These IOCs were released as part of PTI team research.
PTI-252 consists of an interactive phishing panel with fake DHL payment pages that allows the attacker to interact with the victim by manually redirecting the victim to a fake credit card payment page and verification code page. After the victim enters credit card information, attackers can show the victim fake payment error codes to force the victim to enter other card information.
Having received the victim's credit card details, the attackers use them to withdraw funds, and the victim gets a notification on their phone device with a verification code. Using the panel, threat actors redirect the victim to a fake payment confirmation page, forcing the victim to submit a confirmation code. All information, including credit card details, confirmation codes and the victim's IP address, are displayed in the panel.
If the victim cannot use a credit card, the attackers redirect the victim to a fake cryptocurrency payment page. On this page, the payment amount is indicated as 1.85 euros, but to send cryptocurrency, the victim is asked to copy the amount of 0.04704 bitcoins, equivalent to more than a thousand dollars.
The domain names of the DHL phishing pages of PTI-252 are listed below.
DHL Phishing Domains |
---|
dhl.041594212.bookluxurygh.com |
dhl.05463822.novanft.info |
dhl.055244l585.cunghocluat.com |
dhl.0555300202.loginwahana138.org |
dhl.8192738.bradleyequipmentrentals.com |
dhl.915205l4725.thek9circle.com |
dhl.be.038551544l54.yuhsun887.com |
dhl.be.06548452125.athensgaheatingandair.com |
dhl.com-express-nr9593220.polecat.xyz |
dhl.com-id034223449595.covidopedia.com |
dhl.com-id043499292103.gimmegifts.xyz |
dhl.com-id124949299104494.polecat.xyz |
dhl.com-id31q49m94e23v88.polecat.xyz |
dhl.com-id50503340440.covidopedia.com |
dhl.de-express-id0439939458398293.caovive.online |
dhl.de-id003349492283848.gscode.online |
dhl.de-id00559383888228348.gamestats.xyz |
dhl.de-id00595348458532.playerofatomic.online |
dhl.de-id0404955829.espertiinflipping.online |
dhl.de-nr0549599939238484.playerofatomic.online |
dhl.express.vaysieutoc88.com |
dhl.express.whitiania.com |
dhl.express.yo-yo-pen.com |
dhl.f1f21.bradleyequipmentrentals.com |
dhl.id-059593043985830802.adampoland.com |
dhl.id00494885888622.adampoland.com |
dhl.id004949595993992.bestreviewzz.com |
dhl.parcel3.bradleyequipmentrentals.com |
dhl.vaysieutoc88.com |
dhl.vistomasterlist.com |
0059595390202402400202.sobul.net |
9033913901903944209920.queryfood.com |
id-02494353.dhl.trannguyenanhkiet.info |
id.0565281.dhl.olympuscoffee.info |
dhl.be.06548452125.athensgaheatingandair.com |
dhl.id00494885888622.adampoland.com |
dhl.be.038551544l54.yuhsun887.com |
dhl.915205l4725.thek9circle.com |
dhl.055244l585.cunghocluat.com |
dhl.041594212.bookluxurygh.com |
dhl.0555300202.loginwahana138.org |
dhl.05463822.novanft.info |