Of the 60 domains that resolve to this IP, not a single one of them is legitimate. deliveries-mypostoffice.com delivery—dpd.com delivery-service-centre.com dpd-deliveryinfo.net dpd-official-online.com dpd-parcel-info.com dpd-parceltrack.com dpd-postal-redirect.com dpd-redirect-postal.com dpd-reshipment-fees.com dpdlocal-update.com dpdlocal-updates.com ee-missed-payment.com And MANY more.
Автор: blog
Abused / misconfigured newsletter service (listbombing)
The host at this IP address is being (ab)used to «listbomb» email addresses: From: ICYS ExCom <icecoreys@gmail.com> Subject: ICYS 8th Seminar 19th August 21:00-22:00 UTC Problem description ============================ Spammers signed up for the bulk email service using the victim’s email address. As a result, the victim is being «listbombed» with transactional messages and bulk email… Читать далее Abused / misconfigured newsletter service (listbombing)
Phishing redirector — Bitcoin fraud
SBL530274 has a payload on $ host www.haveafroginthroat.com www.haveafroginthroat.com has address 34.102.211.173 which we think exists for this purpose only.
freecpewebinar.com (A, website) (Pioneer Educator)
Google hosts the A record and website of the domain freecpewebinar.com. The owners of this domain are using ESP Benchmark Email to send spam emails to scraped, purchased or appended lists. Google: Please do NOT continue to allow spammers to abuse your network! Received: from pmta604.dedicated.bmsend.com (pmta604.dedicated.bmsend.com [12.174.236.139]) Date: Sat, 21 Aug 2021 12:##:## -0400… Читать далее freecpewebinar.com (A, website) (Pioneer Educator)
Assorted phish landing sites.
Yodobashi Camera mostly. 34.85.93.145 yodubashiace.ga 34.85.93.145 angfumaiban.gq 34.85.93.145 yodubashiace.tk 34.85.93.145 yudubashinfmac.tk 34.85.93.145 yobudashiafo.ml 34.85.93.145 muzztuotacjp.ml 34.85.93.145 actmoyofcojp.cf 34.85.93.145 anuttotakco.cf 34.85.93.145 muzzteakacjp.tk 34.85.93.145 yudubashinfmac.ml 34.85.93.145 madoaccinfjp.gq 34.85.93.145 yodoubeshinccop.cf 34.85.93.145 yudubasinfacc.cf 34.85.93.145 yodoubeshinccop.gq 34.85.93.145 yobudashiafo.cf 34.85.93.145 yodoubeshinccop.ml 34.85.93.145 yodobosheinf.cf 34.85.93.145 yodubashiace.gq 34.85.93.145 yobudashiafo.tk 34.85.93.145 yudobasicoinf.ml 34.85.93.145 anuttotakco.tk 34.85.93.145 yudubasinfacc.ml 34.85.93.145 muzzteakacjp.ml 34.85.93.145 yudobasicoinf.tk 34.85.93.145 yodoubeshiaccop.tk 34.85.93.145 muzzteakacjp.cf… Читать далее Assorted phish landing sites.
Assorted phish landing sites.
35.243.106.247 actmoyofcojp.tk 35.243.106.247 dacomuttjpco.gq 35.243.106.247 yodoubeshiaccop.gq 35.243.106.247 akatenntinfco.cf 35.243.106.247 autidacclin.cf 35.243.106.247 muzztuotacjp.ga 35.243.106.247 mengtoshisan.ml 35.243.106.247 mengtoshisan.gq 35.243.106.247 mengtoshisan.ga 35.243.106.247 docameaccfo.tk 35.243.106.247 docameaccfo.gq 35.243.106.247 mengtoshisan.tk 35.243.106.247 angfumaiban.ml AND MANY MORE, 30+
Spamvertised website
Received: from mail-pg1-x533.google.com ([2607:f8b0:4864:20::533]) From: thaiduong628@gmail.com Date: Sun, 29 Aug 2021 00:01:16 +0200 Subject:Funny T-Shirts For Engineer And Jobs Title T-Shirts https://engineerstore3.blogspot.com/2021/08/h2.html https://scienceflower.com/campaign/heavy-metals-chemistry-science-t-shirts engineerstore3.blogspot.com. 3600 IN CNAME blogspot.l.googleusercontent.com. blogspot.l.googleusercontent.com. 300 IN A 142.251.32.1 scienceflower.com. 300 IN A 104.21.51.216 scienceflower.com. 300 IN A 172.67.186.95
NTT DoCoMo phishing.
334th live listing. 34.146.247.192 smt-docomo-co-jp.website 34.146.247.192 ntt-docomo-co-jp.space 34.146.247.192 ntt-docomo-co-jp.website 34.146.247.192 ntt-docomo-co-jp.casa 34.146.247.192 ntt-docomo-co-jp.uno 34.146.247.192 etc-mylfei-jp.radio.am And MANY MORE variations on a theme. cfg-smt-docomo-ne-jp.website Porkbun, LLC ntt-docomo-co-jp.uno Porkbun, LLC ntt-docomo-ne-jp.website Porkbun, LLC smt-docomo-co-jp.website Porkbun, LLC smt-docomo-ne-jp.website Porkbun, LLC
learnfromgrc.com (GRC Educators, aka Ijona Serivces)
Google hosts the A Record and website of the domain learnfromgrc.com. The domain belongs to GRC Educators, aka Ijona Services/Ijona Skills. GRC Educators spams scarped, purchased, and appended lists to advertise its business compliance training and education services. It usually spams through respectable ESPs, in this case through Salesforce, and has been doing so under… Читать далее learnfromgrc.com (GRC Educators, aka Ijona Serivces)
Assorted phish landing sites.
yodobashi camera 34.97.52.59 yodobashi-ides.onthewifi.com credit card: hxxps://eposcardadmij.servebeer.com hxxps://eposcardnike.servebeer.com hxxps://eposcardmike.servebeer.com hxxps://eposcardokubo.serveftp.com hxxps://eposcardrecrds.servebeer.com hxxps://eposcardnagano.myvnc.com hxxps://eposcardkana.servebeer.com hxxps://eposcardaker.servebeer.com hxxps://eposcardcaces.servebeer.com