Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Zip domains are being abused again to trick victims into a phishing scam

  • May 30, 2023
Total
0
Shares
0
0
0


Not even a month has passed since Google first started offering .zip internet domains, and people have already found a clever and creative way to abuse it for malware distribution.

The scam revolves around turning the web browser window into a fake WinZip or WinRAR instance and tricking the victim into believing they’re opening a legitimate file archive while, in reality, they’re downloading malware.

Researcher mr.dox outlined how a threat actor registers a new domain, for example, “setup.zip”. It looks like an archive for an installer file. Then, they create the website to mimic the look and feel of WinRAR – the file path is there, the icons are there, everything looks legitimate. To add even more credibility to the scam, the attackers can also create a fake antivirus scan popup, informing the victim that the files in the archive were scanned and no threats were found.

A website, or an archive?

The researcher who came up with the method claims this phishing kit can be used in attacks such as malware distribution, or credential theft. A victim could end up double-clicking on a fake PDF file in the fake WinRAR window and be redirected to a fake login page which could steal their login information.

The fake PDF file can also be used to trigger a file download, tricking the victim into downloading malware. 

BleepingComputer also reminds that the way latest Windows versions search for files can also be abused. When a person types a file name into the search bar, the operating system will first search through local storage, but if it doesn’t find anything, it will try to open the query in a browser. If there is a legitimate domain of the same name, it will be opened in the browser. 

“This technique illustrates how ZIP domains can be abused to create clever phishing attacks and malware delivery or credential theft,” the publication concludes. 

Via: BleepingComputer


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

Samsung Galaxy S23 FE: latest news, rumors, and everything we know so far

  • May 30, 2023
View Post
Next Article
  • Technology

UpCodes launches Copilot, an AI-based research assistant for building codes

  • May 30, 2023
View Post
You May Also Like
View Post
  • News

Quordle today – hints and answers for Friday, September 22 (game #606)

  • September 22, 2023
View Post
  • News

The Pixel Fold is now almost entirely repairable as spare parts appear on iFixit

  • September 22, 2023
View Post
  • News

Asus sells the largest microLED monitor ever for a cool $200,000 — but it’s only 4K and a low refresh rate

  • September 21, 2023
View Post
  • News

Facebook now lets you create alt accounts for better privacy and organization

  • September 21, 2023
View Post
  • News

The world’s most famous magician invests in data storage startup that wants to send 100GB disks to the Moon for future humanoids

  • September 21, 2023
View Post
  • News

YouTube reveals powerful new AI tools for content creators – and we’re scared, frankly

  • September 21, 2023
View Post
  • News

CEO of DuckDuckGo Testifies in Google Case

  • September 21, 2023
View Post
  • News

Windows Copilot might be the biggest change Microsoft has ever made to its long-running OS

  • September 21, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.