[ << ALL_FEED ]

Phishing legitimacy

More in General

Phishing Legitimacy 😂

During an analysis of one phishing email, we noticed how attackers attempted to place phishing content on a page of the telegra․ph domain.

Their idea likely wasn’t to use the “extensive” functionality of the service for publishing content, but rather the reputation of the domain itself. And this could work, because given the perfectly legitimate content of the WHOIS data, the SSL certificate, and the web category of the telegra․ph domain for various aggregators, this page would receive at least a neutral status during analysis.

All of this led us to consider some real-world cases of using legitimate services in phishing campaigns.

1️⃣ Telegraph itself.

This is an anonymous blogging platform from a well-known developer. The functionality is minimalistic, with no control elements, and text is published using only two heading levels: Title and the text itself.

Only clickable elements for redirecting to a phishing page can be placed in the blog itself, while the styling remains neutral and minimalistic. An example of a phishing page on telegra․ph is shown in the screenshot.

In a sense, this page style resembles a text email, with the only difference being that the malicious link itself is hidden from automated analysis tools by yet another redirect layer.

2️⃣ Online development environments.

An online development environment that supports HTML, JavaScript, and even includes collaborative development and publishing features (like JSFiddle) can be used to deliver malware or integrate complex and diverse redirect techniques into the chain.
Here, for example, is code hosted on JSFiddle that loads a PNG image and executes without additional actions:


a = document.createElement('a');
document.body.appendChild(a);
a.download = name;
a.href = "data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABAAAAAOCAYAAAAmL5yKAAAAAXNSR0IArs4c6QAAAARnQU1BAACxjwv8YQUAAAAJcEhZcwAADsQAAA7EAZUrDhsAAABWSURBVDhPY0xISPh//0UOA7mAiVyNMH2jBjAwkBQGjD9KGBTEJ6OEO0kG2NvbMwCjnXwDsEU5SS5ANuDhjRCGJbPFSQsDdBfIyMhQZgDIQLK9QLWkDABPsQw5I+5qmAAAAABJRU5ErkJggg==";
a.click();

The problem with such links from online IDEs is clear: it’s easy to come up with phishing email content around them (“I’m a developer, here’s my portfolio with projects”), and the reputation of their domains won’t trigger alerts in analysis tools.

Furthermore, analyzing the page content requires advanced tools capable of emulating page transitions or loading content by executing JavaScript code.

3️⃣ IPFS.

The well-known distributed file storage protocol has become a popular tool among attackers. More precisely, not the protocol itself, but so-called IPFS gateways — online services that provide access to files hosted using this technology without requiring special clients. They act as a kind of proxy for accessing HTML pages stored in such a repository, allowing the attacker to avoid the hassle of hosting the page.

Additionally, a file from an IPFS repository cannot be deleted: an IPFS host can only place a placeholder indicating malicious content for the requested file, while the host itself needs time and resources to find such content in the repository.

✋ To protect against such exploitation of legitimate services, when securing the perimeter, you can use security tools that check the content of URL web content before rendering a verdict. And when receiving such links in personal email or messengers, it’s better to be cautious and check them using several services that show the reputation of indicators of compromise.

#web #ti #tip
@ptescalator

More from ti_author

More from ti_author

More in General