Flying Phish
ID: f8264def-6b0b-5c30-be62-c5dbd71f5d30
STIX ID: report--f8264def-6b0b-5c30-be62-c5dbd71f5d30
Feed Name: DomainTools
Threat Score
This report analyzes a recurring credential-harvesting phishing campaign impersonating Twitter, documenting discovery of a starting domain (twitterreporterhelp.com), pivoting to ~153 related domains, shared GIF/logo resources, VirusTotal-sourced PHP samples and a zip lure, active testing with honey accounts, and network/process artefacts; it provides IoCs, sample hashes, mitigations and an import hash for DomainTools Iris Investigate for further detection and blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
