Executive Summary

This report documents an investigation into a localized phishing campaign on the Threads platform. The threat actor used a fake Touch ’n Go “Money Packet” QR code to lure victims to a newly established, Cloudflare-proxied credential-harvesting domain. The investigation extracted the payload, mapped the hidden infrastructure, and produced actionable Indicators of Compromise (IOCs) with an exceptionally low initial detection rate.


Technical Analysis

1. Initial Discovery & Social Engineering Tactic

The investigation began with a suspicious reply under a viral, high-traffic post on Threads.

Threat Actor Modus Operandi:

  • Comment Hijacking: The attacker targeted a high-visibility post to maximize the number of potential victims.
  • Burner Account: A newly created account with 0 followers deployed the payload, a common indicator of the automated or burner accounts used in phishing campaigns.
  • Baiting (Digital Cash Gift): The attacker uploaded an image disguised as a Touch ’n Go “Money Packet”. By mimicking the genuine acts of charity (sedekah) common on local social media, the attacker exploited victims’ trust and enticed them to scan the malicious QR code.

Threat Actor Bait on Threads Figure 1: Analyst Note: The threat actor’s profile picture is redacted to protect the likely innocent individual whose image was scraped to create this burner account.

2. Evidence Acquisition & Secure Handling

The initial evidence consisted of raw screenshots captured on a mobile device during discovery on Threads.

To maintain strict Operational Security (OpSec) and prevent accidental execution or network leakage on the primary device, the screenshots (qrfraud.png) were transferred directly to the CSI Linux digital forensics environment via an isolated local FTP server.

This established a clean chain of custody and confined the investigation to a controlled virtual machine before any extraction tools were applied.

3. Methodology & Operational Security (OpSec)

Before initiating passive reconnaissance against the malicious infrastructure, the CSI Linux environment was verified to route all traffic through the Tor network.

An initial IP check against a standard geolocation service (ipinfo.io) returned a 403 Forbidden error. This signals OpSec success: the server’s Web Application Firewall (WAF) detected and blocked a connection originating from a known Tor exit node.

❯ curl ipinfo.io
<html><head>
<title>403 Forbidden</title>
[...snip...]
<h1>Error: Forbidden</h1>
<h2>Your client does not have permission to get URL <code>/</code> from this server.</h2>

To confirm Tor routing without relying on third-party services that blacklist Tor nodes, the official Tor Project API was used:

❯ curl -s https://check.torproject.org/api/ip
{"IsTor":true,"IP":"[REDACTED]"}

4. Payload Extraction (QR Decoding)

To analyze the malicious QR code safely, without risking accidental execution or triggering tracking mechanisms, extraction was performed strictly offline within the isolated CSI Linux environment.

The zbarimg command-line utility decoded the embedded payload from the evidence file.

❯ zbarimg qrfraud.png
QR-Code:[https://tng.register-lk1.top/Rayamacam2.my2/](https://tng.register-lk1.top/Rayamacam2.my2/)
scanned 1 barcode symbols from 1 images in 0.08 seconds

Analyst Finding: The extraction decoded a malicious URL pointing to a suspicious subdomain (tng.register-lk1.top). The URI path /Rayamacam2.my2/ correlates directly with the “Duit Raya/Sedekah” bait used on Threads. The threat actor crafted the URL to spoof Touch ’n Go (TNG) branding and match the campaign’s theme.

5. DNS Resolution & Infrastructure Masking

A standard DNS query against the malicious subdomain identified its hosting infrastructure.

❯ nslookup tng.register-lk1.top
Server:     127.0.0.53
Address:    127.0.0.53#53

Non-authoritative answer:
Name:   tng.register-lk1.top
Address: 104.21.28.155
Name:   tng.register-lk1.top
Address: 2606:4700:3034::ac43:aae7

Analyst Finding: The nslookup results show the subdomain resolving to 104.21.28.155, an IP address assigned to Cloudflare’s Content Delivery Network (CDN) and Web Application Firewall (WAF).

This confirms the threat actor is using Cloudflare’s reverse proxy to mask their Origin Server IP. Any direct infrastructure scan (such as an Nmap port scan) against this IP would reach only Cloudflare’s edge servers, not the attacker’s actual hosting infrastructure.

6. OSINT & Threat Intelligence Aggregation

To analyze the domain without interacting directly with the live phishing site, passive OSINT queries were run through industry-standard threat intelligence platforms.

Documenting findings as structured text rather than screenshots keeps the Indicators of Compromise (IOCs) easy to extract for threat hunting.

A. VirusTotal Analysis

The exact payload URL (https://tng.register-lk1.top/Rayamacam2.my2/) was queried for existing vendor flags.

  • Detection Ratio: 1/92 security vendors flagged the URL as malicious.
  • Flagging Vendor: ESET identified the URL as “Phishing”.
  • Analysis Date: 2026-10-05 10:24:31 UTC.
  • Analyst Note (Low Detection Rate): The 1/92 detection rate strongly indicates a newly deployed, potentially zero-day phishing campaign. Most legacy signature-based scanners have not yet blacklisted this URL, making the threat highly elusive to standard endpoint protection.

B. URLScan.io Sandbox Execution

URLScan.io safely executed a remote HTTP request and captured the web server’s response and DOM structure.

  • Target: https://tng.register-lk1.top/Rayamacam2.my2/
  • Submission Date: October 5th 2026, 10:24:13 am UTC
  • Primary IP: 172.67.170.231 (CLOUDFLARENET)
  • DNS A Record: 104.21.28.155 (CLOUDFLARENET)
  • Page Title: “A surprise Money Packet for you!”
  • Detected Technologies: cdnjs, Font Awesome, jQuery, jsDelivr
  • TLS Certificate: Issued by WE1 on October 2nd 2026. Valid for 3 months.
  • Summary: The sandbox loaded the phishing landing page. Its title (“A surprise Money Packet for you!”) correlates directly with the “Duit Raya/Sedekah” bait. The recent TLS certificate issuance (Oct 2, 2026) further supports the hypothesis that this is newly created infrastructure built for a short-term campaign.

URLScan Sandbox Capture Figure 2: Automated sandbox execution rendering the deceptive Touch ’n Go phishing interface.

C. DNSDumpster (Historical DNS Reconnaissance)

The root domain (register-lk1.top) was analyzed for Origin IP leaks and misconfigured DNS records (such as MX or TXT records) that bypass the Cloudflare proxy.

  • Nameservers (NS): The domain delegates DNS resolution exclusively to Cloudflare’s infrastructure (jaxson.ns.cloudflare.com and candy.ns.cloudflare.com).
  • Finding: The threat actor maintained strict OpSec in their DNS configuration. The mapping graph shows no historical Origin IP leaks, no exposed MX records, and no direct A records bypassing the CDN.
  • Evidence Handling: The raw DNS reconnaissance data was exported as an XLSX file (register-lk1.top-eb89694b-8aa9-494c-8ceb-d2c1ee5a43f0.xlsx) and stored with the visual mapping graphs in the local investigation vault.

DNSDumpster Data Records Figure 3: DNSDumpster text data records showing the Cloudflare proxy infrastructure configuration.

DNSDumpster Mapping Graph Figure 4: Visual DNS mapping graph generated by DNSDumpster confirming no historical origin IP leaks.

7. Conclusion & Indicators of Compromise (IOCs)

Investigation Summary: The investigation unmasked a localized phishing campaign operating on Threads. The threat actor used a burner account to distribute a malicious QR code disguised as a Touch ’n Go “Money Packet”. The embedded payload directs victims to a newly established, Cloudflare-proxied domain designed to harvest user credentials and eWallet data. The exceedingly low detection rate (1/92 on VirusTotal) indicates an active, rapid-deployment campaign.

Indicators of Compromise (IOCs): To assist network defenders and SOC teams, the following IOCs were extracted from this investigation:

TypeIndicatorDescription
URLhttps://tng.register-lk1.top/Rayamacam2.my2/Primary phishing payload embedded in QR code
Domaintng.register-lk1.topMalicious subdomain hosting the fake TNG gateway
Root Domainregister-lk1.topParent domain (suspected malicious infrastructure)
IP Address104.21.28.155Cloudflare Proxy IP (CDN/WAF)
IP Address172.67.170.231Cloudflare Proxy IP (CDN/WAF)
Social Engineering“A surprise Money Packet for you!”HTML Page Title used as bait