Spoofing Banks is a Balancing Act
ID: 1afdf3a0-b29d-5b0a-9e08-af60cff8a8f0
STIX ID: report--1afdf3a0-b29d-5b0a-9e08-af60cff8a8f0
Feed Name: DomainTools
DomainTools researchers identified 291 domains spoofing “natwest” and investigated connected infrastructure using Domain Risk Scores and guided pivots; they focused on natwestonline87.ml (high risk) and related domains (servicepaypal759.ml, royalbankservice264.ml, servicemessage368.ml), enumerating shared IPs, name servers, SSL hashes/subjects and noting associations with spoofed PayPal and Royal Bank domains. The report documents risk-score changes, passive DNS records (mail. and www. subdomains), and that VirusTotal returned a 0 detection for the observed www site, concluding that monitoring these artifacts can help detect and block this phishing activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
