payment confirmation page, forcing the victim to submit a confirmation code. All information, including credit card details, confirmation codes and the victim's IP address, are displayed in the panel.

If the victim cannot use a credit card, the attackers redirect the victim to a fake cryptocurrency payment page. On this page, the payment amount is indicated as 1.85 euros, but to send cryptocurrency, the victim is asked to copy the amount of 0.04704 bitcoins, equivalent to more than a thousand dollars.

The domain names of the DHL phishing pages of PTI-252 are listed below.

Operational Environment

DHL Phishing Domains
dhl.041594212.bookluxurygh.com
dhl.05463822.novanft.info
dhl.055244l585.cunghocluat.com
dhl.0555300202.loginwahana138.org
dhl.8192738.bradleyequipmentrentals.com
dhl.915205l4725.thek9circle.com
dhl.be.038551544l54.yuhsun887.com
dhl.be.06548452125.athensgaheatingandair.com
dhl.com-express-nr9593220.polecat.xyz
dhl.com-id034223449595.covidopedia.com
dhl.com-id043499292103.gimmegifts.xyz
dhl.com-id124949299104494.polecat.xyz
dhl.com-id31q49m94e23v88.polecat.xyz
dhl.com-id50503340440.covidopedia.com
dhl.de-express-id0439939458398293.caovive.online
dhl.de-id003349492283848.gscode.online
dhl.de-id00559383888228348.gamestats.xyz
dhl.de-id00595348458532.playerofatomic.online
dhl.de-id0404955829.espertiinflipping.online
dhl.de-nr0549599939238484.playerofatomic.online
dhl.express.vaysieutoc88.com
dhl.express.whitiania.com
dhl.express.yo-yo-pen.com
dhl.f1f21.bradleyequipmentrentals.com
dhl.id-059593043985830802.adampoland.com
dhl.id00494885888622.adampoland.com
dhl.id004949595993992.bestreviewzz.com
dhl.parcel3.bradleyequipmentrentals.com
dhl.vaysieutoc88.com
dhl.vistomasterlist.com
0059595390202402400202.sobul.net
9033913901903944209920.queryfood.com
id-02494353.dhl.trannguyenanhkiet.info
id.0565281.dhl.olympuscoffee.info
dhl.be.06548452125.athensgaheatingandair.com
dhl.id00494885888622.adampoland.com
dhl.be.038551544l54.yuhsun887.com
dhl.915205l4725.thek9circle.com
dhl.055244l585.cunghocluat.com
dhl.041594212.bookluxurygh.com
dhl.0555300202.loginwahana138.org
dhl.05463822.novanft.info