The Anatomy of a Phishing Investigation: How Attackers Exploit Health-Related Fears
ID: 1d1dec29-fadb-5b29-a8e7-8542f9595b6d
STIX ID: report--1d1dec29-fadb-5b29-a8e7-8542f9595b6d
Feed Name: JUMPSEC Labs
JUMPSEC DART investigated a multi-stage phishing campaign using health-related lures that redirected victims through fake "Human Verification" pages to fraudulent shopping sites and payment pages (via ClickBank and Cloudflare). The analyst linked multiple sender domains and 25 hosts by a shared host key, identified associated IPs and ASNs (notably AS-36352, AS-32987, AS-32244), listed IOCs (numerous attacker and phishing site IPs), and mitigated the campaign by quarantining messages and blocking malicious domains and IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
