By Cobi Aloia, Cofense Phishing Defense Center
Google is generally regarded as a safe space since it offers a variety of services that cater to businesses and individuals across the globe, with the primary service being a search engine. Because of its reputation and wide use, typical antivirus and email security solutions – such as secure email gateways (SEGs) – do not tend to block or limit functionality within Google’s domain since they typically block URLs at the domain or subdomain level. The Cofense Phishing Defense Center (PDC) actively analyzes threats reported by well-conditioned users that bypass SEGs; this has given us insight into how Google Translate is being used to spread crimeware.
Figure 1: Email Body
Figure 2: Phishing Page
Figure 3: Cofense Example
Indicators of Compromise | IP |
hxxps://translate.google[.]com/translate?hl=&sl=auto&tl=en&u=digigage[.]club | 142.250.217.78 |
hxxps://digigage[.]club | 192.64.117.42 |