Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Aura Over Rafah

Ido Naor
September 08, 2021

Aura Over Rafah

Scams have been spreading rapidly over the wire as financial gain is around the corner for hackers who go after the weakest link - victims. SMShing attacks impersonating the Israeli Post Office took shape and were targeting Israeli residents on a daily basis. Having recieved a shoutout from local security researchers and victims, we decided to dive into a research that will assist law enforcements to capture the individuals behind these attacks. In the slides you could find the result of the research we conducted.

Ido Naor

September 08, 2021
Tweet

More Decks by Ido Naor

Other Decks in Research

Transcript

  1. $>whoami Co-founder & CEO Book writer Black Belt Ex-SpecialOps (IDF)

    BSc Alumni & Lecturer Malware Analyst & Incident Responder Father of 3 CONFidence | Poland | Sept, 2021
  2. WHOIS 10 employees worldwide /Blog Israel Cyber Alliance Responsible Disclosure

    /News Established 2019 Security as a Service CONFidence | Poland | Sept, 2021
  3. Your package is awaiting delivery, we must confirm payment in

    order to process your request The bit.ly shortlink embedded to the message redirects the victim to a phishing website which is highly similar to the original one: hxxps://bit[.]ly/3gipLJX→ postisrael[.]co[.]il (original is israelpost.co.il). CONFidence | Poland | Sept, 2021
  4. Meet Sigal Nadir from Tel Aviv Notice the phone #

    CONFidence | Poland | Sept, 2021
  5. Meet Sigal Nadir from Tel Aviv ?! Notice the phone

    # CONFidence | Poland | Sept, 2021
  6. Yasmine Kamel & Alaa Mohmmed from Palestine Daughter: Janat Tayyem

    It’s who THEY, not who IS CONFidence | Poland | Sept, 2021
  7. Who is Yasmine Alaa from Palestine Full Name: Yesmena Kamel

    (Em Janat) Status: Married + 2 kids Relatives: Tayyem Family Husband: Alaa Mohmmed Location: Rafah, Gaza (husband in UK) CONFidence | Poland | Sept, 2021
  8. Meet cms2be AT gmail.com Belongs to: Alas Tayyam Last Location

    (Aug 21,2021): El-Gharbiya, Israel CONFidence | Poland | Sept, 2021
  9. Evidences Thus Far Website: postisrael[.]com FAKE WHOIS: - Name: Sigal

    Nadir FAKE - Email: cms2be[@]gmail.com -> Alas Tayyam - Phone: +97259.7104.616 -> Yasmine Alaa Facebook: - Name: Yesmena Kamel (Em Janat) - Husband: Mohmmed Alaa - Relatives: Tayyem family CONFidence | Poland | Sept, 2021
  10. Evidences Thus Far Website: postisrael[.]co.il FAKE WHOIS: - Name: Sigal

    Nadir FAKE - Email: cms2be[@]gmail.com -> Alas Tayyam - Phone: +97259.7104.616 -> Yasmine Alaa Facebook: - Name: Yasmena Kamel (Em Janat) - Husband: Mohmmed Alaa - Relatives: Tayyem family CONFidence | Poland | Sept, 2021
  11. It has something to do with PerfDrive[.]com d.createElement(e); a.async =

    true; a.src = u; b = d.getElementsByTagName(e)[0]; b.parentNode.insertBefore(a, b); })(window,document,"script","https://cdn.perfdrive.com/aperture/apertur e.js","bhkl","ssConf"); ssConf("c1" , "https://israelpost.co.il"); CONFidence | Poland | Sept, 2021
  12. Perfdrive is ShieldSquare, acquired by Radware d.createElement(e); a.async = true;

    a.src = u; b = d.getElementsByTagName(e)[0]; b.parentNode.insertBefore(a, b); })(window,document,"script","https://cdn.perfdrive.com/aperture/apertur e.js","bhkl","ssConf"); ssConf("c1" , "https://israelpost.co.il"); CONFidence | Poland | Sept, 2021
  13. So, it’s an anti-scraping script. The Base64 string fingerprints visitors!

    Let’s test our VM address… SUCCESS! CONFidence | Poland | Sept, 2021
  14. That means that if we have front-end code of the

    attacker – containing data he left behind… What we have here is… THE IP OF THE ATTACKER’S MACHINE! CONFidence | Poland | Sept, 2021
  15. Evidences Thus Far Website: postisrael[.]co.il FAKE Website: israelsecurityupdate[.]co.il FAKE Source

    code: - Arabic language in filenames - Another phone: +97256.720.0653 -> Alaa Tim - IP Address: 46.60.67.250 (from Palestine) WHOIS: - Name: Sigal Nadir FAKE - Email: cms2be[@]gmail.com -> Alas Tayyam - Phone: +97259.7104.616 -> Yasmine Alaa Facebook: - Name: Yasmena Kamel (Em Janat) - Husband: Mohmmed Alaa - Relatives: Tayyem family CONFidence | Poland | Sept, 2021
  16. Your package is awaiting delivery, we must confirm payment in

    order to process your request The bit.ly shortlink embedded to the message redirects the victim to a phishing website which is highly similar to the original one: hxxps://bit[.]ly/3gipLJX→ postisrael[.]co[.]il (original is israelpost.co.il). CONFidence | Poland | Sept, 2021