Indicators of Compromise (IOCs):
Domain: botonpp.turnosrevitec.com
Hosting IP: 50.6.184.25
...
show moreIndicators of Compromise (IOCs):
Domain: botonpp.turnosrevitec.com
Hosting IP: 50.6.184.25
Malicious Activity: Financial Fraud, PII Theft, Phishing.
Technical Details of the Attack:
Fake Payment Gateway: The frontend simulates a checkout process, prompting users for their full name, National ID (DNI), date of birth, email, phone number, and full credit card details.
Luhn Algorithm Validation: The attackers are running local JavaScript to validate credit card numbers mathematically before submission, ensuring they only collect valid cards.
Dynamic Exfiltration Endpoints: To evade automated analysis and basic WAF rules, the attackers are using dynamic POST endpoints and Anti-CSRF tokens for data exfiltration (e.g., action="/a44845f623713b4856651c598acf029b" and action="/43217337862c3cab2ebdeb325a3ae6c9").
Evasion Tactics: The stolen data is being encrypted via a local AES script (AESEncrypter.js) before being sent to the backend, bypassing network inspection tools.
show less
This IP is currently hosting an active phishing website. The malicious domain is: hxxp://botonplus.t ...
show moreThis IP is currently hosting an active phishing website. The malicious domain is: hxxp://botonplus.turnoszentroar.com. Please review.
show less
The domain https://serviciospp.zenixvtv.com/ hosted on this IP is actively running a phishing campai ...
show moreThe domain https://serviciospp.zenixvtv.com/ hosted on this IP is actively running a phishing campaign. The site is designed to deceive visitors into submitting sensitive personal information and credentials. Please investigate and suspend the malicious activity.
show less
Phishing
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.