eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)
2026-06-19T13:23:47Z•757f213e5a9bd4b0634e06599a1df22afc840de17dfe4e9a6d8a4f19f5986635
IPv4‑mapped‑IPv6IPv6JavaScriptRemcosSHA256:a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b8VHDXZIPemaile‑bankingmalicious‑linkmalwarephishing
What happened
SANS ISC diary roundup (Jun 12–19, 2026) highlighting multiple active threats and analysis: a targeted e‑banking phishing campaign using IPv4‑mapped IPv6 addresses to host malicious links (targets a major Belgian bank); a malicious ZIP (SHA256 a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094) that contains a VHDX which auto‑mounts and exposes a JavaScript dropper leading to a Remcos RAT; analysis of image‑based malicious payload techniques ("Evil MSI Background" / steganography); a guest diary on coordinated SSH brute‑force behavior over recent months; and a writeup on browser‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 757f213e5a9bd4b0634e06599a1df22afc840de17dfe4e9a6d8a4f19f5986635
- Enrichment time
- 2026-06-19T13:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.