++--------------------------++
Threat Agent:
Advertisements
Website Redirects
Tracking Codes
Potentially Unwanted Downloads and Programs
Threat Level:
Extreme
Attack Vectors:
Postal Mail Service, Email, Email Subscription Service, Money, Credit Card/Debit Charging, Phone Calls, Customer Service Help Line.
Status of the Enterprise:
Active, Ongoing, Prolonged, and very Dangerous to Consumers and Unsuspecting Citizens. Be Warned.
++--------------------------++
Antivirus Positives:
Virus. Vbs. Qexvmc. 1065
https://maltiverse.com/sample/6fb97f6f8a8e729d9907f5b4fd09fc9719a51cff62e7704cf4595a711f946c94
https://www.vmray.com/analyses/6fb97f6f8a8e/report/overview.html
Virus. Vbs. Qexvmc. 1070
https://www.virustotal.com/gui/file/c1f8c2bd8dd936e*******dc8121c39ca53cf212c5a6b07de9b73b5ff6d04adfb7/detection
https://www.virustotal.com/gui/file/aff85c9f07d20d2fdbcaf*******ef*******edd*******f33f97e81fe616aa08/detection
Threat Intelligence:
https://www.mywot.com/scorecard/danburymint.com
https://www.resellerratings.com/store/Danburymint_com
https://www.virustotal.com/gui/ip-address/199.83.132.42/relations
https://www.malwares.com/report/ip?ip=199.83.132.42
https://www.malwares.com/report/file?hash=99C4DC7679BC*******DA20E0B3FFE*******BD491AE5C542D0B*******D2458C09
https://www.virustotal.com/gui/file/99c4dc7679bc*******da20e0b3ffe*******bd491ae5c542d0b*******d2458c09/detection
Back-Engineering Dossier:
https://urlscan.io/dom/*******a0e-78ca-4912-9668-b647acc9e2f6/
Adversary Playbook Navigator:
*Social Engineering [[[Pretexting]]]
*Clicktracking through Google Analytics
*Clickjacking Scripts
*Hard-Sell
*Cold-Calling
*Zero-Sum Attack Vectors and Information Gathering
*Racketeering Activities [Counterfeit Goods, Identity Theft, Credit Card Fraud, Confidence Tricks]
*Malware, Phishing, Trojan Horses, Worms, Malevolent Executable Code
Material Facts:
https://builtwith.com/danburymint.com
https://www.virustotal.com/gui/url/a0ddeddcbd*******bdc718da5b0f54a6587e5bd24f86d4a9ce28aac2942d85/details
https://www.virustotal.com/gui/url/99b797a35f*******d79e1b6d5af0f087ebac79b96f5264e4d6a03c205b49d15b1/detection
https://www.hybrid-analysis.com/sample/d73a590d3a7d33f9384f078df56d7ba1b1992fc44ac5caa61b60cc16cdd*******
++--------------------------++
Antivirus Positives:
Virus. Vbs. Qexvmc. 1065
Virus. Vbs. Qexvmc. 1070
Proof of Concept:
https://www.virustotal.com/gui/file/c1f8c2bd8dd936e*******dc8121c39ca53cf212c5a6b07de9b73b5ff6d04adfb7
https://www.virustotal.com/gui/file/2c855b2cad18b*******f*******e9da1e4f*******cf643a*******b9f*******a89
Security Report Summary:
https://securityheaders.com/?q=www.danburymint.com&followRedirects=on
Attackers Methods:
*Social Engineering
*Clicktracking through Google Analytics
*Clickjacking Scripts
*Racketeering Activities [Counterfeit Goods, Identity Theft, Credit Card Fraud, Confidence Tricks]
*Javascript Trojans
Material Facts:
*Absence of Strict-Transport-Security Headers
*Absence of Content-Security-Policy
*Absence of X-Content-Type-Options
*Absence of Referrer-Policy
*Absence of Feature-Policy
Source Code Archive:
https://urlscan.io/dom/*******a0e-78ca-4912-9668-b647acc9e2f6/
Additional Information:
Server
This Server header seems to advertise the software being run on the server but you can remove or change this value.
X-AspNetMvc-Version
X-AspNetMvc-Version details further information about your ASP.NET MVC version and should be removed.
X-AspNet-Version
X-AspNet-Version details specific information about your ASP.NET version and should be removed.
Set-Cookie
The 'secure' flag is not set on this cookie. There is no Cookie Prefix on this cookie. This is not a SameSite Cookie.
X-Frame-Options
X-Frame-Options tells the browser whether you want to allow your site to be framed or not. By preventing a browser from framing your site you can defend against attacks like clickjacking.