Kali365 Targets US Organizations with Data Theft via Device Code Phishing
Kali365 is a device code phishing kit targeting US organizations by abusing legitimate Microsoft and Google device authentication flows. Instead of capturing passwords on fake login pages, the kit directs victims to authentic Microsoft/Google device login pages where they enter attacker-provided codes, granting attackers OAuth access and refresh tokens. The phishkit supports 34 lure templates across multiple brands and exposes identifiable API endpoints (/api/generate, /api/lure-config, /api/status) that can be used for detection.
- domainbluefoodtruths[.]xyzKali365 phishing domain listed in related IOCs
- domainbrandintegrityhub[.]deKali365 phishing domain observed in TI Lookup with subdomains pgiwcpb3t4 and bs6k39jv72
- domainbrandswithintegrity[.]deKali365 phishing domain listed in related IOCs
- domainbrandtrustmasters[.]deKali365 phishing domain listed in related IOCs; subdomain xyodqs6fye.brandtrustmasters.de observed in TI Lookup
- domainbuildyouronlineidentity[.]deKali365 phishing domain listed in related IOCs
- domainbusinesssafetysolutions[.]deKali365 phishing domain observed in TI Lookup with subdomains cpmmi4mmc6 and di3l4gdy04
- domaincloud-microsoft-drive-for-business[.]workers[.]devCloudflare Workers domain impersonating Microsoft OneDrive for Business, used as Kali365 phishing infrastructure
- domaincreatesimpact[.]deKali365 phishing domain observed in TI Lookup with subdomain gyduwj1m1f
- domaincustomertrustservices[.]deKali365 phishing domain observed in TI Lookup with subdomain c44op45gyb
- domaindecidewithsecurity[.]deKali365 phishing domain observed in TI Lookup with subdomain hiqdy7k61a
- domaindewdhurstlobl[.]comKali365 phishing domain listed in related IOCs; subdomain urjnwwndtg.dewdhurstlobl.com observed serving active phishing page
- domaindigitalfoundationstability[.]deKali365 phishing domain observed in TI Lookup with subdomain eczob0ub46
- domainflexievolve[.]deKali365 phishing domain listed in related IOCs
- domainflexiscalesystems[.]deKali365 phishing domain hosting multiple lure subdomains (e.g., leildsdlg1.flexiscalesystems.de)
- domainfunctionalityfirst[.]deKali365 phishing domain listed in related IOCs; subdomain a0ohccrq5l.functionalityfirst.de observed in TI Lookup
- domainguardedwebsolutions[.]deKali365 phishing domain listed in related IOCs
- domainguardextion[.]onlineKali365 phishing domain listed in related IOCs section
- domainguardwebsolutions[.]deKali365 phishing domain listed in related IOCs
- domainhbaknoxvillecom[.]topKali365 phishing domain listed in related IOCs
- domaininteractionsoptimized[.]deKali365 phishing domain observed in TI Lookup with subdomain ml9zcrj2rq
- domainloyaltydrivenbyquality[.]deKali365 phishing domain observed in TI Lookup with subdomain Kext4t75yf
- domainloyaltythroughservice[.]deKali365 phishing domain observed in TI Lookup with subdomain 3rme70pcpo
- domainmarketadaptabletech[.]deKali365 phishing domain listed in related IOCs
- domainmodernecosystemhub[.]deKali365 phishing domain observed in TI Lookup with subdomain b5qs2htv4s
- domainmodernwebbalance[.]deKali365 phishing domain listed in related IOCs
- domainna2[.]hubsy[.]lyPhishing domain observed in ANY.RUN TI Lookup results associated with phishing URL https://na2.hubsy.ly/H06yWWs0
- domainnavigatingdigitalchange[.]deKali365 phishing domain listed in related IOCs
- domainonlinebrandinghub[.]deKali365 phishing domain listed in related IOCs
- domainonlineidentityhub[.]deKali365 phishing domain observed in TI Lookup with subdomain 88rhpce52g
- domainonlineidentityperfection[.]deKali365 phishing domain listed in related IOCs; subdomain ea2oq4imx9.onlineidentityperfection.de observed in TI Lookup
- domainonsite-developments[.]netKali365 phishing domain listed in related IOCs
- domainoutcomesbydesign[.]deKali365 phishing domain observed in TI Lookup with subdomain zht08qprj5
- domainperformancereputation[.]deKali365 phishing domain listed in related IOCs
- domainproforcstaffing[.]comKali365 phishing domain listed in related IOCs section
- domainprowebsitemakers[.]deKali365 phishing domain listed in related IOCs
- domainpub-bb2e103a32db4e198524a2e9ed8f35b4[.]r2[.]devCloudflare R2 development domain abused as Kali365 phishing infrastructure, observed in TI Lookup results
- domainqualityfirstonline[.]deKali365 phishing domain listed in related IOCs; subdomain ze1im3fd2b.qualityfirstonline.de observed serving active phishing page
- domainreliablebusinesstech[.]deKali365 phishing domain listed in related IOCs; subdomain jc1wjhjoy4.reliablebusinesstech.de observed in TI Lookup
- domainreliableinnovation[.]deKali365 phishing domain observed in TI Lookup with subdomain qjmvg27le1
- domainreliableperformance[.]deKali365 phishing domain observed in TI Lookup with subdomain 3blxay3rto
- domainreputationboosters[.]deKali365 phishing domain listed in related IOCs
- domainscalableadapt[.]deKali365 phishing domain listed in related IOCs
- domainsdnbbd[.]infoPhishing domain observed in ANY.RUN TI Lookup results associated with phishing file hash 482BEA1EFB446651FFE543BA4FF459A59F6A295FC2913ED188906E22F16A0400
- domainsecuredecisionmakers[.]deKali365 phishing domain listed in related IOCs
- domainsecuredecisionmaking[.]deKali365 phishing domain listed in related IOCs; subdomain 9vzkt2bl18.securedecisionmaking.de observed in TI Lookup
- domaintechnologyfortrust[.]deKali365 phishing domain observed in TI Lookup with subdomain zvcsursrhh
- domaintheconsistencyfactor[.]deKali365 phishing domain listed in related IOCs; subdomain s6gfswtisn.theconsistencyfactor.de observed in TI Lookup
- domaintrustinbrands[.]deKali365 phishing domain listed in related IOCs
- domainturnideastoresults[.]deKali365 phishing domain listed in related IOCs
- domaintxatvrk[.]netKali365 phishing domain listed in related IOCs
- domainurjnwwndtg[.]dewdhurstlobl[.]comKali365 phishing subdomain observed in sandbox session serving lure page with device code BZBJZ2Y7B
- domainuserfriendlyinterface[.]deKali365 phishing base domain; subdomain w5w0trvg0w.userfriendlyinterface.de observed serving SharePoint lure
- domainuserjourneyguide[.]deKali365 phishing domain observed in TI Lookup with subdomain 4no9yhy5i6
- domainw5w0trvg0w[.]userfriendlyinterface[.]deKali365 phishing subdomain serving SharePoint-themed lure page that initiates device code phishing flow
- domainwaschmaschinenmarkt[.]deKali365 phishing domain listed in related IOCs
- domainwellpults[.]comKali365 phishing domain listed in related IOCs
- domainze1im3fd2b[.]qualityfirstonline[.]deKali365 phishing subdomain observed in sandbox session serving lure page with device code ELTQSTVRD
- ip188[.]114[.]96[.]3IP address hosting Kali365 phishing page at w5w0trvg0w.userfriendlyinterface.de, observed in sandbox network connections
- sha256482bea1efb446651ffe543ba4ff459a59f6a295fc2913ed188906e22f16a0400SHA256 hash of phishing content served from https://sdnbbd.info/, observed in ANY.RUN TI Lookup
- sha2565ee10aef46e89bfed08f90abb73d48602d73b5b416ef448d9ecec0d96405d41eSHA256 hash of phishing content served from https://sites.google.com/view/icsshipping/home, observed in ANY.RUN TI Lookup
- urlhxxps://na2[.]hubsy[.]ly/H06yWWs0Phishing URL observed in ANY.RUN TI Lookup results
- urlhxxps://sdnbbd[.]info/Phishing URL observed in ANY.RUN TI Lookup results; associated file hash 482BEA1EFB446651FFE543BA4FF459A59F6A295FC2913ED188906E22F16A0400
- urlhxxps://simplebooklet[.]com/doc01931241174Phishing URL observed in ANY.RUN TI Lookup results abusing legitimate simplebooklet.com platform
- urlhxxps://sites[.]google[.]com/view/icsshipping/homePhishing URL observed in ANY.RUN TI Lookup results; associated file hash 5EE10AEF46E89BFED08F90ABB73D48602D73B5B416EF448D9ECEC0D96405D41E
- urlhxxps://s[.]surveyplanet[.]com/e9pvncusPhishing URL observed in ANY.RUN TI Lookup results abusing legitimate surveyplanet.com platform
- urlhxxps://urjnwwndtg[.]dewdhurstlobl[.]com/l/nZA-5LCJh-0Active Kali365 phishing URL serving lure page with device code BZBJZ2Y7B
- urlhxxps://w5w0trvg0w[.]userfriendlyinterface[.]de/l/RpOCyuLBcOoActive Kali365 phishing URL serving SharePoint-themed lure and initiating Microsoft device code authentication flow
- urlhxxps://ze1im3fd2b[.]qualityfirstonline[.]de/l/aGgh--DD0IQActive Kali365 phishing URL serving lure page with device code ELTQSTVRD
Detection / Hunteropenrouter
What Happened
A phishing toolkit called Kali365 is targeting organizations in the United States by tricking employees into authorizing access to their Microsoft 365 and Google accounts. Instead of creating fake login pages to steal passwords, the attackers use a legitimate feature called device code authentication — the same process you might use to sign into a smart TV or other device. The victim is shown a code and told to enter it on the real Microsoft or Google login page. Once they do, the attackers receive digital keys (called OAuth tokens) that let them access the victim's email, documents, and cloud files without ever knowing the password. This affects any organization using Microsoft 365 or Google Workspace, especially those in technology, healthcare, government, and consulting. It matters because the attack is very hard to detect — the login happens on a real Microsoft page, so it looks normal to security tools. Organizations should consider restricting device code authentication where it is not needed, training employees to recognize these requests, and monitoring for unusual access to cloud accounts. If an account is compromised, simply resetting the password is not enough — the active sessions and digital keys must also be revoked.
Key Takeaways
- Kali365 is a phishing kit that abuses Microsoft and Google device code authentication flows to steal OAuth access and refresh tokens without capturing passwords directly
- The phishkit includes 34 branded lure templates impersonating Microsoft 365 services (SharePoint, OneDrive, Teams, Outlook), DocuSign, Adobe, Dropbox, and Google Drive
- Victims authenticate on legitimate Microsoft/Google login pages, making the attack harder to detect with traditional phishing controls and creating SOC blind spots
- Over 80 public sandbox sessions per week target US organizations across MSSPs, manufacturing, technology, government, healthcare, and consulting sectors
- Most Kali365 phishing pages use .de top-level domains; the phishkit exposes specific API endpoints (/api/generate, /api/lure-config, /api/status) that provide stronger detection signals than the legitimate login pages
Affected Systems
- Microsoft 365 environments
- Microsoft Entra ID (Azure AD) tenants with device code authentication enabled
- Google Workspace environments with device authorization flows
- Organizations relying on OAuth token-based access to cloud SaaS resources
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Victim receives phishing message containing link to Kali365 lure page impersonating SharePoint, OneDrive, Teams, DocuSign, or other trusted brands
- Execution: Victim clicks link and lands on attacker-controlled phishing page (e.g., .de domain) displaying branded lure template with instructions to authenticate via device code
- Credential Access: Victim is directed to legitimate Microsoft device login page (login.microsoftonline.com/common/oauth2/deviceauth) and enters attacker-provided device code
- Defense Evasion: Authentication completes on legitimate Microsoft infrastructure, producing minimal conventional phishing indicators and creating SOC blind spots
- Persistence: Attackers obtain OAuth access and refresh tokens, enabling continued access to Microsoft 365 resources without requiring the victim's password
- Collection/Exfiltration: Attackers use stolen tokens to access corporate email, documents, SharePoint sites, and cloud SaaS resources; may facilitate business email compromise and data theft
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: ANY.RUN Interactive Sandbox, ANY.RUN Threat Intelligence Lookup
The article does not provide specific detection rules but describes Kali365-specific API endpoints (/api/generate, /api/lure-config, /api/status, /api/google/status) and JavaScript configuration fields (design, flow_type) that can be used for detection. ANY.RUN sandbox sessions and TI Lookup queries are referenced for further IOC extraction and analysis.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Low | The attack primarily occurs in the browser and involves legitimate Microsoft authentication pages. EDR agents may see browser process (e.g., msedge.exe) connecting to both phishing domains and legitimate Microsoft endpoints, but the authentication itself happens on Microsoft's infrastructure, not on the endpoint. No malware is dropped to disk. |
| Network Visibility | Medium | Network monitoring can detect connections to Kali365 phishing domains (especially .de domains and Cloudflare Workers/R2 domains) and the Kali365 API endpoint patterns (/api/generate, /api/status). However, the actual authentication traffic flows to legitimate Microsoft/Google endpoints, which would appear normal. DNS resolution of phishing domains is the strongest network signal. |
| Detection Difficulty | Hard | The attack leverages legitimate Microsoft authentication infrastructure, making it extremely difficult to distinguish from normal device code authentication. Traditional phishing detection (URL reputation, fake login pages) is ineffective because the login page is genuine. Detection requires correlating phishing domain visits with subsequent device code authentication events and OAuth token issuance in identity logs, which many organizations do not monitor. |
Required Log Sources
- Microsoft Entra ID (Azure AD) sign-in logs
- Microsoft Entra ID audit logs for OAuth application consent and token issuance
- Microsoft 365 audit logs (Exchange, SharePoint, OneDrive activity)
- Web proxy logs and DNS resolution logs
- Conditional Access policy evaluation logs
- Cloud app security / CASB logs for OAuth app activity
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for device code authentication events in Entra ID sign-in logs where the preceding user activity or network telemetry shows a connection to a suspicious .de domain or Cloudflare Workers/R2 domain shortly before the authentication request | Microsoft Entra ID sign-in logs (non-interactive sign-ins with device code grant type), web proxy logs, DNS logs | Credential Access | Medium — legitimate device code authentication is common for smart TVs, CLI tools, and IoT devices; correlation with suspicious domain visits reduces false positives but requires cross-data-source analysis |
| Consider hunting for OAuth token issuance events where the client application or resource being accessed is unusual or the sign-in originates from an unexpected IP or location pattern compared to the user's baseline | Microsoft Entra ID sign-in logs, OAuth grant logs, conditional access logs | Persistence | Medium — users may legitimately authenticate from new locations or devices; focus on tokens issued via device code grant type from unusual geographies |
| Consider hunting for HTTP requests to URLs containing Kali365 API path patterns (/api/generate, /api/lure-config, /api/status, /api/google/status) in web proxy or firewall logs | Web proxy logs, firewall logs, DNS logs | Initial Access | Low — these specific API path patterns are unique to the Kali365 phishkit and unlikely to appear in legitimate traffic |
| Consider hunting for OAuth refresh token usage from IP addresses or user agents inconsistent with the user's normal access patterns, indicating an attacker using stolen tokens | Microsoft Entra ID sign-in logs, Microsoft 365 activity logs, CASB logs | Collection | Medium — legitimate token refresh can occur from various locations if the user uses VPNs or travels; focus on rapid geographic impossibility or unusual client applications |
| Consider hunting for JavaScript on web pages containing Kali365 configuration fields (design, flow_type, capture_mode) or references to device code verification URLs with specific patterns | Web proxy logs with content inspection, browser security extensions, secure web gateway logs | Initial Access | Low — these configuration field combinations are specific to the Kali365 phishkit |
Control Gaps
- Traditional email security and URL filtering may not flag phishing pages that redirect to legitimate Microsoft authentication endpoints
- Endpoint detection and response (EDR) tools have limited visibility into browser-based social engineering attacks that do not drop malware
- Conditional access policies may not restrict or monitor device code authentication flows specifically
- OAuth token monitoring and revocation capabilities may be insufficient or not integrated into incident response workflows
- DNS filtering may not block newly registered .de phishing domains quickly enough to prevent initial access
Key Behavioral Indicators
- HTTP requests to domains with random subdomain prefixes (e.g., w5w0trvg0w, ze1im3fd2b, urjnwwndtg) on .de TLDs
- URL paths matching /l/<random-string> pattern on suspicious domains, consistent with Kali365 lure delivery
- HTTP requests to Kali365 API endpoints: /api/generate, /api/lure-config, /api/status, /api/google/status
- JavaScript configuration objects containing fields: design, flow_type, capture_mode, cookie_lure_url with values like sharepoint, device_code, cookies
- Device code authentication events (grant type=device_code) in Entra ID logs originating from users who recently accessed suspicious .de domains
- OAuth token issuance for Microsoft Graph or other Microsoft 365 APIs following a device code flow from unusual locations or client applications
- Cloudflare Workers (.workers.dev) or R2 (.r2.dev) domains impersonating Microsoft services in DNS or proxy logs
False Positive Assessment
Medium — Device code authentication is a legitimate flow used by smart TVs, CLI tools, and IoT devices. Detecting malicious use requires correlating phishing domain visits with subsequent authentication events. The Kali365 API endpoint patterns (/api/generate, /api/status) have low false positive risk, but broader behavioral detections around device code authentication will generate false positives from legitimate usage.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider searching web proxy, DNS, and firewall logs for the Kali365 domains and API endpoint patterns listed in this report to identify potentially compromised users.
- If compromised accounts are identified, consider revoking all active sessions and refresh tokens in Entra ID — a password reset alone is insufficient since attackers hold OAuth tokens that bypass password-based authentication.
- Consider reviewing Entra ID sign-in logs for device code authentication events (grant type=device_code) and correlating with any access to the phishing domains identified in this report.
- If your email security platform supports it, consider blocking or quarantining messages containing links to the identified Kali365 phishing domains and .de domains with random subdomain patterns.
Infrastructure Hardening
- Evaluate whether device code authentication (OAuth 2.0 device code flow) is required for your tenant; consider disabling or restricting it via Conditional Access policies where it is not business-essential.
- Consider implementing Conditional Access policies that require compliant devices or specific IP ranges for device code authentication, if supported by your Entra ID configuration.
- If applicable, consider deploying DNS filtering or secure web gateway rules to block newly registered .de domains with random subdomain patterns that match Kali365 infrastructure characteristics.
- Evaluate whether your organization monitors OAuth application consent and token issuance in Entra ID; consider enabling alerts for new OAuth app registrations and unusual token grant patterns.
User Protection
- Consider adding the Kali365 phishing domains and URL patterns from this report to your secure web gateway, DNS filter, and browser security extension blocklists.
- If your organization uses Microsoft Defender for Cloud Apps or a similar CASB, consider creating policies to alert on OAuth token usage from unusual locations or client applications.
- Consider deploying browser security extensions that warn users when accessing newly registered domains or domains with suspicious subdomain patterns.
Security Awareness
- Consider updating phishing awareness training to include device code phishing scenarios, emphasizing that legitimate Microsoft authentication pages can be abused if the user enters an attacker-provided code.
- Consider advising users to verify the source of any device code authentication request through a separate, trusted communication channel before entering codes on Microsoft or Google login pages.
- Consider incorporating guidance on recognizing suspicious .de domains and unexpected SharePoint, OneDrive, or DocuSign sharing notifications into existing security awareness programs.
- If applicable, consider reminding users that legitimate IT or security teams will never ask them to authenticate by visiting a device login page and entering a code provided in an unsolicited email or message.
MITRE ATT&CK Mapping
Initial Access
Credential Access
Lateral Movement
Additional IOCs
- Domains:
bluefoodtruths[.]xyz- Kali365 phishing domain listed in related IOCsguardedwebsolutions[.]de- Kali365 phishing domain listed in related IOCsreputationboosters[.]de- Kali365 phishing domain listed in related IOCsprowebsitemakers[.]de- Kali365 phishing domain listed in related IOCsonlinebrandinghub[.]de- Kali365 phishing domain listed in related IOCsonsite-developments[.]net- Kali365 phishing domain listed in related IOCsfunctionalityfirst[.]de- Kali365 phishing domain listed in related IOCs; subdomain a0ohccrq5l.functionalityfirst.de observed in TI Lookupbuildyouronlineidentity[.]de- Kali365 phishing domain listed in related IOCsflexievolve[.]de- Kali365 phishing domain listed in related IOCsonlineidentityperfection[.]de- Kali365 phishing domain listed in related IOCs; subdomain ea2oq4imx9.onlineidentityperfection.de observed in TI Lookupguardwebsolutions[.]de- Kali365 phishing domain listed in related IOCssecuredecisionmaking[.]de- Kali365 phishing domain listed in related IOCs; subdomain 9vzkt2bl18.securedecisionmaking.de observed in TI Lookupmodernwebbalance[.]de- Kali365 phishing domain listed in related IOCsmarketadaptabletech[.]de- Kali365 phishing domain listed in related IOCswaschmaschinenmarkt[.]de- Kali365 phishing domain listed in related IOCstxatvrk[.]net- Kali365 phishing domain listed in related IOCshbaknoxvillecom[.]top- Kali365 phishing domain listed in related IOCsbrandswithintegrity[.]de- Kali365 phishing domain listed in related IOCsturnideastoresults[.]de- Kali365 phishing domain listed in related IOCswellpults[.]com- Kali365 phishing domain listed in related IOCsnavigatingdigitalchange[.]de- Kali365 phishing domain listed in related IOCsqualityfirstonline[.]de- Kali365 phishing domain listed in related IOCs; subdomain ze1im3fd2b.qualityfirstonline.de observed serving active phishing pagebrandtrustmasters[.]de- Kali365 phishing domain listed in related IOCs; subdomain xyodqs6fye.brandtrustmasters.de observed in TI Lookuptheconsistencyfactor[.]de- Kali365 phishing domain listed in related IOCs; subdomain s6gfswtisn.theconsistencyfactor.de observed in TI Lookupreliablebusinesstech[.]de- Kali365 phishing domain listed in related IOCs; subdomain jc1wjhjoy4.reliablebusinesstech.de observed in TI Lookupperformancereputation[.]de- Kali365 phishing domain listed in related IOCsdewdhurstlobl[.]com- Kali365 phishing domain listed in related IOCs; subdomain urjnwwndtg.dewdhurstlobl.com observed serving active phishing pagesecuredecisionmakers[.]de- Kali365 phishing domain listed in related IOCsscalableadapt[.]de- Kali365 phishing domain listed in related IOCstrustinbrands[.]de- Kali365 phishing domain listed in related IOCsuserfriendlyinterface[.]de- Kali365 phishing base domain; subdomain w5w0trvg0w.userfriendlyinterface.de observed serving SharePoint lurebrandintegrityhub[.]de- Kali365 phishing domain observed in TI Lookup with subdomains pgiwcpb3t4 and bs6k39jv72customertrustservices[.]de- Kali365 phishing domain observed in TI Lookup with subdomain c44op45gybtechnologyfortrust[.]de- Kali365 phishing domain observed in TI Lookup with subdomain zvcsursrhhreliableinnovation[.]de- Kali365 phishing domain observed in TI Lookup with subdomain qjmvg27le1decidewithsecurity[.]de- Kali365 phishing domain observed in TI Lookup with subdomain hiqdy7k61aloyaltydrivenbyquality[.]de- Kali365 phishing domain observed in TI Lookup with subdomain Kext4t75yfloyaltythroughservice[.]de- Kali365 phishing domain observed in TI Lookup with subdomain 3rme70pcpodigitalfoundationstability[.]de- Kali365 phishing domain observed in TI Lookup with subdomain eczob0ub46outcomesbydesign[.]de- Kali365 phishing domain observed in TI Lookup with subdomain zht08qprj5reliableperformance[.]de- Kali365 phishing domain observed in TI Lookup with subdomain 3blxay3rtouserjourneyguide[.]de- Kali365 phishing domain observed in TI Lookup with subdomain 4no9yhy5i6createsimpact[.]de- Kali365 phishing domain observed in TI Lookup with subdomain gyduwj1m1finteractionsoptimized[.]de- Kali365 phishing domain observed in TI Lookup with subdomain ml9zcrj2rqbusinesssafetysolutions[.]de- Kali365 phishing domain observed in TI Lookup with subdomains cpmmi4mmc6 and di3l4gdy04onlineidentityhub[.]de- Kali365 phishing domain observed in TI Lookup with subdomain 88rhpce52gmodernecosystemhub[.]de- Kali365 phishing domain observed in TI Lookup with subdomain b5qs2htv4ssdnbbd[.]info- Phishing domain observed in ANY.RUN TI Lookup results associated with phishing file hash 482BEA1EFB446651FFE543BA4FF459A59F6A295FC2913ED188906E22F16A0400na2[.]hubsy[.]ly- Phishing domain observed in ANY.RUN TI Lookup results associated with phishing URL https://na2.hubsy.ly/H06yWWs0
- Urls:
hxxps://ze1im3fd2b[.]qualityfirstonline[.]de/l/aGgh--DD0IQ- Active Kali365 phishing URL serving lure page with device code ELTQSTVRDhxxps://urjnwwndtg[.]dewdhurstlobl[.]com/l/nZA-5LCJh-0- Active Kali365 phishing URL serving lure page with device code BZBJZ2Y7Bhxxps://sites[.]google[.]com/view/icsshipping/home- Phishing URL observed in ANY.RUN TI Lookup results; associated file hash 5EE10AEF46E89BFED08F90ABB73D48602D73B5B416EF448D9ECEC0D96405D41Ehxxps://simplebooklet[.]com/doc01931241174- Phishing URL observed in ANY.RUN TI Lookup results abusing legitimate simplebooklet.com platformhxxps://sdnbbd[.]info/- Phishing URL observed in ANY.RUN TI Lookup results; associated file hash 482BEA1EFB446651FFE543BA4FF459A59F6A295FC2913ED188906E22F16A0400hxxps://na2[.]hubsy[.]ly/H06yWWs0- Phishing URL observed in ANY.RUN TI Lookup resultshxxps://s[.]surveyplanet[.]com/e9pvncus- Phishing URL observed in ANY.RUN TI Lookup results abusing legitimate surveyplanet.com platform
- File Hashes:
5EE10AEF46E89BFED08F90ABB73D48602D73B5B416EF448D9ECEC0D96405D41E(SHA256) - SHA256 hash of phishing content served from https://sites.google.com/view/icsshipping/home, observed in ANY.RUN TI Lookup482BEA1EFB446651FFE543BA4FF459A59F6A295FC2913ED188906E22F16A0400(SHA256) - SHA256 hash of phishing content served from https://sdnbbd.info/, observed in ANY.RUN TI Lookup4EAF90854125AF5F15510ACEA70C6096466CF207F33644FC7E520E480803ED5(SHA256) - SHA256 hash of phishing content served from shared.outlook.inky.com link, observed in ANY.RUN TI Lookup
- Other:
/api/generate?lure=<ID>- Kali365 phishkit API endpoint used to generate a device-code session and retrieve lure configuration by lure ID/api/lure-config/<ID>- Kali365 phishkit API endpoint used to retrieve lure configuration by ID/api/status/<Number>- Kali365 phishkit polling endpoint used to check status of Microsoft device-code sessions/api/google/status/<Number>- Kali365 phishkit polling endpoint used to check status of Google device-code sessions