CREDENTIALS GATHERING CAMPAIGN

2019-09-02 CERT-SSI

https://www.cert.ssi.gouv.fr/uploads/CERTFR-2019-CTI-002-EN.pdf

Attachments

CERTFR-2019-CTI-002-EN.pdf (1 MB)

Thumbnail for CREDENTIALS GATHERING CAMPAIGN

ANSSI identified a credentials-gathering campaign active since at least 2017 that used spearphishing emails, phishing websites, and large clusters of lookalike domains and subdomains. The infrastructure appeared to target diplomatic bodies, ministries of foreign affairs, UN-related entities, think tanks, Stanford University, South Korea's foreign ministry, and regional email providers. Several domains spoofed cloud, mail, and document services, with many subdomains resolving in the 157.7.184.0/24 range hosted in Japan and grouped by shared registration emails or naming patterns. ANSSI did not attribute the campaign, but noted technical links between some infrastructure and open-source reporting on Kimsuky and Group123, including doc-view.work and mailacounts.com/NavRAT references. The reporting matters because it gives defenders concrete phishing infrastructure and target patterns for monitoring credential-theft activity against strategic organizations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7ca1a603a7440f1031c666afbe44afc8 2019-09-02 2024-12-02
DOMAIN bigwnet.com 2019-09-02 2024-05-10
DOMAIN login-main.bigwnet.com 2019-09-02 2024-05-10
EMAIL [email protected] 2019-09-02 2020-11-22
HASH e12d0655cc09cddb4fb836c641f7317… 2019-09-02 2019-09-02
HASH 9c6f6db86b5ccdda884369c9c52dd85… 2019-09-02 2019-09-02
EMAIL [email protected] 2019-09-02 2019-09-02
EMAIL [email protected] 2019-09-02 2019-09-02
EMAIL [email protected] 2019-09-02 2019-09-02
EMAIL [email protected] 2019-09-02 2019-09-02
EMAIL [email protected] 2019-09-02 2019-09-02
EMAIL [email protected] 2019-09-02 2019-09-02
EMAIL [email protected] 2019-09-02 2019-09-02
EMAIL [email protected] 2019-09-02 2019-09-02
EMAIL [email protected] 2019-09-02 2019-09-02
EMAIL [email protected] 2019-09-02 2019-09-02
EMAIL [email protected] 2019-09-02 2019-09-02
EMAIL [email protected] 2019-09-02 2019-09-02
EMAIL [email protected] 2019-09-02 2019-09-02
URL https://heehorse.com/heehorse_c… 2019-09-02 2019-09-02
URL http://www.china-un.org/eng/dbt… 2019-09-02 2019-09-02
DOMAIN asaninst.info 2019-09-02 2019-09-02
DOMAIN gstaticstorage.com 2019-09-02 2019-09-02
DOMAIN drog-service.com 2019-09-02 2019-09-02
DOMAIN mailseco.com 2019-09-02 2019-09-02
DOMAIN sec-live.com 2019-09-02 2019-09-02
DOMAIN hotrnall.co 2019-09-02 2019-09-02
DOMAIN dauurn.net 2019-09-02 2019-09-02
DOMAIN login-sec.com 2019-09-02 2019-09-02
DOMAIN login-yahoo.info 2019-09-02 2019-09-02
DOMAIN poczta.hotrnall.com 2019-09-02 2019-09-02
DOMAIN ahooc.com 2019-09-02 2019-09-02
DOMAIN dounn.net 2019-09-02 2019-09-02
DOMAIN viewetherwallet.com 2019-09-02 2019-09-02
DOMAIN logins-yahoo.com 2019-09-02 2019-09-02
DOMAIN login-use.com 2019-09-02 2019-09-02
DOMAIN log-yahoo.com 2019-09-02 2019-09-02
DOMAIN hotrnall.com 2019-09-02 2019-09-02
DOMAIN heehorse.com 2019-09-02 2019-09-02
DOMAIN set-login.com 2019-09-02 2019-09-02
DOMAIN lh-yahoo.com 2019-09-02 2019-09-02
DOMAIN mail.aei.org 2019-09-02 2019-09-02
DOMAIN imap-login.com 2019-09-02 2019-09-02
DOMAIN lh-login.com 2019-09-02 2019-09-02
DOMAIN user-accounts.net 2019-09-02 2019-09-02
DOMAIN lh-logs.com 2019-09-02 2019-09-02
DOMAIN mai1.info 2019-09-02 2019-09-02
DOMAIN login-history.vip-sina.com 2019-09-02 2019-09-02
DOMAIN politico.eu.mai1.info 2019-09-02 2019-09-02
DOMAIN dovvn-mail.com 2019-09-02 2019-09-02
DOMAIN mail.unperu.yalnoo.com 2019-09-02 2019-09-02
DOMAIN inbox-yahoo.com 2019-09-02 2019-09-02
DOMAIN mail-down.com 2019-09-02 2019-09-02
DOMAIN yrnall.com 2019-09-02 2019-09-02
DOMAIN china-un.org 2019-09-02 2019-09-02
DOMAIN members.dauurn.net 2019-09-02 2019-09-02
DOMAIN srnbc-card.com 2019-09-02 2019-09-02
DOMAIN naver.mai1.info 2019-09-02 2019-09-02
DOMAIN yalnoo.com 2019-09-02 2019-09-02
DOMAIN matmiho.com 2019-09-02 2019-09-02
DOMAIN phlogin.com 2019-09-02 2019-09-02
DOMAIN wallet-vahoo.com 2019-09-02 2019-09-02
DOMAIN il.daumcdn.net.mailacounts.com 2019-09-02 2019-09-02
DOMAIN eposcard.co 2019-09-02 2019-09-02
DOMAIN mailacounts.com 2018-05-31 2019-09-02

Related Reports

« Back