PhaaS actor uses DoH and DNS MX to dynamically distribute phishing

Infoblox discovered a phishing kit that creatively employs DNS mail exchange (MX) records to dynamically serve fake, tailored, login pages, spoofing over 100 brands. Author: AlienVault

Related Tags:
malspam

cloud

T1199

T1134

T1102

T1566

AlienVault OTX

AlienVault

Phishing

Associated Indicators:
carriertrucks.com

truck-parts.nl

hexatimes.com

38474.com

foxmail.net

movesfitnesszoom.co.uk

nfond.com

zeinabghasemi.ir

185.209.161.155