meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Monday, March 31st: Comparing Phishing Sites; DOH and MX Abuse Phishing; opkssh

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 31 March 2025

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Monday, March 31st: Comparing Phishing Sites; DOH and MX Abuse Phishing; opkssh

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, March 31st, 2025 edition of the Sands and then at Storm Center's Stormcast.

0:09.3

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.4

Jan on Friday looked at two different fishing sites that at first look look very similar. Same layout. They also

0:22.4

use the same trick that we often see, where they're including the favorite icon from a website

0:29.0

that matches your email domain in order to make the entire site look more plausible. Both of

0:35.7

these websites are claiming to be login screens to webmail systems,

0:41.1

something we definitely see over and over again. What Jan really looked at, given that these two

0:46.9

email or these two fishing sites look so similar, are they actually created by the same entity? Are they using the same fishing kit?

0:59.3

And the answer here appears to be no, because the back end of these two fishing site looks very different.

1:08.3

One of them uses telegram as a command control channel or to

1:12.7

infiltrate the data. The other one doesn't. It uses a more sort of generic web hook

1:19.7

process in order to send the data off to some collection site. Both sides are hosted very

1:26.8

differently. So definitely looks different, but similar techniques.

1:31.8

What Jan suggests here, and he's probably right with this, he's looked at a lot of these

1:35.8

fishing sites, that these two are derived from the same fishing kit. So they, which is start out

1:44.1

as one fishing kit, but then

1:46.4

these fishing kits get copied, traded all the time. So basically they split off, they evolve,

1:53.2

and that's probably what's happening here in this particular case. Now sticking with fishing here

1:59.9

for the second story, InfoBlocks has an interesting

2:03.9

blog, a very detailed blog actually, about what they're calling a recent Mercat fishing kit

2:12.0

instance. Merckad is what Info blogs calls this fishing kit. A couple things sort of stuck out here.

2:19.3

I mentioned earlier that the fishing kit that Jan talked about included basically your

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.