vxunderground
I looked at this goop masquerading as the Israel government. I don't know anything about Israeli stuff, so maybe someone can provide context on what these Threat Actors are trying to achieve. > israel[.]gov[.]2026[.]vercel[.]app > domain still live, don't shoot yourself in the foot > all in hebrew > fake cloudflare icon > downloads .vbs file when visiting site > govilreshet26.vbs > a074eba155b982fdb821e8a641f6a061505d46d6cc65de031202a4ce29d486fa > first noted 19 hours ago > heavily obfuscated > requests to runas admin > checks for virtual machines (anti-reverse engineering) > checks for every AV on the planet earth > downloads screenconnect (remote desktop software) > downloads from 130.12.115.24 > IP is small hosting provider in Canada > clean IP > clears everything in event viewer > clears all windows defender logs > downloads bs file from USA IRS (???) I don't understand what this is targeting, what it's trying to achieve, or what reshet26 means in this context.