DNS Insights on a Free Form Builder Phishing Campaign | WhoisXML API

Threat Reports

DNS Insights on a Free Form Builder Service Phishing Campaign

Phishers can take advantage of any third-party service to infiltrate an organization’s network. They did just that to harvest victims’ credentials and take over their organizations’ Microsoft Azure cloud infrastructure by leveraging the HubSpot Free Form Builder service.1

A total of 33 indicators of compromise (IoCs) related to the phishing campaign have already been identified. The WhoisXML API research team expanded the list of IoCs and uncovered:

  • 16 email-connected domains
  • Four additional IP addresses
  • 185 IP-connected domains
  • 289 string-connected domains

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://unit42.paloaltonetworks.com/european-phishing-campaign/
Try our WhoisXML API for free
Get started