chartingshow / crypto-firewall

🎁 Blocks browser-based crypto mining, cryptojacking, banking and crypto malware and phishing websites, apps and hackers command-and-control (C2) servers.
GNU General Public License v3.0
7 stars 0 forks source link

Block `Rilide Stealer` a banking and crypto drainer malware #473

Closed summercms closed 3 months ago

summercms commented 3 months ago

Enhancement idea

Description

We have identified campaigns in the wild which we will examine in detail:

During the investigation of Rilide's related domains and associated IP addresses, we discovered over 1,300 phishing websites impersonating various entities, including banks, government services, software companies, delivery services, and crypto token airdrops. Among these websites, several were found to be distributing harmful malware like BumbleBee, IceID or Phorpiex.

image

Targeting Summary

Links

https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/new-rilide-stealer-version-targets-banking-data-and-works-around-google-chrome-manifest-v3/

IOC

I2P websites

n/a

IPFS websites

n/a

Tor2web websites

n/a

TOR websites

n/a

URL's

n/a

Folders

n/a

Sub-Domains

n/a

Domains

bnbcoinstatic.com
blackfox.lol
eaougheofhuoaez.top
edd2ed2.online
ext-panel.website
extension-login.com
extensionsupdate.com
faugzeazdezgzgfm.top
frz-panel.su
getvoyagebox.org
hdoki.org
io-web.cc
lsadksajpenal.su
nightpredators.com
proyectopatentadomxapostol.com
pupkalazalupka.com
riotrevelry.com
silent-scale.com
tes123123t.com
web-lox.com

IP's

176.111.174.241
185.215.113.66
185.215.113.84
47.253.58.100
78.128.112.218
80.66.79.97
91.215.85.14

ASN's

n/a

Emails

n/a

Wallet addresses

n/a

Mining pool addresses

n/a