NEWLY REGISTERED DOMAINS IN JAPAN-TARGETED PHISHING

    Date: 11/11/2024

    Severity: Critical 

    Summary

    This is an ongoing phishing campaign aimed at Japan-based companies and organizations. The attackers frequently register new domains, often hosted on public cloud platforms. These phishing sites are short-lived, and the threat actor continuously registers a large volume of new domains.  

    Indicators of Compromise (IOC) List

    Domains\URLs :

    asdfghjklzxcvbnmqwertyuiopmlkhnas.com

    asdfghjklzxcvbnmqwertyuiopnlkasuopas.com

    iunjeanjed.com

    iwmaasdioas.com

    tinfrnub.com

    ybrjaobs.com

    ybrjaonjws.com

    yngsowusad.com

    https://a2.jcbmnksasd.com/FjgDET/

    https://a3.uisna.com/CaACrB/

    https://dianyneksa.com/ele

    https://oveksaama.com/ama

    https://oveksadian.com/ele

    https://oveksamaomao.com/yaya

    https://oveksasanjng.com/sj

    https://sanjinyneksa.com/sj

    https://tkwouiasf.com/

    https://ynjkwama.com/ama

    https://ynjkwmaom.com/yaya

    https://www.smbc-card.compctjcpyndamyntbasquvczdjegcsflwhugcfmai@inkiunf.com/

    ​​https://jpyzhsh.comjdlppqploqayhmkeqsklvshkalnhvzhqvpmlmln@tinfrnnjic.com?loginid=hxwqvccnuraxgnkeeprdyguartlxxtegwbnuktfwjznezjkiei9000188595xujlbdvzbq

    https://bllrkco.comsivrdctigsupylijeidyeqjnprojhxtpzglruhl@tinfrns.com?loginid=nafkgfmajbxfktdehpmqqrinrcjmbxnownyciifwmbjywvjpnh7444598292msypxiwwoc

    https://www.smbc-card.comewsbqmsttsfhfmedaagcdfncbbfqmfylshzfwkm@masrpjw.com/

    https://www.smbc-card.comtihjporzafkaiueyuzyvoxkhxklhjbwpnjjshmy@wernhgb.com/ 

    https://yahoo.co.jpybexxlqlrorrekqpwiqrdsgxcvvtfvfjcbogaot@electpmw.com/ 

    https://yahoo.co.jpagfblgsnimurlzxbzcecdaozxcuknpzmkacvhql@kpjpns.com/

    IP Address :

    101.36.105.44

    101.36.105.98

    124.156.212.175

    165.154.231.17

    165.154.231.34

    165.154.231.62

    165.154.231.96

    165.154.231.99

    165.154.231.175

    165.154.231.184

    43.128.237.191

    43.128.237.235

    43.130.232.219

    43.130.245.23

    43.133.12.183

    43.133.13.115

    43.133.13.196

    43.133.173.108

    43.133.193.162

    43.133.193.3

    43.133.196.251

    43.133.8.139

    43.153.140.10

    43.153.147.20

    43.153.149.164

    43.153.168.126

    43.153.176.165

    43.153.178.121

    43.153.183.161

    43.153.185.146

    43.163.198.51

    43.163.204.5

    43.163.212.225

    43.163.221.38

    43.163.234.142

    43.163.238.42

    43.167.237.47

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Domains\URLs :

    userdomainname like "https://ynjkwama.com/ama" or url like "https://ynjkwama.com/ama" or userdomainname like "tinfrnub.com" or url like "tinfrnub.com" or userdomainname like "ybrjaonjws.com" or url like "ybrjaonjws.com" or userdomainname like "yngsowusad.com" or url like "yngsowusad.com" or userdomainname like "https://oveksasanjng.com/sj" or url like "https://oveksasanjng.com/sj" or userdomainname like "https://oveksadian.com/ele" or url like "https://oveksadian.com/ele" or userdomainname like "asdfghjklzxcvbnmqwertyuiopnlkasuopas.com" or url like "asdfghjklzxcvbnmqwertyuiopnlkasuopas.com" or userdomainname like "iwmaasdioas.com" or url like "iwmaasdioas.com" or userdomainname like "asdfghjklzxcvbnmqwertyuiopmlkhnas.com" or url like "asdfghjklzxcvbnmqwertyuiopmlkhnas.com" or userdomainname like "iunjeanjed.com" or url like "iunjeanjed.com" or userdomainname like "https://www.smbc-card.compctjcpyndamyntbasquvczdjegcsflwhugcfmai@inkiunf.com/" or url like "https://www.smbc-card.compctjcpyndamyntbasquvczdjegcsflwhugcfmai@inkiunf.com/" or userdomainname like "https://ynjkwmaom.com/yaya" or url like "https://ynjkwmaom.com/yaya" or userdomainname like "ybrjaobs.com" or url like "ybrjaobs.com" or userdomainname like "https://a2.jcbmnksasd.com/FjgDET/" or url like "https://a2.jcbmnksasd.com/FjgDET/" or userdomainname like "https://a3.uisna.com/CaACrB/" or url like "https://a3.uisna.com/CaACrB/" or userdomainname like "https://dianyneksa.com/ele" or url like "https://dianyneksa.com/ele" or userdomainname like "https://oveksaama.com/ama" or url like "https://oveksaama.com/ama" or userdomainname like "https://oveksamaomao.com/yaya" or url like "https://oveksamaomao.com/yaya" or userdomainname like "https://sanjinyneksa.com/sj" or url like "https://sanjinyneksa.com/sj" or userdomainanme like "https://tkwouiasf.com/" or url like "https://tkwouiasf.com/" or userdomainname like "https://bllrkco.comsivrdctigsupylijeidyeqjnprojhxtpzglruhl@tinfrns.com?loginid=nafkgfmajbxfktdehpmqqrinrcjmbxnownyciifwmbjywvjpnh7444598292msypxiwwoc" or url like "https://bllrkco.comsivrdctigsupylijeidyeqjnprojhxtpzglruhl@tinfrns.com?loginid=nafkgfmajbxfktdehpmqqrinrcjmbxnownyciifwmbjywvjpnh7444598292msypxiwwoc" or userdomainname like "https://jpyzhsh.comjdlppqploqayhmkeqsklvshkalnhvzhqvpmlmln@tinfrnnjic.com?loginid=hxwqvccnuraxgnkeeprdyguartlxxtegwbnuktfwjznezjkiei9000188595xujlbdvzbq" or url like "https://jpyzhsh.comjdlppqploqayhmkeqsklvshkalnhvzhqvpmlmln@tinfrnnjic.com?loginid=hxwqvccnuraxgnkeeprdyguartlxxtegwbnuktfwjznezjkiei9000188595xujlbdvzbq" or userdomainname like "https://www.smbc-card.comewsbqmsttsfhfmedaagcdfncbbfqmfylshzfwkm@masrpjw.com/" or url like "https://www.smbc-card.comewsbqmsttsfhfmedaagcdfncbbfqmfylshzfwkm@masrpjw.com/" or userdomainname like "https://www.smbc-card.comtihjporzafkaiueyuzyvoxkhxklhjbwpnjjshmy@wernhgb.com/" or url like "https://www.smbc-card.comtihjporzafkaiueyuzyvoxkhxklhjbwpnjjshmy@wernhgb.com/" or userdomainname like "https://yahoo.co.jpybexxlqlrorrekqpwiqrdsgxcvvtfvfjcbogaot@electpmw.com/" or url like "https://yahoo.co.jpybexxlqlrorrekqpwiqrdsgxcvvtfvfjcbogaot@electpmw.com/" or userdomainname like "https://yahoo.co.jpagfblgsnimurlzxbzcecdaozxcuknpzmkacvhql@kpjpns.com/" or url like "https://yahoo.co.jpagfblgsnimurlzxbzcecdaozxcuknpzmkacvhql@kpjpns.com/"

    IP Address :

    dstipaddress IN ("43.133.8.139","43.163.238.42","43.133.196.251","165.154.231.17","43.128.237.235","43.163.221.38","124.156.212.175","165.154.231.175","43.163.204.5","43.133.13.115","43.153.149.164","43.133.193.3","165.154.231.34","43.153.140.10","43.153.178.121","43.133.13.196","43.153.176.165","43.130.245.23","43.167.237.47","43.133.12.183","165.154.231.62","43.163.212.225","101.36.105.44","101.36.105.98","165.154.231.96","165.154.231.99","165.154.231.184","43.128.237.191","43.130.232.219","43.133.173.108","43.133.193.162","43.153.147.20","43.153.168.126","43.153.183.161","43.153.185.146","43.163.198.51") or ipaddress IN ("43.133.8.139","43.163.238.42","43.133.196.251","165.154.231.17","43.128.237.235","43.163.221.38","124.156.212.175","165.154.231.175","43.163.204.5","43.133.13.115","43.153.149.164","43.133.193.3","165.154.231.34","43.153.140.10","43.153.178.121","43.133.13.196","43.153.176.165","43.130.245.23","43.167.237.47","43.133.12.183","165.154.231.62","43.163.212.225","101.36.105.44","101.36.105.98","165.154.231.96","165.154.231.99","165.154.231.184","43.128.237.191","43.130.232.219","43.133.173.108","43.133.193.162","43.153.147.20","43.153.168.126","43.153.183.161","43.153.185.146","43.163.198.51") or publicipaddress IN ("43.133.8.139","43.163.238.42","43.133.196.251","165.154.231.17","43.128.237.235","43.163.221.38","124.156.212.175","165.154.231.175","43.163.204.5","43.133.13.115","43.153.149.164","43.133.193.3","165.154.231.34","43.153.140.10","43.153.178.121","43.133.13.196","43.153.176.165","43.130.245.23","43.167.237.47","43.133.12.183","165.154.231.62","43.163.212.225","101.36.105.44","101.36.105.98","165.154.231.96","165.154.231.99","165.154.231.184","43.128.237.191","43.130.232.219","43.133.173.108","43.133.193.162","43.153.147.20","43.153.168.126","43.153.183.161","43.153.185.146","43.163.198.51") or srcipaddress IN ("43.133.8.139","43.163.238.42","43.133.196.251","165.154.231.17","43.128.237.235","43.163.221.38","124.156.212.175","165.154.231.175","43.163.204.5","43.133.13.115","43.153.149.164","43.133.193.3","165.154.231.34","43.153.140.10","43.153.178.121","43.133.13.196","43.153.176.165","43.130.245.23","43.167.237.47","43.133.12.183","165.154.231.62","43.163.212.225","101.36.105.44","101.36.105.98","165.154.231.96","165.154.231.99","165.154.231.184","43.128.237.191","43.130.232.219","43.133.173.108","43.133.193.162","43.153.147.20","43.153.168.126","43.153.183.161","43.153.185.146","43.163.198.51")

    Reference:

    https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2024-11-08-domains-for-Japan-targeted-phishing.txt


    Tags

    MalwarePhishingJapan

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags