{"id":2174,"date":"2021-07-25T18:10:33","date_gmt":"2021-07-25T18:10:33","guid":{"rendered":"https:\/\/osintme.com\/?p=2174"},"modified":"2021-07-25T18:12:25","modified_gmt":"2021-07-25T18:12:25","slug":"another-new-phishing-campaign-against-bank-of-ireland-customers","status":"publish","type":"post","link":"https:\/\/osintme.com\/index.php\/2021\/07\/25\/another-new-phishing-campaign-against-bank-of-ireland-customers\/","title":{"rendered":"Another new phishing campaign against Bank of Ireland customers"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"2174\" class=\"elementor elementor-2174\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7785060 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"7785060\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-d237d73\" data-id=\"d237d73\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-bc64883 elementor-widget elementor-widget-text-editor\" data-id=\"bc64883\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Quick Sunday evening threat research: this feels like a bit of a deja vu &#8211; or maybe it&#8217;s a seasonal thing &#8211; last year, nearly exactly to the day, I wrote about a <a href=\"https:\/\/osintme.com\/index.php\/2020\/07\/18\/new-phishing-campaign-aimed-at-bank-of-ireland-users\/\">phishing campaign targeting Bank of Ireland users<\/a>.<\/p><p>In an uncanny coincidence, a very similar, new phishing campaign just launched.<\/p><p>Malicious SMS messages are being sent from a spoofed BOI number, containing a link to a domain hosted in Ukraine on IP address <a href=\"https:\/\/talosintelligence.com\/reputation_center\/lookup?search=91.214.124.119\">91.214.124.119<\/a> &#8211; created today&#8230;<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-55daa07 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"55daa07\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-b8baa8a\" data-id=\"b8baa8a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-0bde45c elementor-widget elementor-widget-image\" data-id=\"0bde45c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"300\" height=\"183\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/IMG_3404.jpg?fit=300%2C183&amp;ssl=1\" class=\"attachment-medium size-medium wp-image-2176\" alt=\"Bank of Ireland phishing OSINT\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/IMG_3404.jpg?w=828&amp;ssl=1 828w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/IMG_3404.jpg?resize=300%2C183&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/IMG_3404.jpg?resize=768%2C468&amp;ssl=1 768w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2cd8fbc elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2cd8fbc\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-607dcc7\" data-id=\"607dcc7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c312271 elementor-widget elementor-widget-text-editor\" data-id=\"c312271\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The link won&#8217;t open on a desktop browser as the website appears to conduct user agent validation only allowing access to mobile devices.<\/p><p>For the same reason, it also evades detection and scanning with urlscan&#8230;<\/p><p>But good old VirusTotal still detects it:<\/p><p><a href=\"https:\/\/www.virustotal.com\/gui\/url\/e8a9278d2a9df81b65ebf7174e7517830b4fe280f12d6006253749da8c2ba723\/detection\">https:\/\/www.virustotal.com\/gui\/url\/e8a9278d2a9df81b65ebf7174e7517830b4fe280f12d6006253749da8c2ba723\/detection<\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-8f2022f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"8f2022f\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-b2ef76d\" data-id=\"b2ef76d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-72c8589 elementor-widget elementor-widget-image\" data-id=\"72c8589\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"768\" height=\"701\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/Bank-of-Ireland-phishing-OSINT-2.png?fit=768%2C701&amp;ssl=1\" class=\"attachment-medium_large size-medium_large wp-image-2178\" alt=\"Bank of Ireland phishing OSINT 2\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/Bank-of-Ireland-phishing-OSINT-2.png?w=912&amp;ssl=1 912w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/Bank-of-Ireland-phishing-OSINT-2.png?resize=300%2C274&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/Bank-of-Ireland-phishing-OSINT-2.png?resize=768%2C701&amp;ssl=1 768w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-64148c0 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"64148c0\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-df7b9ed\" data-id=\"df7b9ed\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-32f51b1 elementor-widget elementor-widget-image\" data-id=\"32f51b1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"423\" height=\"266\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/Bank-of-Ireland-phishing-OSINT-3.png?fit=423%2C266&amp;ssl=1\" class=\"attachment-large size-large wp-image-2179\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/Bank-of-Ireland-phishing-OSINT-3.png?w=423&amp;ssl=1 423w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/Bank-of-Ireland-phishing-OSINT-3.png?resize=300%2C189&amp;ssl=1 300w\" sizes=\"(max-width: 423px) 100vw, 423px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-8f18d77 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"8f18d77\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-f97393d\" data-id=\"f97393d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-4897867 elementor-widget elementor-widget-text-editor\" data-id=\"4897867\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The same IP address hosts two more similar phishing websites:<\/p><ul><li>boi-authie[.]com<\/li><li>online365-boi[.]com<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-25d26b2 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"25d26b2\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-3d2b36a\" data-id=\"3d2b36a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-7c7f82c elementor-widget elementor-widget-text-editor\" data-id=\"7c7f82c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>A quick scan with Shodan reveals a total of <a href=\"https:\/\/www.shodan.io\/search\/facet?query=ip%3A91.214.124.119&amp;facet=port\">15 open ports<\/a> &#8211; some of which allow direct connection to control panels for the fraudulent domains &#8211; not what you would expect to see on a legitimate Bank of Ireland domain, right?<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2b90c01 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2b90c01\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-48394c5\" data-id=\"48394c5\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-2bc8be9 elementor-widget elementor-widget-image\" data-id=\"2bc8be9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"641\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/22.png?fit=1024%2C641&amp;ssl=1\" class=\"attachment-large size-large wp-image-2180\" alt=\"Bank of Ireland phishing OSINT 4\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/22.png?w=1202&amp;ssl=1 1202w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/22.png?resize=300%2C188&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/22.png?resize=1024%2C641&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/22.png?resize=768%2C480&amp;ssl=1 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b5e16ab elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b5e16ab\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-07c8419\" data-id=\"07c8419\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9e549a5 elementor-widget elementor-widget-image\" data-id=\"9e549a5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"633\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/23.png?fit=1024%2C633&amp;ssl=1\" class=\"attachment-large size-large wp-image-2181\" alt=\"Bank of Ireland phishing OSINT 5\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/23.png?w=1220&amp;ssl=1 1220w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/23.png?resize=300%2C185&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/23.png?resize=1024%2C633&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/23.png?resize=768%2C475&amp;ssl=1 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-5279b79 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5279b79\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-9c2ef75\" data-id=\"9c2ef75\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-8ef64e8 elementor-widget elementor-widget-text-editor\" data-id=\"8ef64e8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The IP address belongs to a Hong Kong hosting provider Eranet.<\/p><p>Their email address for reporting abuse is support(at)tnet.hk &#8211; going to send this article to them now and hopefully this fraudulent operation is taken down promptly.<\/p><p>\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Reporting the new Bank of Ireland phishing campaign that initiated literally hours ago.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[18],"tags":[103,76,82,81,79],"class_list":["post-2174","post","type-post","status-publish","format-standard","hentry","category-digital-privacy-security","tag-bank-of-ireland","tag-cybercrime","tag-phishing","tag-scam","tag-website"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/2174","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/comments?post=2174"}],"version-history":[{"count":10,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/2174\/revisions"}],"predecessor-version":[{"id":2190,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/2174\/revisions\/2190"}],"wp:attachment":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/media?parent=2174"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/categories?post=2174"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/tags?post=2174"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}