Hosting phishing / illegal scrape of Ashoo.com content at https://msknew2.minti.vip/ and apex minti. ...
show moreHosting phishing / illegal scrape of Ashoo.com content at https://msknew2.minti.vip/ and apex minti.vip. Litreev Technologies OU, [email protected].
show less
Hosting referrer-gated phishing / illegal scrape clone of Ashoo.com at https://xxzakaz.com/ (www.xxz ...
show moreHosting referrer-gated phishing / illegal scrape clone of Ashoo.com at https://xxzakaz.com/ (www.xxzakaz.com). Litreev Technologies OU, [email protected].
show less
Hosting phishing / illegal scrape clone of Ashoo.com at https://pizdamba.com/ (Litreev Technologies ...
show moreHosting phishing / illegal scrape clone of Ashoo.com at https://pizdamba.com/ (Litreev Technologies OU, [email protected]). SEO/phishing abuse against Ashoo.com.
show less
Hosts phishing/content-scrape clone feipiter.nl (redirects to feipiter.one) illegally scraping Ashoo ...
show moreHosts phishing/content-scrape clone feipiter.nl (redirects to feipiter.one) illegally scraping Ashoo.com. Reported by Litreev Technologies OU [email protected]. URL: https://feipiter.nl/
show less
Hosts trademark lookalike/impersonation site ashooo.moscow (Ashoo/ะัั). Illegal scrape/phishing risk ...
show moreHosts trademark lookalike/impersonation site ashooo.moscow (Ashoo/ะัั). Illegal scrape/phishing risk against Ashoo.com. Reported by Litreev Technologies OU [email protected]. URL: https://ashooo.moscow/
show less
Hosts phishing/content-scrape clone sites mos-wom.net and moswwom.com impersonating/illegally scrapi ...
show moreHosts phishing/content-scrape clone sites mos-wom.net and moswwom.com impersonating/illegally scraping Ashoo.com (Litreev Technologies OU client). Reported by [email protected]. URLs: https://mos-wom.net/ https://moswwom.com/
show less
Hosting IP for elitemoscow.net. Site illegally scrapes/copies content from legitimate Ashoo.com (cli ...
show moreHosting IP for elitemoscow.net. Site illegally scrapes/copies content from legitimate Ashoo.com (client of Litreev Technologies OU), SEO manipulation and phishing/impersonation. Reported by Aleksandr LITREEV, [email protected]. URL: https://elitemoscow.net/
show less
Hosting IP for escortland.vip and ant-models.fit. Sites illegally scrape/copy content from legitimat ...
show moreHosting IP for escortland.vip and ant-models.fit. Sites illegally scrape/copy content from legitimate Ashoo.com (client of Litreev Technologies OU), engage in SEO manipulation and phishing/impersonation. Reported by Aleksandr LITREEV, [email protected]. URLs: https://escortland.vip/ https://ant-models.fit/
show less
Hosting phishing/impersonation sites ashoos.net and ashoou.org impersonating Ashoo.com (trademark/ph ...
show moreHosting phishing/impersonation sites ashoos.net and ashoou.org impersonating Ashoo.com (trademark/phishing). Reported by Litreev Technologies OU / [email protected]. Sites served over nginx on this origin IP (not Cloudflare proxy).
show less
Phishing / illegal scrape impersonation of Ashoo.com. Malicious URLs: https://s2.indihousee.org/ and ...
show morePhishing / illegal scrape impersonation of Ashoo.com. Malicious URLs: https://s2.indihousee.org/ and apex https://indihousee.org/. Reported by Litreev Technologies OU security ([email protected]).
show less
TTPs: Impersonation of European law enforcement, fake government domains, cross-border SMS/iMessage ...
show moreTTPs: Impersonation of European law enforcement, fake government domains, cross-border SMS/iMessage delivery from Southeast Asia, and escalation threats.
IoCs: https://otx.alienvault.com/pulse/6a0c40
show less
The domain ashoo[.]buzz operates as a fraudulent impersonation site that copies and misuses the bran ...
show moreThe domain ashoo[.]buzz operates as a fraudulent impersonation site that copies and misuses the brand, name, and visual elements of the legitimate adult platform Ashoo. The site blocks direct access and only opens when the browserโs Referer header shows it was reached via Google or Yandex search results.
show less
The domain b[.]prostitutki24[.]su is operating as a fraudulent impersonation site that deliberately ...
show moreThe domain b[.]prostitutki24[.]su is operating as a fraudulent impersonation site that deliberately copies and misuses the brand, name, and elements of the legitimate adult entertainment platform Ashoo
https://otx.alienvault.com/pulse/69ea517a5f0bd47c01d88fd6
show less
The domain ashoo-znakomstva[.]ru hosted on this IP address is operating as a fraudulent impersonatio ...
show moreThe domain ashoo-znakomstva[.]ru hosted on this IP address is operating as a fraudulent impersonation site that deliberately copies and misuses the brand, name, and elements of the legitimate adult entertainment platform Ashoo. Threat Pulse on OTX: https://otx.alienvault.com/pulse/69e8e20bb9e91dec5330e3b4
show less
The domain ashoo-znakomstva[.]ru hosted on this IP address is operating as a fraudulent impersonatio ...
show moreThe domain ashoo-znakomstva[.]ru hosted on this IP address is operating as a fraudulent impersonation site that deliberately copies and misuses the brand, name, and elements of the legitimate adult entertainment platform Ashoo. Threat Pulse on OTX: https://otx.alienvault.com/pulse/69e8e20bb9e91dec5330e3b4
show less
The domain ashoomoskva.[]com on this IP address is operating as a fraudulent impersonation site that ...
show moreThe domain ashoomoskva.[]com on this IP address is operating as a fraudulent impersonation site that deliberately copies and misuses the brand, name, and elements of the legitimate adult entertainment platform Ashoo.
Threat Pulse on OTX: https://otx.alienvault.com/pulse/69e26f6cb2397ab9987a36f5
show less
Specified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting ...
show moreSpecified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting individuals in the Baltics. The threat actor is using the same exact payload as UNC6748, except for a different C2 endpoint (presumably because the old one is already present in threat intelligence feeds).
https://otx.alienvault.com/pulse/69c5ad2cc15ddbc70c30c4fe
show less
Specified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting ...
show moreSpecified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting individuals in the Baltics. The threat actor is using the same exact payload as UNC6748, except for a different C2 endpoint (presumably because the old one is already present in threat intelligence feeds).
https://otx.alienvault.com/pulse/69c5ad2cc15ddbc70c30c4fe
show less
Specified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting ...
show moreSpecified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting individuals in the Baltics. The threat actor is using the same exact payload as UNC6748, except for a different C2 endpoint (presumably because the old one is already present in threat intelligence feeds).
https://otx.alienvault.com/pulse/69c5ad2cc15ddbc70c30c4fe
show less
Specified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting ...
show moreSpecified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting individuals in the Baltics. The threat actor is using the same exact payload as UNC6748, except for a different C2 endpoint (presumably because the old one is already present in threat intelligence feeds).
https://otx.alienvault.com/pulse/69c5ad2cc15ddbc70c30c4fe
show less
Specified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting ...
show moreSpecified IPs were used by Russian state-sponsored hackers for DarkSword RCE exploitation, targeting individuals in the Baltics. The threat actor is using the same exact payload as UNC6748, except for a different C2 endpoint (presumably because the old one is already present in threat intelligence feeds).
https://otx.alienvault.com/pulse/69c5ad2cc15ddbc70c30c4fe
show less
PhishingHacking
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.