
1/27/2021 · Elaine Dzuba
What this post added
This post details a specific phishing campaign that exploited concerns over COVID-19 vaccine availability. It analyzes the attacker's techniques, including display name spoofing, SMTP HELO command manipulation, the use of domains without email authentication protocols, and the compromise of legitimate IPs. The post also examines the phishing website's infrastructure, including the use of newly registered domains (NRDs) and cPanel, and the process.php script used to exfiltrate victim data. It highlights how these advanced techniques bypassed traditional defenses like Microsoft Office 365's native filters, necessitating more sophisticated detection methods.