Phishers hide scam links with IPv6 trick in “free toothbrush” emails
ID: f60ef95e-9adc-5e6c-b5d7-882f1247ebee
STIX ID: report--f60ef95e-9adc-5e6c-b5d7-882f1247ebee
Feed Name: Malwarebytes Blog
This report details a phishing campaign impersonating United Healthcare offering a fake Oral-B toothbrush as bait; attackers obfuscate redirect URLs by using IPv6-mapped IPv4 address literals (e.g., http://[::ffff:5111:8e14]/ which resolves to 81.17.142.20) to hide hosting, and the pages collect PII and payment card data. The report includes indicators of compromise (81.17.142.40, 15.204.145.84, redirectingherenow.com, redirectofferid.pro) and provides mitigation steps for affected users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
