Investigating Infrastructure and Tactics of Phishing-as-a-Service Platform Sniper Dz

    Date: 09/26/2024

    Severity: High

    Summary

    We have been tracking a well-known phishing-as-a-service (PhaaS) platform called Sniper Dz, which primarily targets major social media sites and online services. This platform likely serves a significant number of phishers, as the group behind it boasts thousands of subscribers on their Telegram channel. Our research has uncovered over 140,000 phishing websites linked to the Sniper Dz PhaaS platform in the past year.

    Indicators of Compromise (IOC) List

    URL/Domains

    free-fire-reward-garena-bd-nepazl.epizy.com

    Sniperdz.com

    proxymesh.com

    v0tingsystem.github.io

    freefirefff.github.io

    dev-cdn370.pantheonsite.io

    facebookbusiness0078.blogspot.be

    Climbing-green-botany.glitch.me

    6627c220b5daa507c6cca1c5--votedme.netlify.app

    raviral.com

    raviral.com/k_fac.php

    raviral.com/host_style/style/js-track/track.js

    t.me/JokerDzV2

    t.me/JokerDzV2/19

    automaticgiveaway.000webhostapp.com

    ff-rewards-redeem-codes-org.github.io

    instagram-cutequeen57.netlify.app

    pubg-tournament-official.github.io/free-fire-reedeem-code

    pro.riccardomalisano.com/about/z1to.html?u=ff-insta/?i=[Redacted_For_Anonymity]

    pro.riccardomalisano.com/about/z2to.html?u=ff-reward/?i=[Redacted_For_Anonymity]

    pro.riccardomalisano.com/about/z1to.html?u=eb-log/?i=[Redacted_For_Anonymity]

    pro.riccardomalisano.com/about/z1to.html?u=s-mobi/?i=[Redacted_For_Anonymity]

    pro.riccardomalisano.com/about/z2to.html?u=ff-spiner/?i=[Redacted_For_Anonymity]

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    URL/Domain

    userdomainname like "free-fire-reward-garena-bd-nepazl.epizy.com" or url like "free-fire-reward-garena-bd-nepazl.epizy.com" or userdomainname like "Sniperdz.com" or url like "Sniperdz.com" or userdomainname like "proxymesh.com" or url like "proxymesh.com" or userdomainname like "v0tingsystem.github.io" or url like "v0tingsystem.github.io" or userdomainname like "freefirefff.github.io" or url like "freefirefff.github.io" or userdomainname like "dev-cdn370.pantheonsite.io" or url like "dev-cdn370.pantheonsite.io" or userdomainname like "facebookbusiness0078.blogspot.be" or url like "facebookbusiness0078.blogspot.be" or userdomainname like "Climbing-green-botany.glitch.me" or url like "Climbing-green-botany.glitch.me" or userdomainname like "6627c220b5daa507c6cca1c5--votedme.netlify.app" or url like "6627c220b5daa507c6cca1c5--votedme.netlify.app" or userdomainname like "raviral.com" or url like "raviral.com" or userdomainname like "raviral.com/k_fac.php" or url like "raviral.com/k_fac.php" or userdomainname like "raviral.com/host_style/style/js-track/track.js" or url like "raviral.com/host_style/style/js-track/track.js" or userdomainname like "t.me/JokerDzV2" or url like "t.me/JokerDzV2" or userdomainname like "t.me/JokerDzV2/19" or url like "t.me/JokerDzV2/19" or userdomainname like "automaticgiveaway.000webhostapp.com" or url like "automaticgiveaway.000webhostapp.com" or userdomainname like "ff-rewards-redeem-codes-org.github.io" or url like "ff-rewards-redeem-codes-org.github.io" or userdomainname like "instagram-cutequeen57.netlify.app" or url like "instagram-cutequeen57.netlify.app" or userdomainname like "pubg-tournament-official.github.io/free-fire-reedeem-code" or url like "pubg-tournament-official.github.io/free-fire-reedeem-code" or userdomainname like "pro.riccardomalisano.com/about/z1to.html?u=ff-insta/?i=[Redacted_For_Anonymity]" or url like "pro.riccardomalisano.com/about/z1to.html?u=ff-insta/?i=[Redacted_For_Anonymity]" or userdomainname like "pro.riccardomalisano.com/about/z2to.html?u=ff-reward/?i=[Redacted_For_Anonymity]" or url like "pro.riccardomalisano.com/about/z2to.html?u=ff-reward/?i=[Redacted_For_Anonymity]" or userdomainname like "pro.riccardomalisano.com/about/z1to.html?u=eb-log/?i=[Redacted_For_Anonymity]" or url like "pro.riccardomalisano.com/about/z1to.html?u=eb-log/?i=[Redacted_For_Anonymity]" or userdomainname like "pro.riccardomalisano.com/about/z1to.html?u=s-mobi/?i=[Redacted_For_Anonymity]" or url like "pro.riccardomalisano.com/about/z1to.html?u=s-mobi/?i=[Redacted_For_Anonymity]" or userdomainname like "pro.riccardomalisano.com/about/z2to.html?u=ff-spiner/?i=[Redacted_For_Anonymity]" or url like "pro.riccardomalisano.com/about/z2to.html?u=ff-spiner/?i=[Redacted_For_Anonymity]"

    Reference: 

    https://unit42.paloaltonetworks.com/phishing-platform-sniper-dz-unique-tactics/


    Tags

    MalwarePhishing

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags