Browser-Based Threat Report: May 20

Browser-Based Threat Report

Week of May 20th, 2024

ConcealBrowse is leveraged by teams across the world to combat weaponized URLs. The technology is constantly analyzing suspicious web artifacts to identify risks in the form of drive-by attacks, phishing portals, and other threats that materialize while browsing.

At Conceal, your digital safety is our utmost priority. Our weekly threat report for the week of May 20th, 2024, unveils critical insights into the ever-evolving landscape of online threats.

The following report highlights recently detected sites that were deemed suspicious:

_____________

SHA-256: d5901a67f4df5789ece2cbe1055eed62bc038f344f3a437073ab2d1efeefe198

Browser-based threat 5.20.24

This page was detected by ConcealBrowse on May 20th, the day after other security vendors began reporting. It was initially only reported by one vendor, but currently has nine vendors flagging the site for phishing. ConcealBrowse intervened due to suspicious behavior, giving the page a 34% risk assessment.

Support scams, such as this one, aim to lure users into giving away vital information that can be used to compromise their accounts in the future. The user is informed that their account has violated the terms of use, and an appeal is necessary, or else the account will be permanently deleted. Information gathered using this scam, such as email address and phone number, will be used as part of social engineering to contact the user later to extort money from them to restore their account. ConcealBrowse’s isolation prevents users from entering text into the page, stopping the scam.

_____________

SHA-256: a42d900f47e929c0d1de078512cd562ccd3afcf3dcdc36f36cc81fab04dbe35d

Browser-based threat 5.20.24

This site was first detected by ConcealBrowse on May 16th, along with other security vendors. It was first seen by nine vendors, and as of this writing it has been detected by eight. ConcealBrowse intervened with an 18% risk assessment due to the detection of suspicious behavior.

The page is an advertisement for a browser extension that claims to improve browsing experience for the user. Although the extension has since been removed from the Chrome store, it is highly likely that it was a browser hijacker. Browser hijackers change browser settings, such as the default engine, to redirect users to unwanted sites. These sites could contain spam or steal user data without consent. While in an isolated session, users cannot install browser extensions from the intervened site.

_____________

SHA-256: d3f304ecb24e6eb607eddd411a026a1e6bb5bed60339fccfc88142063aa110ea

Browser-based threat 5.20.24

This page was detected by ConcealBrowse on May 17th, the same day other security vendors began reporting. It was initially detected by four security vendors and has now been flagged by five for malicious activity. ConcealBrowse intervened with a 16% risk assessment due to suspicious behavior.

This phishing attempt aims to steal credentials for a popular video streaming platform. If the user enters their information, the site proceeds to prompt them to enter their payment details. Stolen credentials can pose a risk for other accounts that share those same credentials, highlighting the importance of creating different passwords for every account. While in an isolated session, ConcealBrowse blocks keyboard input and users cannot enter sensitive information.

_____________

Valuable Outcomes

As this recent threat reports exemplify, ConcealBrowse offers comprehensive protection against many sophisticated cyber threats. Our advanced threat detection capabilities have successfully flagged and quarantined malicious web pages, preventing users from falling victim to various cyber-attacks. Conceal remains dedicated to upholding the integrity of online interactions, constantly refining our detection algorithms and threat identification protocols to ensure proactive protection against emerging cyber threats. By integrating cutting-edge technology and a robust security infrastructure, we empower users to confidently navigate the digital landscape, knowing that their online activities are shielded from potential harm.

Join the Conceal Community and claim your FREE ConcealBrowse licenses!

Join the Conceal Community today and fortify your online security for free! Don’t miss the chance to benefit from our advanced threat protection and stay one step ahead of cybercriminals. Experience peace of mind while browsing the internet, knowing that ConcealBrowse is your shield against the ever-evolving threat landscape. Take the proactive step towards a safer online experience – get your free ConcealBrowse license now and join a community committed to safeguarding your digital world.

ConcealBrowse Meets N-able N-sight RMM

Conceal introduces a streamlined solution that combines the comprehensive protection of ConcealBrowse with the unmatched efficiency of N-able N-sight RMM’s capabilities.

Browser-Based Threat Report: May 13

Browser-Based Threat Report

Week of May 13th, 2024

ConcealBrowse is leveraged by teams across the world to combat weaponized URLs. The technology is constantly analyzing suspicious web artifacts to identify risks in the form of drive-by attacks, phishing portals, and other threats that materialize while browsing.

At Conceal, your digital safety is our utmost priority. Our weekly threat report for the week of May 13th, 2024, unveils critical insights into the ever-evolving landscape of online threats.

The following report highlights recently detected sites that were deemed suspicious:

_____________

SHA-256: 3a278c931ccefdc21db9a125ba7afe14198c7b18dac78b9e4f1d17786dc0f57e

browser-based threat 5.13.24

An example of one of the redirects

This site was detected by ConcealBrowse on May 9th, the same day other security vendors began reporting. It was initially detected by three vendors and is now flagged by two vendors for malicious behavior. ConcealBrowse intervened with a 21% risk assessment due to suspicious behavior.

This domain is part of a malicious advertising campaign. The link will redirect to several different sites, which may contain spam, malware, or other harmful material. A browser redirecting to this site without any input from the user may be indicative of a malware infection or a malicious browser extension. ConcealBrowse’s intervention helps alert users that these sites are malicious and encourages further action if their device is compromised.

Conceal Recommends: This domain should be blocked.

_____________

SHA-256: a42d900f47e929c0d1de078512cd562ccd3afcf3dcdc36f36cc81fab04dbe35d

browser-based threat 5.13.24

This page was detected by ConcealBrowse on May 9th, before other security vendors began reporting. This site is an emerging threat and is still not detected by any security vendors. ConcealBrowse intervened with a 32% risk assessment, citing proximity and potential phishing activity.

This is a phishing page that aims to steal email credentials and utilizes user verification features to evade website scanners. Before this page is displayed, the user is asked to verify their identity with a Captcha system. This prevents popular scanners and security vendors from viewing the site using automatic tools, keeping the page up longer and increasing the risk to users. While in an isolated session, keyboard input is blocked, and users cannot enter sensitive information.

Conceal Recommends: This URL should be blocked.

_____________

SHA-256: 55ca0552691ca66b69febbf3c0abf0a4d407a3cbb3a51badc97ea346c56530b6

browser-based threat 5.13.24

This page was detected by ConcealBrowse on May 10th, the same day other security vendors began reported. It was initially detected by seven vendors, and that number remains the same as of this writing. ConcealBrowse intervened with an 18% risk assessment, citing suspicious behavior.

This site offers free downloads of popular software that usually requires payment to access. Although these offers may be tempting, software obtained through illegitimate sources can carry significant risk for the end-user. They may come attached with malware that can compromise accounts or lock the device with ransomware. While in an isolated session, ConcealBrowse users cannot download or execute any files from the website.

Conceal Recommends: This domain should be blocked to prevent the accidental download of harmful software.

_____________

Valuable Outcomes

As this recent threat reports exemplify, ConcealBrowse offers comprehensive protection against many sophisticated cyber threats. Our advanced threat detection capabilities have successfully flagged and quarantined malicious web pages, preventing users from falling victim to various cyber-attacks. Conceal remains dedicated to upholding the integrity of online interactions, constantly refining our detection algorithms and threat identification protocols to ensure proactive protection against emerging cyber threats. By integrating cutting-edge technology and a robust security infrastructure, we empower users to confidently navigate the digital landscape, knowing that their online activities are shielded from potential harm.

Join the Conceal Community and claim your FREE ConcealBrowse licenses!

Join the Conceal Community today and fortify your online security for free! Don’t miss the chance to benefit from our advanced threat protection and stay one step ahead of cybercriminals. Experience peace of mind while browsing the internet, knowing that ConcealBrowse is your shield against the ever-evolving threat landscape. Take the proactive step towards a safer online experience – get your free ConcealBrowse license now and join a community committed to safeguarding your digital world.

ConcealBrowse Meets NinjaOne

Conceal introduces a streamlined solution that combines the comprehensive protection of ConcealBrowse with the unmatched efficiency of NinjaOne’s Remote Monitoring and Management (RMM) capabilities.

press release hero

Conceal and TerraOne (member of Zero One Group) Announce Strategic Partnership to Enhance Cybersecurity Solutions

Conceal partners with Taiwan-based IT solutions provider Zero One, integrating AI-powered browser security into Zero One’s cybersecurity suite

May 13, 2024, 11:44 AM Eastern Daylight Time

AUGUSTA, Ga.–(BUSINESS WIRE)–Conceal, a pioneering AI-powered browser security solutions provider, and Zero One, a leading IT solutions company based in Taiwan, are thrilled to announce their strategic partnership. This collaboration aims to fortify cybersecurity infrastructure and provide cutting-edge solutions to organizations worldwide.

“Our partnership with Zero One is a testament to our shared commitment to revolutionizing cybersecurity solutions,” expressed Gordon Lawson, CEO of Conceal. “This collaboration not only addresses the immediate need for enhanced browser security but also signifies our long-term commitment to the safety and well-being of users worldwide. By integrating ConcealBrowse into Zero One’s cybersecurity suite, we are poised to offer enhanced protection against web threats, leveraging AI-powered technology for real-time threat detection. Together, we will embark on a journey to empower organizations across various sectors with innovative cybersecurity solutions, ensuring they navigate the digital landscape with confidence and resilience.”

“We are thrilled to embark on this transformative journey with Conceal, uniting our strengths to confront the evolving cybersecurity landscape,” stated Polina Yuan, GM of TerraOne. “This partnership signifies a pivotal moment in our commitment to delivering unparalleled IT solutions and safeguarding our client’s digital assets. Together, we will leverage our combined expertise to offer innovative, forward-looking cybersecurity solutions, empowering businesses worldwide to navigate the complexities of the digital age with confidence and resilience.”

This collaboration heralds a new era of fortified online security, marked by groundbreaking initiatives and cutting-edge technology. Highlights of this alliance include the integration of ConcealBrowse into Zero One’s cybersecurity suite, fortifying clients against web threats with AI-driven protection and real-time threat detection. Leveraging Zero One’s expansive global network, Conceal is poised to venture into new markets, bolstering its user base across diverse industries such as finance, healthcare, and education. Conceal and Zero One remain steadfast in their commitment to safeguarding digital landscapes and equipping users with the knowledge and tools necessary for a secure online experience.

 


About Conceal

Conceal is dedicated to defending organizations against web-based threats. Their product, ConcealBrowse, is an AI-powered browser extension designed to detect, prevent, and shield users from sophisticated cyber threats such as phishing and credential theft. ConcealBrowse significantly reduces the risk of costly cyber incidents by focusing on securing the human element of cybersecurity. For more information, visit https://conceal.io/conceal-browse/

About TerraOne

TerraOne was established in 2024 and is committed to developing enterprise information software and hardware equipment sales agents to respond to diverse and changing market demands. It is one of the subsidiaries of Taiwan’s professional IT distributor – Zero One Tech. Taking professional services and excellence as its indicators, TerraOne focuses on expanding the agency business of cybersecurity brands in the first year. At the same time, it provides various sales and marketing-oriented services to partners with the parent company’s data center infrastructure, digital transformation and other solutions Integration support.

About Zero One

Established in 1980, Zero One boasts over 40 years of experience in Taiwan’s information service industry, delivering comprehensive enterprise IT solutions. With a team of over 100 professionals, Zero One excels in IT infrastructure, network and information security, multi-cloud platform management, and AI big data applications. Through its offerings, including sustainable governance, multi-cloud management, information resilience, and AI application, Zero One empowers businesses with forward-thinking and competitive solutions, driving the modernization of enterprise IT. For more information, visit https://www.zerone.com.tw/en

Browser-Based Threat Report: May 6

Browser-Based Threat Report

Week of May 6th, 2024

ConcealBrowse is leveraged by teams across the world to combat weaponized URLs. The technology is constantly analyzing suspicious web artifacts to identify risks in the form of drive-by attacks, phishing portals, and other threats that materialize while browsing.

At Conceal, your digital safety is our utmost priority. Our weekly threat report for the week of May 6th, 2024, unveils critical insights into the ever-evolving landscape of online threats.

The following report highlights recently detected sites that were deemed suspicious:

_____________

SHA-256: d1d8b69ec0af86b8ac534c2565f3d3b9cae46924a5d31a32e5565ba945786bbd

browser-based threat 5.6.24

This page was detected by ConcealBrowse on May 3rd. It was originally reported by one security vendor in February and is currently reported by 11 vendors for phishing activity. ConcealBrowse intervened with a 14% risk assessment due to the detection of suspicious behavior.

This is an email credentials phishing page that utilizes the shared document scam. The user receives a phishing email that alerts them that there are important documents that need their attention, usually pertaining to invoices or bills. This information, combined with a sense of urgency in the message, encourages users to look at the document as soon as possible and not verify its source.

Conceal Recommends: This URL should be blocked. While in an isolated session, keyboard input is blocked, and users cannot enter their credentials.

_____________

SHA-256: 77e425ad6b8d67714e10740b6b061a968ea9e3c8f977f842ab92533a84efb668

browser-based threat 5.6.24

This page was detected by ConcealBrowse on May 6th, the same day other security vendors began reporting. It is currently detected by 12 vendors for phishing and malicious behavior. ConcealBrowse intervened with a 22% risk assessment due to suspicious activity.

This site has been detected as a shopping scam. Shopping scams aim to take financial and personal data from the user by promising popular products at steep discounts. These sites are often taken down shortly after generation and are linked to spam or malicious advertising platforms. Although they may easily appear fraudulent to the average user, ConcealBrowse’s protection offers additional coverage when users may be unsure of a webpage’s legitimacy.

Conceal Recommends: This domain should be blocked. While in an isolated session, keyboard input is blocked, and users cannot enter sensitive information.

_____________

SHA-256: d1d8b69ec0af86b8ac534c2565f3d3b9cae46924a5d31a32e5565ba945786bbd

browser-based threat 5.6.24

This page was detected by ConcealBrowse on May 3rd, with the first security vendors reporting a few days earlier. It was initially detected by five vendors on May 1st and is currently detected by 17 vendors for phishing. ConcealBrowse intervened with a 29% risk assessment, citing suspicious behavior.

This site also demonstrates a shared document scam; however, it differs from others by pretending to be the user’s online storage drive, rather than just one document. This may make users believe that the link took them to their personal account and be more likely to enter their password to access the fraudulent document. This phishing attempt takes advantage of the user not investigating the page further because it looks so close to the legitimate version of the site.

Conceal Recommends: This URL should be blocked. While in an isolated session, keyboard input is blocked, and user credentials remain protected.

_____________

Valuable Outcomes

As this recent threat reports exemplify, ConcealBrowse offers comprehensive protection against many sophisticated cyber threats. Our advanced threat detection capabilities have successfully flagged and quarantined malicious web pages, preventing users from falling victim to various cyber-attacks. Conceal remains dedicated to upholding the integrity of online interactions, constantly refining our detection algorithms and threat identification protocols to ensure proactive protection against emerging cyber threats. By integrating cutting-edge technology and a robust security infrastructure, we empower users to confidently navigate the digital landscape, knowing that their online activities are shielded from potential harm.

Join the Conceal Community and claim your FREE ConcealBrowse licenses!

Join the Conceal Community today and fortify your online security for free! Don’t miss the chance to benefit from our advanced threat protection and stay one step ahead of cybercriminals. Experience peace of mind while browsing the internet, knowing that ConcealBrowse is your shield against the ever-evolving threat landscape. Take the proactive step towards a safer online experience – get your free ConcealBrowse license now and join a community committed to safeguarding your digital world.

Sign up for the Conceal Community and claim your free licenses by completing the form below.


Browser-Based Threat Report: Apr 29

Browser-Based Threat Report

Week of April 29th, 2024

ConcealBrowse is leveraged by teams across the world to combat weaponized URLs. The technology is constantly analyzing suspicious web artifacts to identify risks in the form of drive-by attacks, phishing portals, and other threats that materialize while browsing.

At Conceal, your digital safety is our utmost priority. Our weekly threat report for the week of April 29th, 2024, unveils critical insights into the ever-evolving landscape of online threats.

The following report highlights recently detected sites that were deemed suspicious:

_____________

SHA-256: 643a606f2babcd61e049f14f850640d2c95ec6692671f0f8f190c2d22b33e02e

browser-based threat 4.29.24

This page was detected by ConceaBrowse on April 26th before other security vendors began reporting. It is currently detected by 4 security vendors for phishing. ConcealBrowse intervened with a 44% risk score, citing suspicious behavior.

This site impersonates a popular security vendor, claiming that the user’s machine is at risk until they renew their subscription. Pages such as this one often have links that lead to illegitimate products that are not representative of the service, or affiliated links that generate revenue for the malicious actor under the guise of protecting customer devices. Users should always use trusted means to renew security services and ignore pages like this that ConcealBrowse has intervened on.

Conceal Recommends: Although this domain is currently unavailable, it is still recommended that it be blocked in case it becomes accessible again.

_____________

SHA-256: 3b802b2c2d634feae65621709ce605f32b3792e227a7db95b1b29cdcc2683ce0

browser-based threat 4.29.24

This page was detected by ConcealBrowse on April 26th. It was first detected by one security vendor in January of 2024, and is currently detected by 12 security vendors for malicious behavior. ConcealBrowse intervened with a 28% risk score due to proximity, phishing, and suspicious behavior.

This domain is frequently used to host prize scams. Although prize scams alone can result in the theft of payment information, this specific site has also been connected to a chargeback prevention fraud. Chargeback prevention fraud occurs when the stolen card information is used to charge the users for a service under the guise that it is easy to cancel. However, when victims attempt to cancel the service, the malicious actors utilize deceptive tactics to avoid returning the money.

Conceal Recommends: This domain should be blocked. While in isolation, users do not have access to their keyboards and cannot input sensitive information.

_____________

SHA-256: ee1a27178227546d3dcc49e611a6d72e4f1c30080ee4493ae4085b58a49e28e6

browser-based threat 4.29.24

This page was detected by ConcealBrowse on April 29th, the same day other security vendors started reporting. It is currently detected by one security vendor for malicious behavior. ConcealBrowse intervened with a 30% risk assessment because of proximity, phishing, and malware.

This site pretends to be a verification service and may be encountered when clicking on a compromised link or an advertisement. If the user interacts with the site or follows the instructions on-screen to enable notifications, they may be redirected to a technical support scam, deceptive advertisement, or a harmless website. However, the page has already injected notifications into the user’s browser, causing constant pop-ups that may lead to harmful websites or spam.

Conceal Recommends: This URL should be blocked. If a user interacts with the page while in isolation, the site will not be able to infect their browser.

_____________

Valuable Outcomes

As this recent threat reports exemplify, ConcealBrowse offers comprehensive protection against many sophisticated cyber threats. Our advanced threat detection capabilities have successfully flagged and quarantined malicious web pages, preventing users from falling victim to various cyber-attacks. Conceal remains dedicated to upholding the integrity of online interactions, constantly refining our detection algorithms and threat identification protocols to ensure proactive protection against emerging cyber threats. By integrating cutting-edge technology and a robust security infrastructure, we empower users to confidently navigate the digital landscape, knowing that their online activities are shielded from potential harm.

Join the Conceal Community and claim your FREE ConcealBrowse licenses!

Join the Conceal Community today and fortify your online security for free! Don’t miss the chance to benefit from our advanced threat protection and stay one step ahead of cybercriminals. Experience peace of mind while browsing the internet, knowing that ConcealBrowse is your shield against the ever-evolving threat landscape. Take the proactive step towards a safer online experience – get your free ConcealBrowse license now and join a community committed to safeguarding your digital world.

Sign up for the Conceal Community and claim your free licenses by completing the form below.


The Human Element

Browser Security Case Study: MEI

MEI’s journey with Conceal began with the recommendation of NGS, which is a testament to the strength of our partners, after an initial meeting that showcased Conceal’s capabilities and aligned with MEI’s requirements for a robust security solution that was low maintenance and easy to deploy.

fortifying web security against browser-based threats with SentinelOne Integration

Better Together: Conceal and SentinelOne

In a strategic move that redefines cybersecurity excellence, Conceal joins forces with SentinelOne, underscoring a commitment to delivering an unparalleled cybersecurity solution, combining the advanced capabilities of ConcealBrowse with the robust protection of SentinelOne.

Browser-Based Threat Report: Apr 15

Browser-Based Threat Report

Week of April 15th, 2024

ConcealBrowse is leveraged by teams across the world to combat weaponized URLs. The technology is constantly analyzing suspicious web artifacts to identify risks in the form of drive-by attacks, phishing portals, and other threats that materialize while browsing.

At Conceal, your digital safety is our utmost priority. Our weekly threat report for the week of April 15th, 2024, unveils critical insights into the ever-evolving landscape of online threats.

The following report highlights recently detected sites that were deemed suspicious:

_____________

SHA-256: 37680d1350f89e2205cd7c84d747e6b13bc1b6affd3e06c4d0251ac5bf5d009f

browser-based thrats 4.15.24

This page was first detected by ConcealBrowse on April 12th, before other security vendors began reporting. This site is an emerging threat and is not currently detected by any security vendors. ConcealBrowse intervened with a 14% risk assessment, citing suspicious behavior.

This website is impersonating a banking platform, urging users to verify their account information to unlock it. This urgency, and the fact that the account being targeted is financial, may cause users to fail to recognize the site as a scam. If users click forward to verify, they will be brought to a banking login page and asked to enter in their credentials. The loss of financial information can be devastating to victims, and it is crucial that real-time analysis is in effect to prevent these emerging threats from posing a danger.

Conceal Recommends: ConcealBrowse’s isolation will prevent users from entering any sensitive information. This URL should be blocked to prevent further access.

_____________

SHA-256: f21e8c4ce86eda42bc170ee09dde3dcd83be74d53307cd6eaa184d9eba421c8f

browser-based threat 4.15.24

This page was first seen by ConcealBrowse on April 10th, the day after other security vendors began reporting. It was initially seen by 5 security vendors, and now that the page has been removed, only 4 vendors are reporting the page as malicious. ConcealBrowse intervened with a 22% risk assessment, due to suspicious behavior and proximity to other malicious sites.

This is a document sharing phishing attack, impersonating a company that the user might interact with in their line of work. This method of attack is used to make the page more convincing for the victim and increase the chances that the link will be clicked. If the user proceeds and tries to view the document, they will be taken to a page that attempts to harvest their Microsoft credentials. Compromised company accounts may be used to send this same type of phishing campaign to additional users, continuing the attack.

Conceal Recommends: Users would not be able to enter credentials due to the site’s isolation by ConcealBrowse.

_____________

SHA-256: 90b16451fb17f95885b11e8e639507f976cbb33131efa11bbcf3753c8d9fab2a

browser-based threat 4.15.25

This page was first detected by ConcealBrowse on April 10th. Security vendors began reporting this site as malicious in December of 2022, with five security vendors flagging this page to date. ConcealBrowse intervened with a 14% risk assessment after detecting suspicious behavior.

Although this website represents a legitimate service, it has been previously shown to have vulnerabilities that allow for the injection of malicious scripts. These scripts can steal data that has been entered into the site, including payment information and account credentials. Sharing passwords across sites can make this form of attack more devasting, as malicious actors can continue to infiltrate other accounts belonging to the victim.

Conceal Recommends: ConcealBrowse’s intervention will prevent users from entering data into the forms on the website, therefore preventing the scripts from stealing information.

_____________

Valuable Outcomes

As this recent threat reports exemplify, ConcealBrowse offers comprehensive protection against many sophisticated cyber threats. Our advanced threat detection capabilities have successfully flagged and quarantined malicious web pages, preventing users from falling victim to various cyber-attacks. Conceal remains dedicated to upholding the integrity of online interactions, constantly refining our detection algorithms and threat identification protocols to ensure proactive protection against emerging cyber threats. By integrating cutting-edge technology and a robust security infrastructure, we empower users to confidently navigate the digital landscape, knowing that their online activities are shielded from potential harm.

Join the Conceal Community and claim your FREE ConcealBrowse licenses!

Join the Conceal Community today and fortify your online security for free! Don’t miss the chance to benefit from our advanced threat protection and stay one step ahead of cybercriminals. Experience peace of mind while browsing the internet, knowing that ConcealBrowse is your shield against the ever-evolving threat landscape. Take the proactive step towards a safer online experience – get your free ConcealBrowse license now and join a community committed to safeguarding your digital world.

Sign up for the Conceal Community and claim your free licenses by completing the form below.