Interactive Brokers W-8BEN Lure Hid Behind a 0-Day Domain
ID: 42dff869-f294-5cf3-b847-6eb78c8b8139
STIX ID: report--42dff869-f294-5cf3-b847-6eb78c8b8139
Feed Name: IRONSCALES
A phishing campaign impersonating Interactive Brokers sent W-8BEN renewal emails that linked to a zero-day domain (ehdgmsrd.com) registered the same day and hidden behind a Cloudflare challenge; the recipient organization's link-protection proxy loaded its proxy page and reported the URL clean while the underlying credential-harvest page remained unreachable to scanners, enabling credential theft. Indicators include sending domain jlrimes.com (DKIM body-hash fail, DMARC p=none), sender [email protected], and the EdgePilot-wrapped CTA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
