https://storage.googleapis.com/xcvbds1bdf351gze3r5g/d1b3e5rfd2r.html
Content:
<script>document ...
show morehttps://storage.googleapis.com/xcvbds1bdf351gze3r5g/d1b3e5rfd2r.html
Content:
<script>document.location.href = 'http://undertalehadid.net/anchor'+window.location.href.split('#')[1];</script>
Reloads to undertalehadid.net and the string behind anchor is used to track the victim of the phishing
undertalehadid.net is malicious,
see
https://www.virustotal.com/gui/domain/undertalehadid.net
https://urlscan.io/search/#undertalehadid.net
show less
https://storage.googleapis.com/65f4g/ddd21c23/trackingh.html
Content:
<script>
var tarcking_par ...
show morehttps://storage.googleapis.com/65f4g/ddd21c23/trackingh.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "apexhorizoncraft.com";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/t/'+tarcking_param;
}
</script>
Script is used to redirect victims to apexhorizoncraft.com and still another domain by tracking parameters, like intotechworld.com
Malicious, see
https://urlscan.io/search/#apexhorizoncraft.com
https://www.virustotal.com/gui/domain/apexhorizoncraft.com
https://www.virustotal.com/gui/domain/intotechworld.com
show less
frizrake.com
Part of reload chain used by pishing criminals
Malicious, see
https://urlscan.io ...
show morefrizrake.com
Part of reload chain used by pishing criminals
Malicious, see
https://urlscan.io/search/#frizrake.com
show less
https://storage.googleapis.com/12fg4new24/newdfs5.html
Content:
<script>
var tarcking_param = w ...
show morehttps://storage.googleapis.com/12fg4new24/newdfs5.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "apexhorizoncraft.com";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/t/'+tarcking_param;
}
</script>
Script is used to redirect victims to apexhorizoncraft.com and still another domain by tracking parameters, like intotechworld.com
Malicious, see
https://urlscan.io/search/#apexhorizoncraft.com
https://www.virustotal.com/gui/domain/apexhorizoncraft.com
https://www.virustotal.com/gui/domain/intotechworld.com
show less
thepetgroomy.com
Part of reload chain used by phishing criminals:
https://thepetgroomy.com/vbvcv ...
show morethepetgroomy.com
Part of reload chain used by phishing criminals:
https://thepetgroomy.com/vbvcvfdfg/fggfdfg
show less
https://storage.googleapis.com/hqyoqzatqthj/aemmfcylvxeo.html
Content:
<script>document.location ...
show morehttps://storage.googleapis.com/hqyoqzatqthj/aemmfcylvxeo.html
Content:
<script>document.location.href = 'http://weatherthisday.com/anchor'+window.location.href.split('#')[1];</script>
Reloads to weatherthisday.com and uses parameters after # for redirecting to another domain, like
Malicious, see
https://www.virustotal.com/gui/url/045641ae04917162f223915be90e90c3b66ad650dec1051e09b8eb7d7a6571c2
https://urlscan.io/search/#weatherthisday.com
show less
https://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
Content:
<script>document.loc ...
show morehttps://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
Content:
<script>document.location.href = 'http://tourismalaysia.com/anchor'+window.location.href.split('#')[1];</script>
Domain used in phishing reload chain
See https://urlscan.io/search/#tourismalaysia.com
show less
https://storage.googleapis.com/q1nvblpxt2wxrbts/1c2msqnp4kjmyv0h/acf3b3f.html
Content:
<script ...
show morehttps://storage.googleapis.com/q1nvblpxt2wxrbts/1c2msqnp4kjmyv0h/acf3b3f.html
Content:
<script type="text/javascript">
function getHash() {
if (window.location.hash) {
var hash = window.location.hash.substring(1);
if (hash.length > 5) {return hash;} else {return false;}
} else {return false;}
}
var hashCode = getHash();var dom = "http://helpinneed.asso.eu.org";
if(hashCode){var url = dom+"/"+hashCode;}else{var url = dom+"/404.html";}
window.location.replace(url);
</script>
helpinneed.asso.eu.org
Script is used by phishing criminals to redirect victims to another domain
Malicious, see
https://urlscan.io/search/#helpinneed.asso.eu.org
https://www.virustotal.com/gui/domain/helpinneed.asso.eu.org
show less
https://storage.googleapis.com/b1tr3h2erd32gzeg/bv1re31d2fger.html
Content:
<script>document.loc ...
show morehttps://storage.googleapis.com/b1tr3h2erd32gzeg/bv1re31d2fger.html
Content:
<script>document.location.href = 'http://abqopenhouse.com/anchor'+window.location.href.split('#')[1];</script>
Reloads to abqopenhouse.com and this domain uses the parameters after # to redirect victims to the phishing website, like datawhich.com (https://www.virustotal.com/gui/domain/datawhich.com)
Malicious, see
https://www.virustotal.com/gui/domain/abqopenhouse.com
https://urlscan.io/search/#abqopenhouse.com
show less
dxn4ksd3j.com
Part of reload chain used by phishing criminals
Malicious, see
https://urlscan. ...
show moredxn4ksd3j.com
Part of reload chain used by phishing criminals
Malicious, see
https://urlscan.io/search/#dxn4ksd3j.com
https://www.virustotal.com/gui/url/732fd29007a5e02e6f0b063862a721c18359dc64a668777bce232c7621304a00/detection
show less
tyingree.com
Part of phishing reload chain:
Malicious, see
https://urlscan.io/search/#tyingree. ...
show moretyingree.com
Part of phishing reload chain:
Malicious, see
https://urlscan.io/search/#tyingree.com
https://www.virustotal.com/gui/url-analysis/u-e4e5fa3289bbd50786546b91bb35018d54e722b2c659a4b70be434206538d2ef-1732381221
show less
https://storage.googleapis.com/xcvbds1bdf351gze3r5g/d1b3e5rfd2r.html
Content:
<script>document ...
show morehttps://storage.googleapis.com/xcvbds1bdf351gze3r5g/d1b3e5rfd2r.html
Content:
<script>document.location.href = 'http://undertalehadid.net/anchor'+window.location.href.split('#')[1];</script>
Reloads to undertalehadid.net and the string behind anchor is used to track the victim of the phishing
undertalehadid.net is malicious,
see
https://www.virustotal.com/gui/domain/undertalehadid.net
https://urlscan.io/search/#undertalehadid.net
show less
https://storage.googleapis.com/bhsales25/bhsales4wd.html
Content:
<script>
var tarcking_param = ...
show morehttps://storage.googleapis.com/bhsales25/bhsales4wd.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "185.80.128.4";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/?'+tarcking_param;
}
</script>
Script reloads to IP 185.80.128.4 and the string after # is used to track the victim and to redirect the victims to the phishing domain like intotechworld.com (malicious, see https://www.virustotal.com/gui/domain/intotechworld.com)
Malicious, see
https://www.virustotal.com/gui/ip-address/185.80.128.4/detection
https://urlscan.io/search/#185.80.128.4
show less
https://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
Content:
<script>document.loc ...
show morehttps://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
Content:
<script>document.location.href = 'http://tourismalaysia.com/anchor'+window.location.href.split('#')[1];</script>
Domain used in phishing reload chain
show less
https://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
Content:
<script>document.loc ...
show morehttps://storage.googleapis.com/fdg13erh2e3r1h5rtj/g1erh6r5the.html
Content:
<script>document.location.href = 'http://tourismalaysia.com/anchor'+window.location.href.split('#')[1];</script>
Domain used in phishing reload chain
show less
https://storage.googleapis.com/bhsales25/bhsales4wd.html
Content:
<script>
var tarcking_param = ...
show morehttps://storage.googleapis.com/bhsales25/bhsales4wd.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "185.80.128.4";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/?'+tarcking_param;
}
</script>
Script reloads to IP 185.80.128.4 and the string after # is used to track the victim and to redirect the victims to the phishing domain like intotechworld.com (malicious, see https://www.virustotal.com/gui/domain/intotechworld.com)
Malicious, see
https://www.virustotal.com/gui/ip-address/185.80.128.4/detection
https://urlscan.io/search/#185.80.128.4
show less
https://storage.googleapis.com/xcvbds1bdf351gze3r5g/d1b3e5rfd2r.html
Content:
<script>documen ...
show morehttps://storage.googleapis.com/xcvbds1bdf351gze3r5g/d1b3e5rfd2r.html
Content:
<script>document.location.href = 'http://undertalehadid.net/anchor'+window.location.href.split('#')[1];</script>
Reloads to undertalehadid.net and the string behind anchor is used to track the victim of the phishing
undertalehadid.net is malicious,
see
https://www.virustotal.com/gui/domain/undertalehadid.net
https://urlscan.io/search/#undertalehadid.net
show less
https://storage.googleapis.com/loblaman996655/lobla.html
Content:
<script>document.location.href ...
show morehttps://storage.googleapis.com/loblaman996655/lobla.html
Content:
<script>document.location.href = 'http://moviedownloadserver.com//anchor'+window.location.href.split('#')[1];</script>
moviedownloadserver.com
Malicious, see
https://urlscan.io/search/#moviedownloadserver.com
show less
PhishingEmail Spam
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.