Research
A collection of our research and investigations.
The Risk of Day in the Life
This paper investigates the risks associated with "day in the life" social media videos and their role in facilitating cyber fraud and social engineering attacks. It aims to understand how these seemingly innocuous videos expose sensitive employee credentials, contributing to structured fraudulent campaigns that exploit AI, deepfake technology, and algorithm-driven engagement.
PDF ↗Anatomy of a Sophisticated Phishing Campaign: The usps.otognluguws.top Case Study
The USPS package has arrived at the warehouse and cannot be delivered due to incomplete address information. Please confirm your address in the link within 12 hours.
PDF ↗Likes and Cards: Dissecting Instagram's Algorithm in the Facilitation of Carding Activities
This paper investigates the role of Instagram's algorithm in possibly facilitating the promotion of carding activities. It aims to understand how the proliferation of carding practices can ripple across the digital landscape, affecting consumer trust, financial security, and the integrity of online transactions.
PDF ↗Investigating the IP and Hosting Details of Six Pivotal Phishing Scams
Analysis for one IP and six domains include usp.exprous.com, traci.exprous.com, mo.ctm-1.top, wrm.termsus.com, wrm.exprous.com, and track.termsus.com that mimic the services they impersonate, such as USPS and Walmart, in a complicated yet interesting structure.
PDF ↗Fake USPS Service Scam Using Brazilian Government Domain [urucuia.mg.gov.br]
A comprehensive analysis of a domain that once belonged to the state of Minas Gerais in Brazil, now used in a phishing operation.
PDF ↗Fake USPS Service Scam Using Argentina's Domain [carloslaurenz.com.ar]
This investigation concerns a URL flagged as a phishing operation masquerading as a USPS service.
PDF ↗Phishing Activity Using Fake eBay and USPS Websites Domain Yaraticilikfest[.]anabilim.k12[.]tr
An official Turkish school website is being used in a phishing scam to impersonate USPS and eBay and redirect customers to a Japanese website.
PDF ↗Malicious IP Associated with more than 60 Subdomains: 47.251.33[.]8
The examination reveals the use of an IP address linked to Alibaba Cloud LLC infrastructure, strategically deploying deceptive domains to exploit trust in recognized entities through subtle manipulations of subdomains and top-level domains.
PDF ↗The Dual-Edged Sword of Cloudflare Workers: Leveraging Serverless Computing for Phishing Attacks
This paper explores the architecture of Cloudflare Workers, their legitimate use cases, and how their features can be twisted for phishing, with recommendations for mitigating these threats.
PDF ↗USPS Squatting Campaign - Domain: vxhbs[.]cfd
A package delivery notification lure asking the target to update the delivery address via the provided link.
PDF ↗