๐บ๐ธ
analysisphishing
2026-04-04 07:00:16
(2 months ago)
We have detected malicious redirection targeting "Jojobet" users, where traffic is diverted to fraud ...
show more
We have detected malicious redirection targeting "Jojobet" users, where traffic is diverted to fraudulent resources such as: https://m.guncel-domain-jojobet.com. This redirection leads unsuspecting users to phishing pages, enabling unauthorized collection of credentials and personal data.
This activity constitutes fraud, unfair competition, and infringement upon our intellectual property rights. It also violates consumer protection regulations by misleading users and causing reputational and financial harm.
We kindly request AbuseIPDB to take prompt measures to disable this malicious infrastructure and prevent further abuse.
Best regards,
Brand Protection Officer
Jojobet Legal Team
show less
Phishing
Hacking
Web App Attack
๐ฏ๐ต
fred
2024-09-18 14:51:52
(1 year ago)
as aeon.pio333qm3.com for Amazon fake login in Japanese
Phishing
๐ฏ๐ต
pota
2024-09-18 11:50:00
(1 year ago)
*** Phishing website Spoofing Amazon.co.jp
genuine site: https://www.amazon.co.jp/
category: E-Com ...
show more
*** Phishing website Spoofing Amazon.co.jp
genuine site: https://www.amazon.co.jp/
category: E-Commerce
e-mail receive date _ URL _ IP:
Wed, 18 Sep 2024 20:02:22 +0900
https://aeon.vouzwandne.com/Wbk3YSAdsafewerasasdweqweqwsDEEEWWasdasdAmazon
2606:4700:3030::6815:14c7 / 2606:4700:3037::ac43:c21f / 172.67.194.31 / 104.21.20.199
Wed, 18 Sep 2024 20:02:35 +0900
https://aeon.pio333qm3.com/Wbk3YSAdsafewerasasdweqweqwsDEEEWWasdasdAmazon
2606:4700:3037::ac43:9d38 / 2606:4700:3036::6815:38f6 / 172.67.157.56 / 104.21.56.246
country: USA
hosting: Cloudflare, Inc (Phishing Site GIGA Factory)
contact form: https://www.cloudflare.com/abuse
show less
Phishing
Email Spam
Spoofing
Anonymous
2021-10-28 06:48:19
(4 years ago)
From: [email protected] On Behalf Of fedex
Abusive RU account fraud โ illicit SM ...
show more
From: [email protected] On Behalf Of fedex
Abusive RU account fraud โ illicit SMTP โ click tracking
UBE (officiacfzzf.bouzagrouuh.com. [45.121.146.108]) Invision Seven Solutions
Spam link junglezoo.site = 162.220.163.169 Interserver Inc โ redirects:
- nlovelyu.com = 102.129.133.27 Digital Energy Technologies Ltd
- tornadospins.com = 104.21.94.41, 172.67.219.81 Cloudflare
- dominionflag.com = 104.21.56.246, 172.67.157.56 Cloudflare
- code.jquery.com = cds.s5x3j6q5.hwcdn.net 69.16.175.10, 69.16.175.42 Highwinds Network Group
- unpkg.com = 104.16.122.175, 104.16.123.175, 104.16.124.175, 104.16.125.175, 104.16.126.175 Cloudflare
- trk-aliquando.com = 104.21.77.189, 172.67.211.43 Cloudflare
- a.mgid.com = 104.19.132.78, 104.19.133.78, 104.19.134.78, 104.19.135.78, 104.19.136.78 Cloudflare
images i.imgur.com 151.101.248.193
/Hjn8gQf.png = Chase survey
/bkDDvZk.png = 115 E 23rd St, New York, NY 10010 - common scam address
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Bad Web Bot
Exploited Host
Anonymous
2021-10-27 13:56:01
(4 years ago)
From: Thank You Venmo <{xxx}[email protected] >
Repetitive RU reward/account fraud
UBE 104.168.204.2 ...
show more
From: Thank You Venmo <{xxx}[email protected] >
Repetitive RU reward/account fraud
UBE 104.168.204.235 (EHLO voluptatumxvrbw.yandex.ru) Hostwinds LLC.
Header comms.aol.net = 159.127.187.11 Epsilon Interactive LLC
Spam link mernashok.co.uk = 185.66.91.122 (previous 176.119.30.16) Virtual Systems LLC โ BLACKLISTED โ redirects:
- openxfunds.com = 195.133.83.239 LLC Baxet
- tornadospins.com = 104.21.94.41, 172.67.219.81 Cloudflare
- dominionflag.com = 104.21.56.246, 172.67.157.56 Cloudflare
- code.jquery.com = cds.s5x3j6q5.hwcdn.net 69.16.175.10, 69.16.175.42 Highwinds Network Group
- unpkg.com = 104.16.122.175, 104.16.123.175, 104.16.124.175, 104.16.125.175, 104.16.126.175 Cloudflare
- trk-aliquando.com = 104.21.77.189, 172.67.211.43 Cloudflare
- a.mgid.com = 104.19.132.78, 104.19.133.78, 104.19.134.78, 104.19.135.78, 104.19.136.78 Cloudflare
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Bad Web Bot
Anonymous
2021-10-26 14:20:48
(4 years ago)
From: T-Mobile <{xxx}@mlk.org.uk>
Abusive RU reward/account fraud
UBE 104.168.211.193 (EHLO utnt ...
show more
From: T-Mobile <{xxx}@mlk.org.uk>
Abusive RU reward/account fraud
UBE 104.168.211.193 (EHLO utntqsd.yandex.ru) Hostwinds LLC.
Header comms.aol.net = 159.127.187.11 Epsilon Interactive LLC
Spam link mernashok.co.uk = 176.119.30.16 Virtual Systems LLC โ BLACKLISTED โ redirects:
- openxfunds.com = 195.133.3.239 LLC Baxet
- tornadospins.com = 104.21.94.41, 172.67.219.81 Cloudflare
- dominionflag.com = 104.21.56.246, 172.67.157.56 Cloudflare
- code.jquery.com = cds.s5x3j6q5.hwcdn.net 69.16.175.10, 69.16.175.42 Highwinds Network Group
- unpkg.com = 104.16.122.175, 104.16.123.175, 104.16.124.175, 104.16.125.175, 104.16.126.175 Cloudflare
- trk-aliquando.com = 104.21.77.189, 172.67.211.43 Cloudflare
- a.mgid.com = 104.19.132.78, 104.19.133.78, 104.19.134.78, 104.19.135.78, 104.19.136.78 Cloudflare
- unsub: cdnjs.cloudflare.com = 104.16.18.94, 104.16.19.94 Cloudflare script
show less
Fraud Orders
Phishing
Email Spam
Spoofing
Bad Web Bot
Anonymous
2021-10-26 10:40:24
(4 years ago)
From: [email protected]
RU account fraud โ illicit SMTP โ click tracking
UBE ...
show more
From: [email protected]
RU account fraud โ illicit SMTP โ click tracking
UBE officiacfzzf.bouzagrouuh.com (officiacfzzf.bouzagrouuh.com. [45.121.146.108]) Invision Seven Solutions
Header officiacfzzf.bouzagrouuh.com = 45.121.146.108 Gigabit Hosting Sdn Bhd
Spam link junglezoo.site = 162.220.163.169 Interserver Inc โ redirects:
- nlovelyu.com = 102.129.133.27 Digital Energy Technologies Ltd
- tornadospins.com = 104.21.94.41, 172.67.219.81 Cloudflare
- dominionflag.com = 104.21.56.246, 172.67.157.56 Cloudflare
- code.jquery.com = cds.s5x3j6q5.hwcdn.net 69.16.175.10, 69.16.175.42 Highwinds Network Group
- unpkg.com = 104.16.122.175, 104.16.123.175, 104.16.124.175, 104.16.125.175, 104.16.126.175 Cloudflare
- trk-aliquando.com = 104.21.77.189, 172.67.211.43 Cloudflare
- a.mgid.com = 104.19.132.78, 104.19.133.78, 104.19.134.78, 104.19.135.78, 104.19.136.78 Cloudflare
i.imgur.com 151.101.248.193
- /u89ypRl.png = 9901 Brodie Lane Ste 160, Austin, TX 78748 - scam address
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Bad Web Bot
Exploited Host
Anonymous
2021-10-25 14:04:47
(4 years ago)
From: T-Mobile <{xxx}@mlk.org.uk>
Repetitive RU reward/account fraud
UBE 188.213.140.138 (EHLO n ...
show more
From: T-Mobile <{xxx}@mlk.org.uk>
Repetitive RU reward/account fraud
UBE 188.213.140.138 (EHLO nginx.com) FIRSTHEBERG
Header comms.aol.net = 159.127.187.11 Epsilon Interactive LLC
Spam link mernashok.co.uk = 176.119.30.16 Virtual Systems LLC โ BLACKLISTED โ redirects:
- openxfunds.com = 195.133.3.239 LLC Baxet
- tornadospins.com = 104.21.94.41, 172.67.219.81 Cloudflare
- dominionflag.com = 104.21.56.246, 172.67.157.56 Cloudflare
- code.jquery.com = cds.s5x3j6q5.hwcdn.net 69.16.175.10, 69.16.175.42 Highwinds Network Group
- unpkg.com = 104.16.122.175, 104.16.123.175, 104.16.124.175, 104.16.125.175, 104.16.126.175 Cloudflare
- trk-aliquando.com = 104.21.77.189, 172.67.211.43 Cloudflare
- a.mgid.com = 104.19.132.78, 104.19.133.78, 104.19.134.78, 104.19.135.78, 104.19.136.78 Cloudflare
- unsub: cdnjs.cloudflare.com = 104.16.18.94, 104.16.19.94 Cloudflare script
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Bad Web Bot
Anonymous
2021-09-21 11:49:22
(4 years ago)
From: Savage Grow Plus <[email protected] >
Pornographic ED fake news - repetitive ...
show more
From: Savage Grow Plus <[email protected] >
Pornographic ED fake news - repetitive scam address
UBE 89.163.219.213 (EHLO sintxintr.smartdrops.me) myLoc managed IT AG
Header smtp.mailfrom=sintxintr.smartdrops.me; - ditto
Spam link triumfator-m.com = 67.198.232.42 Krypt Technologies โ redirects:
- xilosong.com = 69.51.5.18 Arachnitec, INC
- kinoplanets.com = 104.21.84.27, 172.67.185.95 Cloudflare
- dominionflag.com = 104.21.56.246, 172.67.157.56 Cloudflare
- code.jquery.com = 69.16.175.10, 69.16.175.42 Highwinds Network Group - script
- unpkg.com = 104.16.122.175, 104.16.123.175, 104.16.124.175, 104.16.125.175, 104.16.126.175 Cloudflare
- trk-aliquando.com = 104.21.77.189, 172.67.211.43 Cloudflare
- a.mgid.com = 104.19.132.78, 104.19.133.78, 104.19.134.78, 104.19.135.78, 104.19.136.78 Cloudflare
- unsub: x3dr6udo.embtrk.com = 35.239.171.48 Google
Unsub address: no entity name; 801 US Highway 1, North Palm Beach FL 33408 โ REPETITIVE SCAM ADDRESS
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Bad Web Bot
Anonymous
2021-09-17 13:36:04
(4 years ago)
From: Free Flashlight <[email protected] >
Repetitive RU reward fraud/phishing (Home Depot, CVS, W ...
show more
From: Free Flashlight <[email protected] >
Repetitive RU reward fraud/phishing (Home Depot, CVS, Walmart, ...)
UBE 193.0.178.166 (EHLO agharass.xyz) PE Viktor Tyurin
Spam link offfers.duckdns.org = 199.231.188.170 Interserver, Inc โ redirects:
- openxfunds.com = 111.90.139.57 Shinjiru Technology Sdn Bhd
- dimondstardust.com = 69.51.5.14 Arachnitec, INC
- dominionflag.com = 104.21.56.246, 172.67.157.56 Cloudflare
- unpkg.com = 104.16.122.175, 104.16.123.175, 104.16.124.175, 104.16.125.175, 104.16.126.175 Cloudflare
- trk-aliquando.com = 104.21.77.189, 172.67.211.43 Cloudflare
- a.mgid.com = 104.19.132.78, 104.19.133.78, 104.19.134.78, 104.19.135.78, 104.19.136.78 Cloudflare
- upxstream.com = 184.73.162.154, 34.194.208.170 Amazon โ contact: [email protected] = 138.197.213.185, 104.248.224.170, 162.255.118.51, 162.255.118.52 Digital Ocean
http://offfers.duckdns.org/2a7087647abe7fa.jpg = unsub: 3335 S. Airport Rd, Traverse City, MI
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Bad Web Bot
Anonymous
2021-09-16 14:06:48
(4 years ago)
From: "iPhone 13" <[email protected] >
Repetitive RU reward fraud/phishing (Home Depot, CVS, Walma ...
show more
From: "iPhone 13" <[email protected] >
Repetitive RU reward fraud/phishing (Home Depot, CVS, Walmart, ...)
UBE 92.38.171.131 (EHLO amgtd.org.uk) G-Core Labs S.A.
Spam link mernashok.co.uk = 176.119.30.16 Virtual Systems LLC โ redirects:
- openxfunds.com = 111.90.139.57 Shinjiru Technology Sdn Bhd
- kinoplanets.com = 104.21.84.27, 172.67.185.95 Cloudflare
- dominionflag.com = 104.21.56.246, 172.67.157.56 Cloudflare
- unpkg.com = 104.16.122.175, 104.16.123.175, 104.16.124.175, 104.16.125.175, 104.16.126.175 Cloudflare
- trk-aliquando.com = 104.21.77.189, 172.67.211.43 Cloudflare
- a.mgid.com = 104.19.132.78, 104.19.133.78, 104.19.134.78, 104.19.135.78, 104.19.136.78 Cloudflare
Images http://mernashok.co.uk/img
- /w5SpPwEYKgCiF5tK = spoofing Walmart loyalty with free iPhone
- /gAwfBiV5mWVQWMyo = COVID marketing survey
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Bad Web Bot
Anonymous
2021-09-15 07:38:49
(4 years ago)
From: "iPhone 13" <[email protected] >
Repetitive RU reward fraud/phishing (Home Depot, CVS, Walma ...
show more
From: "iPhone 13" <[email protected] >
Repetitive RU reward fraud/phishing (Home Depot, CVS, Walmart, ...)
UBE 92.38.171.131 (EHLO amgtd.org.uk) G-Core Labs S.A.
Spam link mernashok.co.uk = 176.119.30.16 Virtual Systems LLC โ redirects:
- openxfunds.com = 111.90.139.57 Shinjiru Technology Sdn Bhd
- kinoplanets.com = 104.21.84.27, 172.67.185.95 Cloudflare
- dominionflag.com = 104.21.56.246, 172.67.157.56 Cloudflare
- unpkg.com = 104.16.122.175, 104.16.123.175, 104.16.124.175, 104.16.125.175, 104.16.126.175 Cloudflare
- trk-aliquando.com = 104.21.77.189, 172.67.211.43 Cloudflare
- a.mgid.com = 104.19.132.78, 104.19.133.78, 104.19.134.78, 104.19.135.78, 104.19.136.78 Cloudflare
Images http://mernashok.co.uk/img
- /w5SpPwEYKgCiF5tK = spoofing Walmart loyalty with free iPhone
- /gAwfBiV5mWVQWMyo = COVID marketing survey
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Bad Web Bot
Anonymous
2021-09-10 07:48:43
(4 years ago)
From: Home Depot <{xxx}@mlk.org.uk>
Repetitive RU reward fraud/phishing (Home Depot, CVS, Netflix, ...
show more
From: Home Depot <{xxx}@mlk.org.uk>
Repetitive RU reward fraud/phishing (Home Depot, CVS, Netflix, ...)
UBE 23.254.226.89 (EHLO moditxplb.princeton.edu) Hostwinds LLC.
Header Reply-To: "[email protected] " = 159.127.187.11 Epsilon Interactive LLC
Spam link mernashok.co.uk = 176.119.30.16 Virtual Systems LLCโ MALICIOUS โ redirects:
- openxfunds.com = 111.90.139.57 Shinjiru Technology Sdn Bhd
- zuprasting.com = 104.21.83.131, 172.67.176.153 Cloudflare
- dominionflag.com = 104.21.56.246, 172.67.157.56 Cloudflare
- unpkg.com = 104.16.122.175, 104.16.123.175, 104.16.124.175, 104.16.125.175, 104.16.126.175 Cloudflare
- trk-aliquando.com = 104.21.77.189, 172.67.211.43 Cloudflare
- a.mgid.com = 104.19.132.78, 104.19.133.78, 104.19.134.78, 104.19.135.78, 104.19.136.78 Cloudflare
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Bad Web Bot
Anonymous
2021-09-07 14:39:57
(4 years ago)
From: Netflix <[email protected] >
RU scamvertising โ reward fraud/phishing
UBE 23.254.224.182 ...
show more
From: Netflix <[email protected] >
RU scamvertising โ reward fraud/phishing
UBE 23.254.224.182 (EHLO quoceaja.princeton.edu) Hostwinds LLC.
Header Reply-To: "[email protected] " = 159.127.187.11 Epsilon Interactive LLC
Spam link mernashok.co.uk = 176.119.30.16 Virtual Systems LLC (22nd Innovative Street, San Francisco, CA) โ MALICIOUS - redirects:
- openxfunds.com = 111.90.139.57 Shinjiru Technology Sdn Bhd
- zuprasting.com = 104.21.83.131, 172.67.176.153 Cloudflare
- dominionflag.com = 104.21.56.246, 172.67.157.56 Cloudflare
- unpkg.com = 104.16.122.175, 104.16.123.175, 104.16.124.175, 104.16.125.175, 104.16.126.175 Cloudflare
- trk-aliquando.com = 104.21.77.189, 172.67.211.43 Cloudflare
- a.mgid.com = 104.19.132.78, 104.19.133.78, 104.19.134.78, 104.19.135.78, 104.19.136.78 Cloudflare
Images - http://mernashok.co.uk/img
/PGJHP4LMe8Uz1t8o = Netflix reward
/gAwfBiV5mWVQWMyo = COVID vaccine survey
/86CB7f3dQ34N7GW7 = unsub link; no entity name/address
/bOqc6EQL4jWfP6Yv = ditto
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Bad Web Bot
Anonymous
2021-09-06 11:08:01
(4 years ago)
From: UPS <{xxx}@mlk.org.uk>
RU scamvertising โ reward fraud/phishing
UBE 185.174.29.150 (EHLO s ...
show more
From: UPS <{xxx}@mlk.org.uk>
RU scamvertising โ reward fraud/phishing
UBE 185.174.29.150 (EHLO sapienteokpqn.nbcnews.com) CORELUXLTD
Header Reply-To: "[email protected] " = 159.127.187.11 Epsilon Interactive LLC
Spam link mernashok.co.uk = 176.119.30.16 Virtual Systems LLC (22nd Innovative Street, San Francisco, CA 94043) โ redirects:
openxfunds.com = 111.90.139.57 Shinjiru Technology Sdn Bhd
zuprasting.com = 104.21.83.131, 172.67.176.153 Cloudflare
dominionflag.com = 104.21.56.246, 172.67.157.56 Cloudflare
unpkg.com = 104.16.122.175, 104.16.123.175, 104.16.124.175, 104.16.125.175, 104.16.126.175 Cloudflare
trk-aliquando.com = 104.21.77.189, 172.67.211.43 Cloudflare
a.mgid.com = 104.19.132.78, 104.19.133.78, 104.19.134.78, 104.19.135.78, 104.19.136.78 Cloudflare
http://mernashok.co.uk/img -
/Ihvvzqj39MapBVwW = UPS spoofing; no entity/address
/xyJsrUUBszNJosbC = no entity; 337 Garden Oaks Blvd #87987, Houston, TX 77018 - repetitive scam address
show less
Fraud Orders
Phishing
Web Spam
Email Spam
Spoofing
Bad Web Bot