Osumi, Yusuke Profile picture
Threat Intelligence, Cyber Security Researcher, PenTester. CISSP,CISA
Jun 26, 2022 4 tweets 3 min read
⚠️ #Phishing Alert
IP: 158.51.96[.]35 (AS397270 NetInformatik)
IoC: otx.alienvault.com/pulse/62b87f1c…
Brand: JR East えきねっと

eki-nzt[.]com[.]iofo[.]crmiet[.]com[.]cn
eki-nzt[.]com[.]iofo[.]jgmm[.]com[.]cn
eki-nzt[.]com[.]iofo[.]jgmd[.]com[.]cn
eki-nzt[.]com[.]iofo[.]jgmh[.]com[.]cn
#phishing
eki-nzt[.]com[.]iofo[.]zxtj[.]com[.]cn
eki-nzt[.]com[.]personal[.]crmiet[.]com[.]cn
eki-nzt[.]com[.]personal[.]jgmd[.]com[.]cn
eki-nzt[.]com[.]personal[.]jgmh[.]com[.]cn
eki-nzt[.]com[.]personal[.]jgmm[.]com[.]cn
eki-nzt[.]com[.]personal[.]zxtj[.]com[.]cn
Jun 25, 2022 4 tweets 3 min read
🔥⚠️Massive 2618 #Phishing Sites on 1 IP! 🔥
Domain: com[.]cn🇨🇳
IP: 107.175.3[.]44 (AS36352 COLOCROSSING)
IoC: otx.alienvault.com/pulse/62b7301b…
Brand: VISA/Master/JCB/AMEX

➡️DGA based, Third Level Domain
hxxp://www[.]masccsorod[.]asosscemend[.]6ei2p4y1[.]com[.]cn/ic6oXx7P3s/page1.php
... ImageImageImage This Actor uses domains just before they expire.
They may be purchasing second-hand domains(二手域名) at a discount.❓ ImageImage