Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #IOC #OptiData #VR #fraud #phishing #ukrposhta
- https://pastebin.com/AqQEjNTg
- attack_vector
- --------------
- email URL > redirect > fake ukrposhta page > get credit card data
- email_headers
- --------------
- Return-Path: <ukrposhta@ukrposhta.ua>
- Received: from ukrposhta.ua ([46.173.210.44])
- Received: from ukrposhta.ua ([46.173.210.44] RDNS failed) by ukrposhta.ua
- From: Укрпошта Експрес <ukrposhta@ukrposhta.ua>
- Subject: Ваш пакет не може бути доставлений 05.12.2020
- To: victim@company.org
- Date: Sat, 5 Dec 2020 16:29:19 -0800
- X-Mailer: Microsoft Outlook, Build 11.5608.5606
- X-OriginalArrivalTime: 06 Dec 2020 00:29:19.0116 (UTC) FILETIME=[D5FBCCC0:01D6CB66]
- X-FEAS-SURL: https://inc-ukraine-redirect.com/ukraine/info.html
- X-FEAS-CLIENT-IP: 46.173.210.44
- URL`s
- --------------
- https://inc-ukraine-redirect.com/ukraine/info.html >> redirect >> https://ukrposhta-ua.com/ua/877317730/1605824564/381a5/
- Domain
- --------------
- https://urlscan.io/result/13f97ef6-9da4-49a1-b187-b125b0cc1c35/
- https://urlscan.io/domain/ukrposhta-ua.com
- SSL Cert
- --------------
- Let's Encrypt
- Validity
- Not Before: Dec 5 13:33:34 2020 GMT
- Not After : Mar 5 13:33:34 2021 GMT
- Subject:
- commonName = webdisk.inc-ukraine-redirect.com
- X509v3 Subject Alternative Name:
- DNS:autodiscover.inc-ukraine-redirect.com
- DNS:autodiscover.ukrposhta-ua.com
- DNS:cpanel.inc-ukraine-redirect.com
- DNS:cpanel.ukrposhta-ua.com
- DNS:cpcalendars.inc-ukraine-redirect.com
- DNS:cpcalendars.ukrposhta-ua.com
- DNS:cpcontacts.inc-ukraine-redirect.com
- DNS:cpcontacts.ukrposhta-ua.com
- DNS:inc-ukraine-redirect.com
- DNS:inc-ukraine-redirect.ouidadkaramace.com
- DNS:mail.inc-ukraine-redirect.com
- DNS:mail.ukrposhta-ua.com
- DNS:ukrposhta-ua.com
- DNS:ukrposhta-ua.ouidadkaramace.com
- DNS:webdisk.inc-ukraine-redirect.com
- DNS:webdisk.ukrposhta-ua.com
- DNS:webmail.inc-ukraine-redirect.com
- DNS:webmail.ukrposhta-ua.com
- DNS:www.inc-ukraine-redirect.com
- DNS:www.inc-ukraine-redirect.ouidadkaramace.com
- DNS:www.ukrposhta-ua.com
- DNS:www.ukrposhta-ua.ouidadkaramace.com
- https://crt.sh/?q=ukrposhta-ua.com
- https://www.ssllabs.com/ssltest/analyze.html?d=ukrposhta-ua.com
- MX
- --------------
- 46.173.210.44
- https://urlscan.io/ip/46.173.210.44
- https://www.virustotal.com/gui/ip-address/46.173.210.44/details
- # # #
- VR
Add Comment
Please, Sign In to add comment