logo

Phishers hide scam links with IPv6 trick in “free toothbrush” emails

ID: f60ef95e-9adc-5e6c-b5d7-882f1247ebee

STIX ID: report--f60ef95e-9adc-5e6c-b5d7-882f1247ebee

Feed Name: Malwarebytes Blog

Threat Score
50/100

Date Published: 2026-03-11

Date Updated: 2026-04-28

...
...

This report details a phishing campaign impersonating United Healthcare offering a fake Oral-B toothbrush as bait; attackers obfuscate redirect URLs by using IPv6-mapped IPv4 address literals (e.g., http://[::ffff:5111:8e14]/ which resolves to 81.17.142.20) to hide hosting, and the pages collect PII and payment card data. The report includes indicators of compromise (81.17.142.40, 15.204.145.84, redirectingherenow.com, redirectofferid.pro) and provides mitigation steps for affected users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.