Time Monday, December 27, 2021 at 1:41 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.88.235
Time Monday, December 27, 2021 at 1:41 PM EST Location São Paulo, SP 01323, BRAZIL IP address 160.116.88.235
LACNIC says the IP range was transferred to AFRINIC. They then say that it is owned by:
Affiliated Computing Services (Pty) Ltd descr: P. O. Box 261333 descr: Excom 2023 country: ZA
But then further note that ownership is in dispute! We need someone to look it up in the current routing tables to see where it's presently being routed to.
Help/insight from ASN? BGP? networking experts would be appreciated..! Thanks a lot
Be very wary of geo-ip results, on the modern internet they are effectively useless.
Geo-ip is a perfect analysis trap, because it seems like it's probably a good idea so people put it into the roadmap. Then they spend forever tracking down all the ways it doesn't work (I bet you have customers in whatever geo you're thinking of blocking, there's a surprising amount of netblocks that are attributed incorrectly, etc), and then the sunk cost fallacy leads them to maintaining their creaky system. Imagine what you could have done with that effort in the meantime.
Now, let's put our badguy hat on. It takes effectively zero time to tell if your target is geo-blocking (compare your port results between several geos, or cheat with censys and shodan). Being blocked? Launch your attack from IP space in another geo. Pro-tip on that: nobody blacklists cloud provider IP space because of VDI solutions. You can migrate between stolen cloud accounts faster than the provider can suspend them, especially for reconnaissance and initial payload delivery.
Edit: see also, renting time on botnets, renting physical colo, compromising residential ISP equipment, and friends.
For the IP posted above, I have 3 providers claiming it's in Sao Paulo, 3 who says it's in Joburg (this is as accurate as anyone's going to get right now) and one says it's in Chicago! If I'm trying to do something with these results programmatically, I don't have a majority or a plurality to pick as a "winner" and I have to try weighting specific providers, which is a whole new mess.
Anyway, there's a good idea brewing in RFC8805 but it'd require pretty much every AS to play along.
My home would routinely show up as from a country a thousand miles away. Friends down the street would show up several states over. Customers I know which were a state over would appear from a different country. The databases are usually right, but they're still often wrong. Often enough to cause frustrations.
[1] https://scamalytics.com/ip/isp/cooperative-investments-llc
https://i.imgur.com/C9HQw1c.png
The full non-clickable URL:
https://us.poonstate.click/us/i/spectrum/?track=u.pslnk.link&key=eyJ0aW1lc3RhbXAiOiIxNjQwNjM4NTIyIiwiaGFzaCI6IjNiZjRkYTg5MTA5MzMzNmU5NjRmMjZiNDY1NWUyN2UwMjk3NzI0OTYifQ%3D%3D&tsid=7ae4766b-0de5-4865-9f1b-025a45c71c3f&bemobdata=c%3D314f53db-f844-46ea-99f8-f277456639d3..l%3Df57d9a37-1c67-4958-ac52-6f4854ce6840..a%3D2..b%3D1..z%3D0.0016..e%3Dzr4b7f4393675711ecb78f122b3efc6f65f31163358f914cea90c49d2c8cc35b7b0612682b8c773fbcf1..c1%3Dwhiskey-oar-eAcMKVvZ..c2%3Dgriseous-trout..c4%3DDOMAIN..c6%3DNON-ADULT..c8%3D1655308..c9%3Dfbb8c5b0-5140-11ec-a217-0aea8b85a94f..c10%3D0#
I went through and answered the "questions", and it tried to take me to the actual phishing site:https://i.imgur.com/wYt5WB3.png
https://i.imgur.com/Picaw4a.png
Screenshots of the actual phishing site
https://i.imgur.com/Bh5c2lZ.png
https://i.imgur.com/q7xnSki.png
https://i.imgur.com/GX4hWnQ.png
And its url (non-clickable):
https://welcome.myonlineeconomy.com/us/238700/25/?pubid=aff-us&pob=3&click_id=61ca28bcf92ca000011aa4c0&subid=RT-60338e1b79fcbe00012195a3-168&utm_medium=mail&utm_term=ipadpro&terms=y&email=&fname=&lname=&fp=&address=&city=&zip=&state=&lpkeyua=a17666fa4eadface9331c0311b1e8875.1640638952
Now, the interesting part is that this phishing attempt only happened once. When I tried to visit again just now, it just says "something went wrong" (on the first site) and "Access denied" (on the second site).I saved the sites to disk as I went, but I doubt these dumps will tell you much. Just in case though:
1. https://gist.github.com/shawwn/4deace812e7c752949a0df096ef66...
2. https://gist.github.com/shawwn/721f235e760dd2257cd760edb1188...
Long story short: It sounds like all of you got phished. I suspect you installed a malicious app that somehow targeted your web browser's LastPass extension, modifying it to send your master password to these fine people. ¯\_(ツ)_/¯
That's quite possible, for sure. I am not beyond/above/below being phished like anyone else, ha!
The issue -- what makes it perplexing -- is that I haven't used this LastPass password since 2017. I know because this LastPass account was only used to share passwords within an org that I left back then.
Is it possible that I was phished 4 years ago, and they sat on the password? Sure.
But 2 other people in this thread being phished from the same exact same phishing server/group?
Or we were separately phished using different techniques, and now one Brazil server attempted to use all of our logins?
That's what's rather strange.
I'm still seeing hackers trying to log on using passwords I haven't used in ~10 years, because it's on a list somewhere.
So LastPass (their extension) may have been hacked ~5 years ago ish, a few people here on the thread were all hacked in the same way, our passwords were sold off, and now the same Brazil IP range just tried all of those passwords.
https://news.ycombinator.com/item?id=29710262
https://news.ycombinator.com/item?id=29711950
That would make "more sense" that our credentials weren't stored and unused for years, i.e. that this is possibly a new, recent breach.
That doesn't mean they didn't try stuffing it elsewhere previously, or have login attempts you weren't notified of.
Nor do you know if the entity responsible for the failed login is the one who originally captured the credentials.
If you'll forgive the wild speculation, your credentials could have been sold recently and the new owners are less picky about alerting victims to the breach.
It could be that a bunch of credentials were captured for a specific purpose. Perhaps it was a targetted attack aiming for a specific victim, you and others here were collateral damage, and now the attacker is selling the assets.
I also generally am more suspicious of the idea that they sat on the credentials for years. Although that is not impossible.
One disproving fact (of sitting on the password for years) is that a few people here in this thread confirm having a login attempt from the exact same ip range, but with an account that was created this year -- in one case, in November 2021:
https://news.ycombinator.com/item?id=29710262
So... it might turn out to be a much more recent vulnerability after all.
I agree that it could be totally unrelated to the root mystery though. But "everyone here fell for malware or got phished" seems like the most likely explanation, even if my answer happens to be otherwise incorrect.
How many extensions are you using again? :-)
“Too many” :)
EditThisCookie was last updated November 22, 2020, so it doesn't seem likely from that.
ublock origin was updated December 2, 2021, but they haven't changed devs or anything that would make me suspicious.