logo

Intel Drops #1

ID: 81a7833f-84f5-5b7d-9e93-5fc8a96ef87e

STIX ID: report--81a7833f-84f5-5b7d-9e93-5fc8a96ef87e

Feed Name: IntelInsights (Substack)

Threat Score
68/100

Date Published: 2025-07-30

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

Active phishing emails targeting EU and US companies deliver PDFs with QR codes that redirect to identical credential-harvesting sites hosted on dallasonrasolutions.cloud and withbible.com; the latter may be a compromised long-registered domain. Evidence includes hundreds of related EMLs, consistent HELO headers, and two source IPs (51.89.86.103, 23.26.201.168), collectively indicating a single coordinated campaign and providing actionable IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.