Analysing a massive Office 365 phishing campaign
ID: e3d645b8-1cd6-5bf3-92fc-734864c3120e
STIX ID: report--e3d645b8-1cd6-5bf3-92fc-734864c3120e
Feed Name: Blaze's Security Blog
This report details an active, large-scale Office 365 credential-phishing campaign in which spearphish emails lead victims through compromised SharePoint/OneDrive pages to SSL-backed phishing sites hosted on happymachineit.info (178.159.36.107) within AS48666, with 875 unique O365 phishing instances identified; it provides IOCs (domains, IPs, URIs, email), notes the use of both valid and self-signed certificates, and recommends detection (YARA), response actions (password resets, mailbox rule checks), and preventive controls (blocking 178.159.36.0/24, anti-phishing filters, MFA, user awareness).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
