<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>credential harvesting detection - osintafrica</title>
	<atom:link href="https://www.osintafrica.net/tag/credential-harvesting-detection/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.osintafrica.net</link>
	<description>intelligency blog</description>
	<lastBuildDate>Sun, 04 Aug 2024 20:44:34 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.2</generator>

<image>
	<url>https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=32%2C32&#038;ssl=1</url>
	<title>credential harvesting detection - osintafrica</title>
	<link>https://www.osintafrica.net</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">221010672</site>	<item>
		<title>New update in URLSCAN to detect malicious domains</title>
		<link>https://www.osintafrica.net/new-update-in-urlscan-to-detect-malicious-domains/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-update-in-urlscan-to-detect-malicious-domains</link>
		
		<dc:creator><![CDATA[Bangaly Koita]]></dc:creator>
		<pubDate>Sun, 04 Aug 2024 20:43:56 +0000</pubDate>
				<category><![CDATA[Main News]]></category>
		<category><![CDATA[credential harvesting analysis]]></category>
		<category><![CDATA[credential harvesting detection]]></category>
		<category><![CDATA[HTTP POST request detection based]]></category>
		<category><![CDATA[maldomains]]></category>
		<category><![CDATA[urlscan]]></category>
		<guid isPermaLink="false">https://www.osintafrica.net/?p=838</guid>

					<description><![CDATA[<p>If you are following our blog Home Home &#8211; osintafrica, you already know the tool...</p>
<p>The post <a href="https://www.osintafrica.net/new-update-in-urlscan-to-detect-malicious-domains/">New update in URLSCAN to detect malicious domains</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></description>
										<content:encoded><![CDATA[<p><span style="color: #000000;">If you are following our blog</span> <a href="https://www.osintafrica.net/">Home Home &#8211; osintafrica</a>, <span style="color: #000000;">you already know the tool</span> <a href="https://urlscan.io/">URL and website scanner &#8211; urlscan.io</a>, <span style="color: #000000;">click on</span>  <a href="https://www.osintafrica.net/how-to-use-urlscan-part1/">https://www.osintafrica.net/how-to-use-urlscan-part1/</a> <span style="color: #000000;">for more details.</span></p>
<p><span style="color: #000000;">The best tools always need improvement and urlscan.io is one of those. The tool has done some improvements that can help an Analyst to perform faster and more efficiently the investigation on phishing website mimicking an organization.</span></p>
<p><span style="color: #000000;">Let’s have a look at the new improvements.</span></p>
<p><span style="color: #000000;">The tool introduced two great features (<strong>Favicon hash detection based and the HTTP post request detection</strong>) which can be used to detect <strong>phishing website mimicking</strong> an organization and <strong>credentials harvesting domain</strong>.</span></p>
<p><span style="color: #000000;">To better understand that, lets practice a bit.</span></p>
<p><span style="color: #000000;"><strong>Detecting a website mimicking Netflix using the FAVICON HASH ANALYSIS </strong></span></p>
<p><span style="color: #000000;">A Favicon is the website icon, it helps to visually represent a website and to distinguish between open tabs or search results.</span></p>
<p><span style="color: #000000;">A favicon contains a hash, a hash of a favicon can be used to detect similar website.</span></p>
<p><span style="color: #000000;">The feature has been introduced into urlscan.io to make it easier for the Analyst to quickly perform his or her investigation.</span></p>
<p><span style="color: #000000;"><strong>Example 1:</strong></span></p>
<p><span style="color: #000000;">We will connect to <strong>urlscan.io</strong> and use a domain mimicking <strong>NETFLIX website</strong>, we will use the <strong>favicon hash</strong> to find similar website.</span></p>
<p><span style="color: #000000;">Let’s do it.</span></p>
<p><strong><span style="color: #000000;">Connect to</span> </strong><a href="https://urlscan.io/result/fb90e947-db87-4476-924d-5db678a50acd/#transactions">https://urlscan.io/result/fb90e947-db87-4476-924d-5db678a50acd/#transactions</a></p>
<p><span style="color: #000000;">Click on the <strong>“HTTP”</strong> button in blue, type (crtl F &#8211; favicon), scroll down, click on the hash and open in a new tab, you will see the result. </span></p>
<p><img data-recalc-dims="1" fetchpriority="high" decoding="async" class="alignnone wp-image-839 size-large" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-new-update.png?resize=640%2C193&#038;ssl=1" alt="" width="640" height="193" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-new-update.png?resize=1024%2C308&amp;ssl=1 1024w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-new-update.png?resize=300%2C90&amp;ssl=1 300w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-new-update.png?resize=768%2C231&amp;ssl=1 768w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-new-update.png?resize=1536%2C463&amp;ssl=1 1536w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-new-update.png?w=1816&amp;ssl=1 1816w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-new-update.png?w=1280&amp;ssl=1 1280w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<p>Example 2:  <strong>Detect website mimicking Microsoft.com.</strong></p>
<p><a href="https://urlscan.io/result/b4cf2f17-ebee-47b4-b85e-f63eae623ec4/#transactions">https://urlscan.io/result/b4cf2f17-ebee-47b4-b85e-f63eae623ec4/#transactions</a></p>
<p><img data-recalc-dims="1" decoding="async" class="alignnone size-large wp-image-840" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-2.png?resize=640%2C219&#038;ssl=1" alt="" width="640" height="219" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-2.png?resize=1024%2C350&amp;ssl=1 1024w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-2.png?resize=300%2C102&amp;ssl=1 300w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-2.png?resize=768%2C262&amp;ssl=1 768w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-2.png?resize=1536%2C525&amp;ssl=1 1536w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-2.png?w=1827&amp;ssl=1 1827w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-2.png?w=1280&amp;ssl=1 1280w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<p><span style="color: #000000;">click on the hash and open in a new tab, you will see the result. </span></p>
<p><span style="color: #000000;"><strong> </strong></span></p>
<p><span style="color: #000000;"><strong>Detecting a credential harvesting domain using HTTP POST request detection based. </strong></span></p>
<p>&nbsp;</p>
<p><span style="color: #000000;">A <strong>credentials harvest</strong> is when a threat actor sends a phishing link to user, once the user clicks and enters his/her credentials, the credentials will be sent to another domain, where they will be stored by the threat actor which will be used to impersonate the user or sell via the Dark web. This technic is commonly used against organizations that use the cloud as a service such as Microsoft O365</span></p>
<p><span style="color: #000000;">Let’s give an example, we have detected a maldomain mimicking Microsoft login, when a user enters the credentials, the credentials will be sent to</span> <a href="https://robertreed1313.xyz/next.php">hxxps://robertreed1313[.]xyz/next.php</a></p>
<p><span style="color: #000000;">Click on the link:</span></p>
<p><a href="https://urlscan.io/result/e25dc1e1-9ab7-491c-94a8-20aec6eba2d8/#transactions">https://urlscan.io/result/e25dc1e1-9ab7-491c-94a8-20aec6eba2d8/#transactions</a></p>
<p><img data-recalc-dims="1" decoding="async" class="alignnone size-large wp-image-841" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-3.png?resize=640%2C201&#038;ssl=1" alt="" width="640" height="201" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-3.png?resize=1024%2C321&amp;ssl=1 1024w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-3.png?resize=300%2C94&amp;ssl=1 300w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-3.png?resize=768%2C241&amp;ssl=1 768w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-3.png?resize=1536%2C482&amp;ssl=1 1536w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-3.png?w=1797&amp;ssl=1 1797w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-3.png?w=1280&amp;ssl=1 1280w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<p><span style="color: #000000;">As you see in the image, there is “HTTP POST” request which is an indication of data being sent to another URL  in this case</span> (<a href="https://robertreed1313.xyz/next.php">hxxps://robertreed1313[.]xyz/next.php</a>)</p>
<p><span style="color: #000000;">Let’s give another example to better understand it.</span></p>
<p><span style="color: #000000;">Another maldomian mimicking Microsoft login website:</span></p>
<p><a href="https://urlscan.io/result/3c37d73b-3f5c-4e09-a992-1bb996e75a95/#summary">fattykins.za.com &#8211; urlscan.io</a></p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone size-large wp-image-842" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-4.png?resize=640%2C186&#038;ssl=1" alt="" width="640" height="186" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-4.png?resize=1024%2C298&amp;ssl=1 1024w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-4.png?resize=300%2C87&amp;ssl=1 300w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-4.png?resize=768%2C223&amp;ssl=1 768w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-4.png?w=1138&amp;ssl=1 1138w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<p><span style="color: #000000;">Let’s show the last example</span></p>
<p><a href="https://urlscan.io/result/193192b1-b665-4a69-a1e3-89522038572d/#transactions">ron-marom12.github.io &#8211; urlscan.io</a></p>
<p><span style="color: #000000;">Maldomain mimicking Netflix website login.</span></p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone size-large wp-image-843" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-5.png?resize=640%2C202&#038;ssl=1" alt="" width="640" height="202" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-5.png?resize=1024%2C323&amp;ssl=1 1024w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-5.png?resize=300%2C95&amp;ssl=1 300w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-5.png?resize=768%2C242&amp;ssl=1 768w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-5.png?w=1188&amp;ssl=1 1188w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<p><span style="color: #000000;">NB: Be careful while checking the domains, always check with Virustotal and check if the domain is newly created before making a decision.</span></p>
<p>&nbsp;</p>
<p><span style="color: #000000;"><strong>Do you know that we can use URLSCAN to find maldomains or typo squatting domains mimicking our organization? </strong></span></p>
<p><span style="color: #000000;">We will try to find domains name similar to Microsoft.com</span></p>
<p><span style="color: #000000;">Connect to urlscan.io, go to search – type: page.domain:( page.domain:(microsoft.com~ AND NOT microsoft.com))</span></p>
<p><a href="https://urlscan.io/search/#page.domain%3A(microsoft.com~%20AND%20NOT%20microsoft.com)">Search &#8211; urlscan.io</a></p>
<p><img data-recalc-dims="1" loading="lazy" decoding="async" class="alignnone size-large wp-image-845" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-6.png?resize=640%2C309&#038;ssl=1" alt="" width="640" height="309" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-6.png?resize=1024%2C495&amp;ssl=1 1024w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-6.png?resize=300%2C145&amp;ssl=1 300w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-6.png?resize=768%2C371&amp;ssl=1 768w, https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2024/08/urlscan-6.png?w=1129&amp;ssl=1 1129w" sizes="(max-width: 640px) 100vw, 640px" /></p>
<p><span style="color: #000000;">Like you see, URLSCAN has improved a lot; by using the tool, you can save a lot of times during your investigation. Feel free to start using the tool</span> <a href="https://urlscan.io/">https://urlscan.io/</a>.</p>
<p>&nbsp;</p>
<div class="saboxplugin-wrap" itemtype="http://schema.org/Person" itemscope itemprop="author"><div class="saboxplugin-tab"><div class="saboxplugin-gravatar"><img loading="lazy" decoding="async" src="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=100%2C100&#038;ssl=1" srcset="https://i0.wp.com/www.osintafrica.net/wp-content/uploads/2023/05/cropped-osintafrica-1.jpg?fit=200%2C200&#038;ssl=1 2x" width="100" height="100" alt="Bangaly Koita" class="avatar avatar-100 wp-user-avatar wp-user-avatar-100 photo avatar-default" /></div><div class="saboxplugin-authorname"><a href="https://www.osintafrica.net/author/admin/" class="vcard author" rel="author"><span class="fn">Bangaly Koita</span></a></div><div class="saboxplugin-desc"><div itemprop="description"><p>Bangaly Koita is a SOC Analyst and  Cyber Security researcher . As a passionate in cyber security,  he spends most of the time  writing articles and making videos online to share his knowledge and experience to the vast community of IT but in general Cyber Security. Feel free to contact me in case.</p>
</div></div><div class="saboxplugin-web "><a href="https://osintafrica.net" target="_self" >osintafrica.net</a></div><div class="clearfix"></div><div class="saboxplugin-socials "><a title="Linkedin" target="_blank" href="https://www.linkedin.com/in/bangaly-koita-68b8b912a/" rel="nofollow noopener" class="saboxplugin-icon-grey"><svg aria-hidden="true" class="sab-linkedin" role="img" xmlns="http://www.w3.org/2000/svg" viewbox="0 0 448 512"><path fill="currentColor" d="M100.3 480H7.4V180.9h92.9V480zM53.8 140.1C24.1 140.1 0 115.5 0 85.8 0 56.1 24.1 32 53.8 32c29.7 0 53.8 24.1 53.8 53.8 0 29.7-24.1 54.3-53.8 54.3zM448 480h-92.7V334.4c0-34.7-.7-79.2-48.3-79.2-48.3 0-55.7 37.7-55.7 76.7V480h-92.8V180.9h89.1v40.8h1.3c12.4-23.5 42.7-48.3 87.9-48.3 94 0 111.3 61.9 111.3 142.3V480z"></path></svg></span></a></div></div></div><p>The post <a href="https://www.osintafrica.net/new-update-in-urlscan-to-detect-malicious-domains/">New update in URLSCAN to detect malicious domains</a> first appeared on <a href="https://www.osintafrica.net">osintafrica</a>.</p>]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">838</post-id>	</item>
	</channel>
</rss>
