jroosen

Exchange Barrel'o'phish 5-6-20

May 6th, 2020
1,915
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.36 KB | None | 0 0
  1. Exchange Phishing Sites:
  2. https://unada.ga/.well-known/pki-validation/OWA-AUT/index.html?l=_JeHFUq_VJOXK0QWHtoGYDw_Product-UserID&#alfredhole@youare.com
  3. https://aadarshgroup.org/owa111/?path=orly@owl.com
  4.  
  5. Sandbox run:
  6. https://app.any.run/tasks/9ec2427c-9d7a-434f-9327-c88d014a4574
  7. https://app.any.run/tasks/9c7f9292-2381-43b0-8f45-3855571054f6
  8.  
  9. Pivot to other sites using the same kit:
  10. https://urlscan.io/result/5f355edb-792d-443a-812a-f33104c16b4c/related/
  11.  
  12. Potentially running off Storage on Google APIs:
  13.  
  14. #storage.googleapis.com/aoutlook-platilla-256443704/index.html
  15. #storage.googleapis.com/owaab/index.html
  16. #storage.googleapis.com/owa-ym/index.html
  17.  
  18. Cred validation sites:
  19. munshiganjeralo.com
  20.  
  21. Total list of domains running this phishing kit:
  22.  
  23. annaeva.hu
  24. blufftonbaysails.com
  25. cna.thephotosisters.com
  26. cressolbank.com
  27. dma.bieca.net
  28. futureguides.in
  29. gunnesonflooring.com
  30. hindiclub.in
  31. htt.munsternissan.com
  32. illustrateomar.net
  33. mobile.gepf.co.za
  34. mxi.humanitythemixtape.com
  35. munshiganjeralo.com
  36. neg.willstrust.info
  37. sable-tidy-deposit.glitch.me
  38. simptaxt-err.tk
  39. sorobonmasters.com
  40. speedbangla.akij.net
  41. staging.zoelifespasalon.com
  42. syntax-oga.us-south.cf.appdomain.cloud
  43. virtualschooling.com
  44. ww3.nycimmigrationevals.net
  45. www.aislacontrol.com
  46. www.campcrest.com
  47. www.habibinyc.com
  48. www.ilovingme.services
  49. www.lightnhealthy.com.au
  50. www.unitronsea.com
Add Comment
Please, Sign In to add comment