In accordance to a Monday blog post by FireEye, shoppers who clicked on the connection within the emails had been directed to a log-in site that convincingly impersonated the well-known streaming media service’s internet site. The malicious net site – hosted on a genuine, nevertheless compromised net server – would initial request end users to indicator in with their qualifications. At the time that stage was total, it would direct victims to extra webpages requesting even more facts these as names, start dates, billing addresses, Social Protection figures and payment card info. FireEye noted that the phishing web sites had been no longer energetic by the time its report was posted. To stay away from detection, the campaign used AES encryption to encode and obfuscate written content presented on the client’s side. “By obfuscating the webpage, attackers consider to deceive textual content-primarily based classifiers and reduce them from inspecting webpage written content,” the web site put up explains. Also, the phishing pages had been not exhibited to end users positioned at IPs belonging to specific companies like Google or PhishTank.
Source connection Share this:Click to share on Twitter (Opens in new window)Click to share on Facebook (Opens in new window)Click to share on Google+ (Opens in new window)
Related
In accordance to a Monday blog post by FireEye, shoppers who clicked on the connection within the emails had been directed to a log-in site that convincingly impersonated the well-known streaming media service’s internet site. The malicious net site – hosted on a genuine, nevertheless compromised net server – would initial request end users to indicator in with their qualifications. At the time that stage was total, it would direct victims to extra webpages requesting even more facts these as names, start dates, billing addresses, Social Protection figures and payment card info.
FireEye noted that the phishing web sites had been no longer energetic by the time its report was posted.
To stay away from detection, the campaign used AES encryption to encode and obfuscate written content presented on the client’s side. “By obfuscating the webpage, attackers consider to deceive textual content-primarily based classifiers and reduce them from inspecting webpage written content,” the web site put up explains. Also, the phishing pages had been not exhibited to end users positioned at IPs belonging to specific companies like Google or PhishTank.