Threat Actors Hide Behind School-Themed Domains In Newly Uncovered Bulletproof Infrastructure
ID: e58b2b1e-4fab-521b-a297-2b33d6986fbf
STIX ID: report--e58b2b1e-4fab-521b-a297-2b33d6986fbf
Feed Name: GBHackers
Analysts found a sophisticated traffic distribution system (TDS) operating behind education-themed domains that uses a first-stage XOR-obfuscated JavaScript loader (e.g., https://toxicsnake-wifes.com/promise/script.js) to fingerprint and route victims to phishing, scams, and malware payloads; the infrastructure leverages bulletproof hosting (HZ Hosting Ltd, AS202015), disposable Let’s Encrypt certificates, shared WHOIS/contact details, and multiple related domains and IPs (185.33.84.152, 185.33.84.189) indicating an operator cluster distributing credential-stealers and other commodity malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
