VRad

#ukrposhta_fraud_051220

Dec 7th, 2020 (edited)
545
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.73 KB | None | 0 0
  1. #IOC #OptiData #VR #fraud #phishing #ukrposhta
  2.  
  3. https://pastebin.com/AqQEjNTg
  4.  
  5. attack_vector
  6. --------------
  7. email URL > redirect > fake ukrposhta page > get credit card data
  8.  
  9. email_headers
  10. --------------
  11. Return-Path: <[email protected]>
  12. Received: from ukrposhta.ua ([46.173.210.44])
  13. Received: from ukrposhta.ua ([46.173.210.44] RDNS failed) by ukrposhta.ua
  14. From: Укрпошта Експрес <[email protected]>
  15. Subject: Ваш пакет не може бути доставлений 05.12.2020
  16. Date: Sat, 5 Dec 2020 16:29:19 -0800
  17. X-Mailer: Microsoft Outlook, Build 11.5608.5606
  18. X-OriginalArrivalTime: 06 Dec 2020 00:29:19.0116 (UTC) FILETIME=[D5FBCCC0:01D6CB66]
  19. X-FEAS-SURL: https://inc-ukraine-redirect.com/ukraine/info.html
  20. X-FEAS-CLIENT-IP: 46.173.210.44
  21.  
  22. URL`s
  23. --------------
  24. https://inc-ukraine-redirect.com/ukraine/info.html >> redirect >> https://ukrposhta-ua.com/ua/877317730/1605824564/381a5/
  25.  
  26. Domain
  27. --------------
  28. https://urlscan.io/result/13f97ef6-9da4-49a1-b187-b125b0cc1c35/
  29. https://urlscan.io/domain/ukrposhta-ua.com
  30.  
  31. SSL Cert
  32. --------------
  33. Let's Encrypt
  34.  
  35. Validity
  36. Not Before: Dec 5 13:33:34 2020 GMT
  37. Not After : Mar 5 13:33:34 2021 GMT
  38. Subject:
  39. commonName = webdisk.inc-ukraine-redirect.com
  40.  
  41. X509v3 Subject Alternative Name:
  42. DNS:autodiscover.inc-ukraine-redirect.com
  43. DNS:autodiscover.ukrposhta-ua.com
  44. DNS:cpanel.inc-ukraine-redirect.com
  45. DNS:cpanel.ukrposhta-ua.com
  46. DNS:cpcalendars.inc-ukraine-redirect.com
  47. DNS:cpcalendars.ukrposhta-ua.com
  48. DNS:cpcontacts.inc-ukraine-redirect.com
  49. DNS:cpcontacts.ukrposhta-ua.com
  50. DNS:inc-ukraine-redirect.com
  51. DNS:inc-ukraine-redirect.ouidadkaramace.com
  52. DNS:mail.inc-ukraine-redirect.com
  53. DNS:mail.ukrposhta-ua.com
  54. DNS:ukrposhta-ua.com
  55. DNS:ukrposhta-ua.ouidadkaramace.com
  56. DNS:webdisk.inc-ukraine-redirect.com
  57. DNS:webdisk.ukrposhta-ua.com
  58. DNS:webmail.inc-ukraine-redirect.com
  59. DNS:webmail.ukrposhta-ua.com
  60. DNS:www.inc-ukraine-redirect.com
  61. DNS:www.inc-ukraine-redirect.ouidadkaramace.com
  62. DNS:www.ukrposhta-ua.com
  63. DNS:www.ukrposhta-ua.ouidadkaramace.com
  64.  
  65.  
  66. https://crt.sh/?q=ukrposhta-ua.com
  67. https://www.ssllabs.com/ssltest/analyze.html?d=ukrposhta-ua.com
  68.  
  69. MX
  70. --------------
  71. 46.173.210.44
  72. https://urlscan.io/ip/46.173.210.44
  73. https://www.virustotal.com/gui/ip-address/46.173.210.44/details
  74.  
  75. # # #
  76.  
  77.  
  78. VR
Add Comment
Please, Sign In to add comment