
'Shipping Advice' Phishing Chain Skips Fingerprints, Leans on Disposable Hosting
A RAR-wrapped JavaScript dropper disguised as shipping paperwork stages a font-masquerading payload and checks its victim's IP before touching a single, disposable Namecheap-hosted domain. Tied loosely to TA505/RockLoader, the campaign shows almost no shared imphash or code-signing evidence — its strength is behavioural, not structural.
A phishing wave dressed up as a "shipping advice" notice is running a tight, four-step reconnaissance-and-drop chain before it ever touches a durable piece of infrastructure. The sequence — a RAR-wrapped JavaScript dropper that stages a font-disguised payload and then queries the victim's own external IP address before reaching out to a single, disposable web host — reads less like a bespoke intrusion tool and more like a lean, repeatable delivery kit.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read