I looked at this goop masquerading as the Israel government. I don't know anything about Israeli stuff, so maybe someone can provide context on what these Threat Actors are trying to achieve.
> israel[.]gov[.]2026[.]vercel[.]app
> domain still live, don't shoot yourself in the foot
> all in hebrew
> fake cloudflare icon
> downloads .vbs file when visiting site
> govilreshet26.vbs
> a074eba155b982fdb821e8a641f6a061505d46d6cc65de031202a4ce29d486fa
> first noted 19 hours ago
> heavily obfuscated
> requests to runas admin
> checks for virtual machines (anti-reverse engineering)
> checks for every AV on the planet earth
> downloads screenconnect (remote desktop software)
> downloads from 130.12.115.24
> IP is small hosting provider in Canada
> clean IP
> clears everything in event viewer
> clears all windows defender logs
> downloads bs file from USA IRS (???)
I don't understand what this is targeting, what it's trying to achieve, or what reshet26 means in this context.
Copy of one brasileiro, who se people sell pdf in nice words and make words became dream, or you call offer or product?, someone can’t be good in copy and code at same timekk