v4ensics
@v4ensics
Followers
232
Following
37
Media
951
Statuses
1K
Vital Digital Forensics: Cyber-security services, specializing in Digital Forensics / Incident Response (DFIR), malware analysis and expert witness testimony
Athens
Joined October 2021
2022 #phishing #insights report published today by @v4ensics. Phishing campaigns, Greek wise, targeted the #HellenicPostService (ELTA), #NationalBankGr and #AlphaBank, while global wise, postal and #Meta targeting scams were on the rise. Read the report on
v4ensics.gr
In 2022, V4ensics team analyzed more than 400 phishing sites, in most cases along with the associated e-mails, which either derived from phishing campaigns...
2
3
10
Both phishing sites seem to be subdomains of legitimate commercial sites (theoutwrld[.]com and flybus-travel[.]com) and , irrelevant obviously to the supposed recruiters brands (#Asos and #Airbus). Based on OSINT (kudos @urlscanio ) campaign is active the least 16 days
0
0
0
New #IPaddress (193.46.217.13) hosting malicious sites. IP uncovered through e-mail campaigns mimicking @bookingcom and hosts multiple #FakeCaptcha sites
1
0
3
New #phishing campaign targeting #eltacourier (elta[.]courier-ls[.]sale/gr) just spotted in the wild
0
1
1
4 Greek banks available for the alleged #taxrefund (@NationalBankGR , #AlphaBank, #Eurobank and #PiraeusBank
0
0
0
As #Greekcitizens submit their tax statements #phishers try to trick them that #taxrefund is communing. Relevant phishing site is https://syndesiapp[.]web[.]app/main
1
0
1
🚨Ransomware actors exploited an unpatched vulnerability (CVE-2024-57727) in SimpleHelp RMM to compromise a utility billing software provider—part of a pattern of actors targeting downstream customers. See our advisory for mitigations👉 https://t.co/Yli2jWTtOw
8
47
125
With #phishers playing again the familiar to @v4ensics @Meta #policyviolation scheme accompanied with the "short"/24h #accountterminationnotice phishers sent the e-mails that triggered the investigation from @gmail accounts and targeted #German speaking users
0
0
0
New #phishing campaign targeting @Piraeus_Bank active since yesterday. Phishers use makaanshop[.]com/haikku to direct intended victims to online[.]myirdrefund[.]nz[.]ilhii[.]ip-ddns[.]com/PiraeusGR/
0
1
1
the #fakecaptcha page instructs, as seen before, the intended victim to execute #powershell code
0
0
0
As #infostealing #campaigns targeting #hospitality evolve malicious actors the last few days use @Github sites to direct victims to #fakecaptcha pages and get them infect. At the moment commentsgst[.]github[.]io/698434 is used to direct to stayinfovstr[.]com
1
0
0
It seems that #Lumma #infostealer infra has been brought to a halt. Kudos @Microsoft and @EC3Europol for making this happen ( https://t.co/D1lqMwusTO,
https://t.co/3rLRkrQKYQ)
Lumma customers claim to have received this message on Telegram, apparently on Lumma customers group
0
0
1