Showing posts with label linkedin. Show all posts
Showing posts with label linkedin. Show all posts

Tuesday, June 24, 2025

Piktochart - Phishing with Infographics (Guest diary on Sans Internet Storm center - isc.sans.edu)

Noticed today I'd forgotten to re-post this guest diary I shared to Storm center.   Link to original post,  My most recent work hasn't fit well with open source sharing, so I've been a bit quieter online lately, but as always feel free to reach out, and I'm always happy to learn something new or hear what you are working on or passionate about.

Thanks Johannes as always, for sharing the research to the community!


In line with our recent diaries featuring unique attack vectors for credential theft, such as phishing over LinkedIn Mail[1] and pretending to be an Outlook version update[2], we've recently learned of a phishing campaign targetting users of the Infographic service Piktochart.

During the COVID-19 pandemic, nearly every kind of company has moved to use more online collaboration tools.  This means that many small businesses, universities, primary and secondary schools, and others that may not be well-trained in online safety will be especially vulnerable to this type of attack, especially if they are using a relatively new tool, like Piktochart.

I had not used Piktochart before, but this week, security researcher @pageinsec[3] shared with me an infographic that asks the user to click on a link, in order to read a shared pdf document [4].

Piktochart has about 2,000 registered users, and about 24 million Piktocharts Created and is used by companies such as Forbes, TechCrunch, and others, according to their website.  With a legitimate business purpose that is endorsed by some large companies, it is likely this is an effective way for the attackers to evade DNS filtering or other simple defenses against credential-stealing attacks.
Piktochart has a feature that makes it even better for phishing:  Their registered "Pro users" can download an actual .pdf file, with the malicious link intact, or as well render the file into several different sizes of .png images, as indicated in the IOCs near the bottom of this page, which might be useful to hunt for similar activity.
An unsuspecting victim would receive an e-mail or social media post including the malicious Piktochart, from someone they knew, whose account had already been compromised.  If they click the link, a 2nd stage credential stealer follows, which is a pretty decent-looking (but fake) Microsoft login page hosted at the domain obggladdenlightfoundation(.)org.  This base domain currently has "0 out of 87" vendors reporting it as malicious on Virus Total, and is made out to be a non-profit in Lagos, Nigeria.  This specific example had a different site registration than most of the other, identical sites I've researched, so it is possible this site was the result of a takeover of a legitimate business' WordPress website, or a redirection of the site's DNS.



Despite the technical simplicity, this is a dangerous campaign since it is after Microsoft 0365 credentials, and evidence points to the same IP being used for a large variety of credential theft sites.

There are  quite a few  domains on the same IP[5], for example: 
pwan-heritage(.)com/pol/OfficeV4/*    
secure-official-spotify.pwanplus(.)com       
www.dhl-delivery-failure-resolve.naijamail.com  - This one includes a nice-looking DHL form [6]


Indicators of compromise - IOCs  
URLS/Domains
create.piktochart.com/output/52653368-my-visual
piktochart.com (if not needed for businses)
2nd stage/stealer
obggladdenlightfoundation.org/dfsmith/ofc3
obggladdenlightfoundation.org/dfsmith/ofc3/
obggladdenlightfoundation.org/dfsmith/ofc3/r.php?signin=d41d8cd98f00b204e9800998ecf8427e&auth=39bea2eedcf78c893b4d0898d91bba501390ced533b8de1d796bcc5973da76e5b1cf6668
obggladdenlightfoundation.org/dfsmith/ofc3/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=39bea2eedcf78c893b4d0898d91bba501390ced533b8de1d796bcc5973da76e5b1cf666
IP
173.231.197.145 [7]
Hostname:    ded5495.inmotionhosting.com
Domain registrar: 007NAMES INC.
*Used in most of the domains
Microssoft cred stealer image - hashes(sha2) 
7, 10, and 3kb versions of the same image
a90370dc587b73cd2dbe33504794e83c83dc9f365cd9cd94511593046db5ae09
bc2afe6e49541902541497a6823e1aa0f8e8683e203d4da6bc75590bddebeb702bed6013d59910f6714448cafeda98708886d48978b6b991627526964379efc0
DOM (cred-stealer page)
"
<form id="1MDAwMDMxMjAyMS0wMy0wMjE2MTQ2NTgwMDQ4NTgxMTAx"> <input type="hidden" value="[removed]"><input type="hidden" value="[removed"> </form>
"
Post request
"form id="f2" method="post" action="#" style="margin-bottom: 0px;"> <input required="" type="email" placeholder="Email, phone, or Skype" name="e"
    style="outline:none; background-color:transparent;border:0px solid;height:30px;width:300px;font-weight:lighter;font-size:15px;margin-left:5px;padding-bottom:0px;padding-top:0px;"> <img
    src="data:image/png;base64"...
Cookies
obggladdenlightfoundation.org/    1969-12-31
23:59:59    Name: PHPSESSID
obggladdenlightfoundation.org/dfsmith/ofc3/s    1969-12-31
23:59:59    Name: ip11


 JB Bowers
@cherokeejb_

References:
[1] - https://isc.sans.edu/forums/diary/The+new+LinkedInSecureMessage/27110
[2] - https://isc.sans.edu/forums/diary/Pretending+to+be+an+Outlook+Version+Update/27144/
[3] - https://apageinsec.wordpress.com/
[4] - https://create.piktochart.com/output/52653368-my-visual
[5] - https://urlscan.io/result/e02ea839-9671-4d31-a039-effd54877c0b/related/
[6] - https://urlscan.io/screenshots/205111b7-b981-48e9-9359-df55f278163b.png
[7] - https://isc.sans.edu/ipinfo.html?ip=173.231.197.145

Friday, March 5, 2021

The new "LinkedInSecureMessage"​ ?


Image of a stage 1 malware, from a pdf in a inkedin mail phishing message


With all the talk of secure messenger applications lately, I bet you’d like to have just one more, right? In the past few weeks, we’ve noticed a new variant on a typical cred-stealer, in this case offering itself up as a new, secure messaging format used right here on the career website LinkedIn.

There’s only one problem with this… there is no such thing as a “LinkedIn Private Shared Document”.

Not Quite Secure

Victims will receive an ordinary message, likely from someone which they already are connected with. These are not from the more recent, unsolicited “InMail” feature, but a regular, internal “Message” on LinkedIn. There is nothing interesting about the message, although it contains a 3rd-party link, claiming to be a “LinkedInSecureMessage” which serves up the nice-looking pdf file shown above.

If you click “VIEW DOCUMENT,” it opens up a convincing LinkedIn login page. ...


...this diary was published on the Internet Storm Center website, read the complete article at:

https://isc.sans.edu/forums/diary/The+new+LinkedInSecureMessage/27110/


Sunday, September 24, 2017

Next up: comparing Free & Open Source DFIR tools


This post was originally published at https://www.linkedin.com/pulse/next-up-comparing-free-open-source-dfir-tools-jb-?trk=mp-reader-card

-

Next I'll look at comparing Free & Open Source DFIR tools, and will also include the first of the B-Sides Springfield videos & reposts from KC, soon after this.

Infosecfeeds.org is up with the "planet" of Security #infosec podcasts (browser-based master feed of #security and #dfir pocasts)



I've really enjoyed a few blogs this year that were published directly on Linkedin, for example the Jiu Jitsui, chess and other blogs by Tim MV; so for the blog component of infosecfeeds.org, I'm testing out the "pages" function of Linkedin.
The homepage url for infosecfeeds.org should feature an aggregation of non-commercial (IT) Security podcasts, soon, if not it's not already up by the time you read this. I will update it and get some cron on it to regularly update it soon; there were also about 10 other feeds I wanted to initially include, including some dead-box-forensics focused shows I hope. InfosecFeeds.org is a planet based site, which is an open sourceproject under the python license. The original planet web app is featured on planet.debian.org for Planet Debian. I really love the format!
So the planet feed was just an idea to contribute to the community, but the main goal of the url was to include a blog link, which I will update after duplicating this blog, to blog.infosecfeeds.org for the entire journal (which I'll probably host somewhere else, or also on Github like the --The site can just as easily link for any other blogging site (for exposure alone, e.g. Blogger.com), or add that Ghost platform that I've wanted to see since Fab from Linux Outlaws touted it so highly (although he is a professional writer!)--and then just link/post the most career-relevant posts here), and dfir.infosecfeeds.org for only the most original research and computer-forensics focused content (which will be a link to here, if that is possible; the posts will all be "articles" here as well, to whichever degree of automation possisble.
This post actually I wouldn't even include there, but in a month or so, once I'm completely happy with the plant page of infosec podcasts, I think it is a great resource to the forensics and active defense communities as well, just as much as a post of original research.
The next super-relevant post should be a comparison of all the open-source linux "distros" already packaged up for Computer Forensics use. The post I mentioned above, will focus on several pre-packaged "forensic" computer systems, and which packages, and which major differences make up for example Sans' SIFT Workstation, REMnux, or any of these vs. just using Kali, or Black Arch, or building your own from the extensive Debian repositories, (tons were "#newinstretch"). I won't include Security Onion, which comes pre-packed with several IDS & IPS solutions; I'd read about that distro last spring in Amanda Berlin's Defensive Security Handbook. Off-topic I'd like to also include sometime soon also, a few off-topic posts about the early stages of the OWASP capture the flag.
Videos from B-Sides Springfield (and other videos from the MO/AR/#nwark Orzarks region) will also be posted soon, as I finish editing them. So whether here, or somewhere else, look soon for the videos from B-Sides Springfield (Missouri), posted one-by-one, as well as some initial blog-posts.
I plan to also include soon not only the first re-posts of other content from Bsides, but also a recap of the rough videos someone shared from Kansas City, including the special intro by Jack Daniels, and very inspiring, team & community-building opening from Chris Nickerson.
Approximately every 2nd or 3rd post, I hope to include the podcast form, which is a learning and case/study lab-based DFIR podcast called "Computer Forensics Podcast." I spent a lot of my life creating music and other content--also my current company is sound-related, even though I'm in networks & security--so don't think I'm jumping on a bandwagon here, but to help fill the void of forensics podcasts, and do sometimes an audio versions is not that much of a stretch for me at all! Any fans ending up back here in a year will agree, I promise. You should expect to hear projects, interviews, tutorial-like how-to's, (also original music from the community here in Berlin), all based around potentially vicious, authority-questioning attitude that every beginner, or always-learner will love. (Ok maybe not love, but brutally naive questions will never be off the table!) . For DFIR-related topics, I tend to approach things sometimes from an off-the-wall pov, whether it is a new topic, or just something I've already built a habit around, so I find that others usually find this very helpful, or at least funny. #knowthyself
I'm also busy studying for SANS SEC503 (GCIA) [I hope!], or whichever class I might get accepted to in Berlin on the work study program for SANS, and reading through Professor Mike O'Leary's book with the Brakeing Down Security Podcast's book club. Join us and read along and work on the labs together.
Peace & best wishes goes out to those experiencing the hurricane right now in Texas & across the south. Years from now we will not forget you!

JB's computer forensics blog

In order not to clog up my main Forensics blog:
http://dfir.infosecfeeds.org ---> which redirects to my LinkedIn "Today"

-- To see the more #dfir focused blog see directly https://www.linkedin.com/today/author/cherokeejb --

I started very recently blogging on the LinkedIn platform, although I am not happy with how much of a "gated community" it is.  As a lover of RSS and podcasts, it's a bit ironic that a so-called social site, does not provide integration with these tools by default.  (By the way, speaking of RSS, Aaron, you are not forgotten!)

So, I've started keeping the complete blog here on blogger.com (https://cherokeejb.blogger.com).  This will include off-topic posts, such as me experimenting with basic "red-team tactics," going off-topic about something technical but not computer forensics or incident response-related, or even talking about #familyfirst.  Speaking of family-first... my family is growing! So much later on you might even see posts here that just relate to the infosec-related topics I studied or worked on in the lab, that week, which I didn't think were worthy of putting on the main blog, for whatever reason.

So, I am happy if you subscribe, comment, comment, and comment to help us all grow! ...as I'm hoping in life to always be learning, and be a student of this Earth, as well as everyone in the community and every team that I join.

The first two posts will be "catchup" from what I'd written on LinkedIn already, and then we'll go from there.

All my best wishes,
jb



The following post was originally published at:

https://www.linkedin.com/pulse/infosecfeedsorg-up-planet-security-infosec-podcasts-master-eck-sieben


Piktochart - Phishing with Infographics (Guest diary on Sans Internet Storm center - isc.sans.edu)

Noticed today I'd forgotten to re-post this guest diary I shared to Storm center.    Link to original post ,  My most recent work hasn...

Follow by RSS