Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add 5.181.3.225 and related indicators - malware #734

Merged
merged 4 commits into from
Feb 1, 2025

Conversation

g0d33p3rsec
Copy link
Contributor

@g0d33p3rsec g0d33p3rsec commented Feb 1, 2025

Phishing Domain/URL/IP(s):

5.181.3.225
guardianviewer.com
sysoieaosgwoeesa.xyz
http://guardianviewer.com/box/setup.msi
http://guardianviewer.com/html/dl/Form%20I-19.pdf.url
https://guardianviewer.com/docu/Form%20I-19.pdf.lnk

Impersonated domain


Describe the issue

When exploring AS215540 earlier, I came across http://5.181.3.225:8080/ which is an open directory for guardianviewer.com. The site hosts an attack chain for an info stealer http://guardianviewer.com/html/dl/Form%20I-19.pdf.url -> https://guardianviewer.com/docu/Form%20I-19.pdf.lnk -> http://guardianviewer.com/box/setup.msi -> stolen information exfiltrated to sysoieaosgwoeesa.xyz.

Related external source

https://app.any.run/tasks/3eec1e59-3058-49dc-85b5-cedd8b571075
https://app.any.run/tasks/dc2cbf23-c54c-4722-a29d-225291335bed
https://urlscan.io/ip/5.181.3.225
https://www.virustotal.com/gui/file/d4d273b80e1373c46f5c13d4ce14e4184f2c8b2422ccadb1c00b24d75565a7e3

Screenshot

Click to expand

image
image
image
image
image
image
image
image
image

@g0d33p3rsec g0d33p3rsec merged commit 9935e97 into Phishing-Database:master Feb 1, 2025
1 check passed
@g0d33p3rsec g0d33p3rsec changed the title Add 5.181.3.225 Add 5.181.3.225 and related indicators - malware Feb 1, 2025
@g0d33p3rsec g0d33p3rsec deleted the add-5.181.3.225 branch February 1, 2025 01:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant