Website Security & Threat Management
Latest SBA phishing attempt: stealthy social engineering phish using newly registered domains attempts to gain bank details

Latest SBA phishing attempt: stealthy social engineering phish using newly registered domains attempts to gain bank details

9/9/2020 · Elaine Dzuba

What this post added

This post details a sophisticated phishing campaign impersonating the US Small Business Administration (SBA) to steal financial details. It highlights the use of newly registered domains (NRDs), spoofed sender addresses, and a seemingly legitimate PDF form to trick victims. The analysis includes technical details on email header manipulation (HELO command), NRD registration information, and the PDF's creation properties (Skia engine) as indicators of compromise. The post also outlines Area 1 Security's (now Cloudflare) advanced techniques for detecting such threats, including analysis of NRDs, domain obfuscation, look-alike domains, lexical analysis, and header validation (SPF, DKIM, DMARC). Recommendations are provided for users to protect themselves from SBA-themed phishing attacks.

Read the original post ↗