๐บ๐ธ
analysisphishing
2026-04-29 13:36:54
(1 month ago)
We have detected malicious redirection targeting "Betper" users, where traffic is diverted to fraudu ...
show more
We have detected malicious redirection targeting "Betper" users, where traffic is diverted to fraudulent resources such as: https://tr.betper-1.vip. This redirection leads unsuspecting users to phishing pages, enabling unauthorized collection of credentials and personal data.
This activity constitutes fraud, unfair competition, and infringement upon our intellectual property rights. It also violates consumer protection regulations by misleading users and causing reputational and financial harm.
We kindly request AbuseIPDB to take prompt measures to disable this malicious infrastructure and prevent further abuse.
Best regards,
Brand Protection Officer
Betper Legal Team
show less
Phishing
Hacking
Web App Attack
๐ฏ๐ต
pota
2024-07-28 06:54:00
(1 year ago)
*** Phishing website Spoofing Amazon.co.jp
genuine site: https://www.amazon.co.jp/
category: E-Com ...
show more
*** Phishing website Spoofing Amazon.co.jp
genuine site: https://www.amazon.co.jp/
category: E-Commerce
---- redirect from
URL:
https://izffmluowhhfjvglbfpjx.ifanmy.cn/caonima
https://sxthkdhqvwyiwc.ifanmy.cn/caonima
https://odaiexfiwtwalullawwcgduhk.ifanmy.cn/caonima
https://irjbznnkvkjxvjoisfcdtrgvq.ifanmy.cn/caonima
https://sfnrxvxebjpezlsjqgta.ifanmy.cn/caonima
https://cjwpjqcbvjrhwzlruzukdpxdt.ifanmy.cn/caonima
https://ozjyrpefemaijsyhmxgykxg.ifanmy.cn/caonima
IP address: 2606:4700:3037::6815:3c23 / 2606:4700:3032::ac43:bf21 / 104.21.60.35 / 172.67.191.33
country: USA
hosting: Cloudflare, Inc (Phishing Site GIGA Factory)
contact form: https://www.cloudflare.com/abuse
---- redirect to
URL:
[129.226.210.239]
http://logisgate.cn/
http://hiluu.cn/
[43.134.94.72]
http://aepfiad.cn/
http://pruk.cn/
IP address: 129.226.210.239 / 43.134.94.72
country: Japan / Singapore
hosting: Tencent Cloud Computing / Aceville Pte.Ltd.
contact form: https://www.tencentcloud.com/contact-us
show less
Phishing
Email Spam
Spoofing
๐ฏ๐ต
Nanoniele
2024-07-28 05:41:00
(1 year ago)
Phishing; jmedadayzdxpkmfijxx.ifanmy.cn -> etdenll.cn; Amazon.
Phishing
Email Spam
Spoofing
๐ฏ๐ต
fred
2024-07-27 15:02:49
(1 year ago)
as kksxnohzpcsxtbjynejbl.ifanmy.cn for Amazon fake login in Japanese
Phishing
๐ฏ๐ต
Nanoniele
2024-07-27 14:35:00
(1 year ago)
Phishing; eqcgrfojvvbfhlpq.ifanmy.cn -> imeler.cn; Amazon.
Phishing
Email Spam
Spoofing
๐ฏ๐ต
pota
2024-07-27 09:55:00
(1 year ago)
*** Phishing website Spoofing Amazon.co.jp
genuine site: https://www.amazon.co.jp/
category: E-Com ...
show more
*** Phishing website Spoofing Amazon.co.jp
genuine site: https://www.amazon.co.jp/
category: E-Commerce
---- redirect from
URL:
https://izffmluowhhfjvglbfpjx.ifanmy.cn/caonima
https://sxthkdhqvwyiwc.ifanmy.cn/caonima
https://odaiexfiwtwalullawwcgduhk.ifanmy.cn/caonima
https://irjbznnkvkjxvjoisfcdtrgvq.ifanmy.cn/caonima
https://sfnrxvxebjpezlsjqgta.ifanmy.cn/caonima
https://cjwpjqcbvjrhwzlruzukdpxdt.ifanmy.cn/caonima
IP address: 2606:4700:3037::6815:3c23 / 2606:4700:3032::ac43:bf21 / 104.21.60.35 / 172.67.191.33
country: USA
hosting: Cloudflare, Inc (Phishing Site GIGA Factory)
contact form: https://www.cloudflare.com/abuse
---- redirect to
URL:
[129.226.210.239]
http://logisgate.cn/
http://hiluu.cn/
[43.134.94.72]
http://aepfiad.cn/
IP address: 129.226.210.239 / 43.134.94.72
country: Japan / Singapore
hosting: Tencent Cloud Computing / Aceville Pte.Ltd.
contact form: https://www.tencentcloud.com/contact-us
show less
Phishing
Email Spam
Spoofing
๐ฏ๐ต
fred
2024-07-27 05:59:08
(1 year ago)
as oavvvqmbvedwekyoz.ifanmy.cn for Amazon fake login in Japanese
Phishing
๐ฏ๐ต
fred
2024-07-26 17:34:56
(1 year ago)
as mocydrbpdcbkqcrjiaulqkod.ifanmy.cn for Amazon fake login in Japanese;
again 5 hrs later
Phishing
๐ฏ๐ต
pota
2024-07-26 12:57:00
(1 year ago)
*** Phishing website Spoofing Amazon.co.jp
genuine site: https://www.amazon.co.jp/
category: E-Com ...
show more
*** Phishing website Spoofing Amazon.co.jp
genuine site: https://www.amazon.co.jp/
category: E-Commerce
---- redirect from
e-mail receive date _ URL:
Thu, 25 Jul 2024 19:42:55 +0900 _ https://izffmluowhhfjvglbfpjx.ifanmy.cn/caonima
Fri, 26 Jul 2024 03:17:10 +0900 _ https://sxthkdhqvwyiwc.ifanmy.cn/caonima
Fri, 26 Jul 2024 18:57:50 +0900 _ https://odaiexfiwtwalullawwcgduhk.ifanmy.cn/caonima
IP address: 2606:4700:3037::6815:3c23 / 2606:4700:3032::ac43:bf21 / 104.21.60.35 / 172.67.191.33
country: USA
hosting: Cloudflare, Inc (Phishing Site GIGA Factory)
contact form: https://www.cloudflare.com/abuse
---- redirect to
URL:
http://logisgate.cn/
http://hiluu.cn/
IP address: 129.226.210.239
country: Japan / Singapore
hosting: Tencent Cloud Computing / Aceville Pte.Ltd.
contact form: https://www.tencentcloud.com/contact-us
e-mail: [email protected] , [email protected] , [email protected]
show less
Phishing
Email Spam
Spoofing
๐ฏ๐ต
Nanoniele
2024-07-26 04:11:00
(1 year ago)
Phishing; yuhhaadvjlgasxyibubknzoo.ifanmy.cn -> biaojingd.cn; Amazon.
Phishing
Email Spam
Spoofing
๐ฏ๐ต
fred
2024-07-26 01:49:48
(1 year ago)
as fripmggpyriwkhcc.ifanmy.cn for Amazon fake login in Japanese
Phishing
๐ฏ๐ต
pota
2024-07-25 12:52:00
(1 year ago)
*** Phishing website Spoofing Amazon.co.jp
genuine site: https://www.amazon.co.jp/
category: E-Com ...
show more
*** Phishing website Spoofing Amazon.co.jp
genuine site: https://www.amazon.co.jp/
category: E-Commerce
---- redirect from
e-mail receive date: Thu, 25 Jul 2024 19:42:55 +0900
URL: https://izffmluowhhfjvglbfpjx.ifanmy.cn/caonima
IP address: 2606:4700:3037::6815:3c23 / 2606:4700:3032::ac43:bf21 / 104.21.60.35 / 172.67.191.33
country: USA
hosting: Cloudflare, Inc (Phishing Site GIGA Factory)
contact form: https://www.cloudflare.com/abuse
---- redirect to
URL: http://logisgate.cn/
IP address: 129.226.210.239
country: Japan / Singapore
hosting: Tencent Cloud Computing / Aceville Pte.Ltd.
contact form: https://www.tencentcloud.com/contact-us
e-mail: [email protected] , [email protected] , [email protected]
show less
Phishing
Email Spam
Spoofing
Anonymous
2022-11-28 16:48:55
(3 years ago)
From: Congrats! <[email protected] >
Subject: undefined, Order #18372018182 is arriving.....
...
show more
From: Congrats! <[email protected] >
Subject: undefined, Order #18372018182 is arriving.....
Delivery fraud/phishing โ ref image: fraudulent Pfizer treatment survey <http://img.ukimya.com/i/072022/77716185_0.png>
Ref 10620 NW 123 Street Road Unit 102, Medley, Florida โ UPS drop-box. Per Snopes, UPS link redirects to souldatabase.ru (not verified)
Repetitive scamvertising, reward scam, account scam, pay-per-click tracking. Abusive spam series <[email protected] >.
Received: from 103.67.247.80 (EHLO ukya-247080.ukimya.com)
Header ukimya.com = 103.67.247.79, 103.67.247.80, 103.67.247.81, 103.67.247.82 Wowway Labs
Message URL t.ukimya.com = 103.18.251.221 Wowway Labs โ redirect:
- www.zinvvv.com = 45.86.79.21 DediPath
- contagion1189.com = 104.21.60.35, 172.67.191.33 Cloudflare โ MALICIOUS
- unsub: opt.listarmor.com = 206.189.197.92 DigitalOcean
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Bad Web Bot
Exploited Host
Anonymous
2022-09-07 17:35:38
(3 years ago)
From: Pfizer <[email protected] >
Subject: undefined, Order #18372018182 is arriving.....
Repet ...
show more
From: Pfizer <[email protected] >
Subject: undefined, Order #18372018182 is arriving.....
Repetitive [email protected] - mix of spamvertising, account fraud, reward scam. Zero response from ISP.
Note โ Per Snopes, listed address tied to RU reward fraud: 10620 NW 123 Street Road Unit 102, Medley, Florida
Received: from 103.67.247.81 (EHLO ukya-247081.ukimya.com) Wowway Labs Private Limited
Header ukimya.com = 103.67.247.79, 103.67.247.80, 103.67.247.81, 103.67.247.82 Wowway Labs Private Limited
Message URL t.ukimya.com = 103.18.251.221 Wowway Labs โ redirect BOT:
- www.zinvvv.com = 45.86.79.21 DediPath
- contagion1189.com = 104.21.60.35, 172.67.191.33 Cloudflare โ per Norton: dangerous web page
- landing: birdinvestment.ru = 104.21.24.204, 172.67.220.135 Cloudflare
- pushrev.neptuneadspush.com = 104.21.87.10, 172.67.139.33 Cloudflare
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Bad Web Bot
Exploited Host