Phish spam site @172.67.198.54

Received: from [116.85.69.180] (helo=visa.co.jp) From: «VISA JAPAN» <vpass@visa.co.jp> Subject: 【重要なお知らせ】VISAカードの利用確認 Date: Sat, 10 Jul 2021 11:24:35 +0800 https://www.veias.cc/ www.veias.cc. 300 IN A 172.67.198.54 www.veias.cc. 300 IN A 104.21.44.86

Spammer DNS server @173.245.58.126

The host at this IP address is being used by spammers to provide DNS resolution to spammer domains. —————————— Spammer redirection chain: https://israeltaxrefund.co.il/apotheke.html [redirection] -> https://bit.ly/3gTE9cd [redirection] —> https://www.online-rezeptfrei.de/ [Final spammer site] $ dig +short www.online-rezeptfrei.de 104.21.49.169 172.67.191.50 $ dig +short online-rezeptfrei.de NS kim.ns.cloudflare.com. earl.ns.cloudflare.com. $ dig +short earl.ns.cloudflare.com. 108.162.193.161 173.245.59.161 172.64.33.161 $ dig +short… Читать далее Spammer DNS server @173.245.58.126

Carding fraud site/forum: pluscc.store / plusccws.ru

https://pluscc.store/ pluscc.store. 300 IN A 104.21.90.226 pluscc.store. 300 IN A 172.67.162.50 cpanel.pluscc.store. 300 IN A 172.67.162.50 cpanel.pluscc.store. 300 IN A 104.21.90.226 _________________ Was: pluscc.store. 187 IN A 172.67.158.208 pluscc.store. 187 IN A 104.21.49.44 plusccws.ru. 299 IN A 104.21.95.140 plusccws.ru. 299 IN A 172.67.170.115 dc-31e175bf7e9e.pluscc.store. 299 IN A 111.90.156.151 111.90.156.151 _dc-mx.51ae5bba6e53.plusccws.ru pluscc.store. 21599 IN NS angela.ns.cloudflare.com.… Читать далее Carding fraud site/forum: pluscc.store / plusccws.ru

Spamvertised website

https://feedproxy.google.com/~r/x7i/~3/gwKXCfxH6W0 => https://pillsselect.com/?6Ccv85AAuDF8 pillsselect.com. 300 IN A 104.21.57.27 pillsselect.com. 300 IN A 172.67.158.190 pillsselect.com. 172800 IN NS emerson.ns.cloudflare.com. pillsselect.com. 172800 IN NS dawn.ns.cloudflare.com. dawn.ns.cloudflare.com. 29678 IN A 173.245.58.106 dawn.ns.cloudflare.com. 29678 IN A 108.162.192.106 dawn.ns.cloudflare.com. 29678 IN A 172.64.32.106 emerson.ns.cloudflare.com. 29678 IN A 162.159.44.96 emerson.ns.cloudflare.com. 29678 IN A 172.64.35.96 emerson.ns.cloudflare.com. 29678 IN A 108.162.195.96

Carding fraud site/forum: ascarding.com

Stolen credit card data websites: https://ascarding.com/threads/ ascarding.com. 300 IN A 104.21.12.146 ascarding.com. 300 IN A 172.67.152.139 ascarding.com. 172799 IN NS zariyah.ns.cloudflare.com. ascarding.com. 172799 IN NS toby.ns.cloudflare.com. toby.ns.cloudflare.com. 172799 IN A 108.162.193.239 toby.ns.cloudflare.com. 172799 IN A 172.64.33.239 toby.ns.cloudflare.com. 172799 IN A 173.245.59.239 zariyah.ns.cloudflare.com. 172799 IN A 172.64.34.72 zariyah.ns.cloudflare.com. 172799 IN A 108.162.194.72 zariyah.ns.cloudflare.com. 172799 IN A… Читать далее Carding fraud site/forum: ascarding.com

Carding fraud site/forum: legitcarders.ru

Stolen credit card data websites. legitcarders.ru. 300 IN A 172.67.155.37 legitcarders.ru. 300 IN A 104.21.6.142 _______________ Was: 185.178.208.135 legitcarders.ru 2021-06-28 12:21:53 185.178.208.135 backup.legitcarders.ru 2021-05-01 06:37:22 185.178.208.135 secure.legitcarders.ru 2021-06-06 01:54:12 185.178.208.135 sitemap.legitcarders.ru 2021-06-21 19:12:02 185.178.208.135 wordpress.legitcarders.ru 2021-06-06 02:54:25 185.178.208.135 wp.legitcarders.ru 2021-04-29 06:50:23 185.178.208.135 www.m.legitcarders.ru 2021-06-07 09:20:22 185.178.208.135 www.ssl.legitcarders.ru 2021-06-27 10:53:52 ________________ Legit Carders,carders forum,carding forumhttps://legitcarders.ru Need… Читать далее Carding fraud site/forum: legitcarders.ru

Phishing payload against PayPal

$ host www.coconews.com www.coconews.com has address 172.67.132.41 www.coconews.com has address 104.21.12.150 www.coconews.com has IPv6 address 2606:4700:3032::6815:c96 www.coconews.com has IPv6 address 2606:4700:3031::ac43:8429

Russian carding fraud site/forum hosting: unicc.cx / unicvv.vip / unicc.am / unicvv.ru / unicc-tor.site / unicc.com.ng (uniccshop.ru / carder.su / cvvshop.lv / pinkshop.name / carderpro.com / cardmafia.mn / ccbase.biz / cpro.su)

Stolen credit card data websites: http://unicc-tor.site >>> https://unicc.cx >>> https://unicvv.top/ unicc-tor.site. 599 IN A 212.26.132.246 unicc.cx. 599 IN A 85.192.56.29 unicvv.top. 299 IN A 104.21.81.95 unicvv.top. 299 IN A 172.67.189.14 ___________________ Was: ;; QUESTION SECTION: ;unicc.am. IN NS ;; ANSWER SECTION: unicc.am. 21599 IN NS ns1.he.net. unicc.am. 21599 IN NS ns3.he.net. unicc.am. 21599 IN NS… Читать далее Russian carding fraud site/forum hosting: unicc.cx / unicvv.vip / unicc.am / unicvv.ru / unicc-tor.site / unicc.com.ng (uniccshop.ru / carder.su / cvvshop.lv / pinkshop.name / carderpro.com / cardmafia.mn / ccbase.biz / cpro.su)

Phishing payload against PayPal

$ host www.coconews.com www.coconews.com has address 172.67.132.41 www.coconews.com has address 104.21.12.150 www.coconews.com has IPv6 address 2606:4700:3032::6815:c96 www.coconews.com has IPv6 address 2606:4700:3031::ac43:8429

Hosting spam & cybercrime sites (escalation — reports ignnored for months)

SBL527760 172.67.155.37 cloudflare.com 2021-07-20 Carding fraud site/forum: legitcarders.ru SBL499997 172.67.155.223 cloudflare.com 2020-10-30 Hosting porn spam site: urseductivegirls.com SBL498446 172.67.153.164 cloudflare.com 2021-03-10 Carding fraud site/forum: carder.one SBL495887 172.67.155.42 cloudflare.com 2020-09-24 Gift card fraud spam — fireplacecoffee.com SBL521377 172.67.153.95 cloudflare.com 2021-04-22 Carding fraud site/forum: fernandogoods.at SBL520327 172.67.154.42 cloudflare.com 2021-05-26 Carding fraud site/forum: cv2.su (cvvmecc.com / briansclub.club /… Читать далее Hosting spam & cybercrime sites (escalation — reports ignnored for months)