Spamvertised website

Received: from mail.alotsofmagic.co (mail.alotsofmagic.co [64.225.79.5]) Date: Sat, 24 Jul 2021 05:1x:xx +0000 Subject: kans te maken op een weekend in een Van der Valk hotel. From: «Van der Valk hotel.» <mail@alotsofmagic.co> URL: https://soul.jackychecky.co/index.php/campaigns/[] Server IP address is 172.67.213.195 Location: https://coffeecome.co/biz3600 Server IP address is 172.67.176.85 Location: https://www.suppertous.com/[] Server IP address is 185.95.85.241 Location: https://go.nltrck.com/?c=387&s1=3219&s2=[] Server… Читать далее Spamvertised website

Spamvertised website

Received: from mail.alotsofmagic.co (mail.alotsofmagic.co [64.225.79.5]) Date: Sat, 24 Jul 2021 05:1x:xx +0000 Subject: kans te maken op een weekend in een Van der Valk hotel. From: «Van der Valk hotel.» <mail@alotsofmagic.co> URL: https://soul.jackychecky.co/index.php/campaigns/[] Server IP address is 172.67.213.195 Location: https://coffeecome.co/biz3600 Server IP address is 172.67.176.85 Location: https://www.suppertous.com/[] Server IP address is 185.95.85.241 Location: https://go.nltrck.com/?c=387&s1=3219&s2=[] Server… Читать далее Spamvertised website

Hosting Google phishing and/or fraud domain: googlecdn.in (DNS)

Strange how Google IPs, DNS or registrar are not used by «Google CDN»… https://otx.alienvault.com/indicator/url/http://googlecdn.in/ 45.207.55.244 w71.googlecdn.in 2021-07-25 22:56:58 45.207.55.30 k48.googlecdn.in 2021-07-25 15:46:24 45.207.55.143 k76.googlecdn.in 2021-07-25 12:30:47 45.207.55.244 w47.googlecdn.in 2021-07-25 10:53:31 45.207.55.64 k51.googlecdn.in 2021-07-25 08:31:39 45.207.55.68 k58.googlecdn.in 2021-07-25 08:28:40 45.207.55.144 k80.googlecdn.in 2021-07-25 07:39:59 45.207.55.68 k57.googlecdn.in 2021-07-25 05:05:42 45.207.55.65 k52.googlecdn.in 2021-07-25 03:50:48 45.207.55.245 y53.googlecdn.in 2021-07-24 13:39:47 45.207.55.66… Читать далее Hosting Google phishing and/or fraud domain: googlecdn.in (DNS)

Fraud spam for: hellenicloans.webs.com (ignored by vistaprint.com)

hellenicloans.webs.com. 299 IN A 104.17.119.40 hellenicloans.webs.com. 299 IN A 104.16.140.31 Received: from mail-lf1-f53.google.com (HELO mail-lf1-f53.google.com) (209.85.167.53) by xxS; Wed, 21 Jul 2021 08:07:43 +0000 Received: by mail-lf1-f53.google.com with SMTP id xx; Wed, 21 Jul 2021 01:07:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:reply-to:from:date:message-id:subject:to; bh=UKXOJqFntzTA+42U+ncp+9EwXkwepbOuPhrdB1ZCBTQ=; b=Y+KOh6zESPIw7Br3pM5J6oduB0NmClYRilRiR25kLlALvUgW3tkRE2Jp5OF8dadlZ3 aX2jYzpW5dMoHpf//Dw8rFTurUvbdqub1t1MTbueA+Kc0s5l+oRwGdD6bmwgftm5rREZ hPM78QbfUCtzBFJbuMMuspuHPvUS4WN5el3MbkWjBAxWlclcxRWPhERK0ixMy39GGGey KbGfzKHXxhRqnmob8ODOvKYNrAWQ7HAPZBCwZ54ARbV1mL9+5FLA3Arog4vhnXPPbU3d +fuqGts395WAIf4BfU747OK2RWwgVYJMiIk0TL2sptmDzPdKQBURYZCcJKvMkpYu15JM DKWQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256;… Читать далее Fraud spam for: hellenicloans.webs.com (ignored by vistaprint.com)

Carding fraud site/forum: hgn01.ru / hgn01.com / hgnstore.to

https://altenen.is/ >>> https://hgn01.ru/ hgn01.ru. 299 IN A 104.21.86.56 hgn01.ru. 299 IN A 172.67.215.89 hgn01.com. 299 IN A 104.21.2.237 hgn01.com. 299 IN A 172.67.129.207 hgnstore.to. 299 IN A 104.21.51.79 hgnstore.to. 299 IN A 172.67.177.99 _________________ Was: 111.90.141.126 hgn01.com 2021-07-13 13:51:21 111.90.141.126 hgn01.ru 2021-07-13 16:51:33 _________________ Was: hgn01.ru. 2701 IN A 186.2.171.3 186.2.171.3 hgn01.com 2021-07-03 03:00:41 186.2.171.3… Читать далее Carding fraud site/forum: hgn01.ru / hgn01.com / hgnstore.to

Carding fraud site/forum: hgn01.ru / hgn01.com / hgnstore.to

https://altenen.is/ >>> https://hgn01.ru/ hgn01.ru. 299 IN A 104.21.86.56 hgn01.ru. 299 IN A 172.67.215.89 hgn01.com. 299 IN A 104.21.2.237 hgn01.com. 299 IN A 172.67.129.207 hgnstore.to. 299 IN A 104.21.51.79 hgnstore.to. 299 IN A 172.67.177.99 _________________ Was: 111.90.141.126 hgn01.com 2021-07-13 13:51:21 111.90.141.126 hgn01.ru 2021-07-13 16:51:33 _________________ Was: hgn01.ru. 2701 IN A 186.2.171.3 186.2.171.3 hgn01.com 2021-07-03 03:00:41 186.2.171.3… Читать далее Carding fraud site/forum: hgn01.ru / hgn01.com / hgnstore.to

Carding fraud site/forum: hgn01.ru / hgn01.com / hgnstore.to

https://altenen.is/ >>> https://hgn01.ru/ hgn01.ru. 299 IN A 104.21.86.56 hgn01.ru. 299 IN A 172.67.215.89 hgn01.com. 299 IN A 104.21.2.237 hgn01.com. 299 IN A 172.67.129.207 hgnstore.to. 299 IN A 104.21.51.79 hgnstore.to. 299 IN A 172.67.177.99 _________________ Was: 111.90.141.126 hgn01.com 2021-07-13 13:51:21 111.90.141.126 hgn01.ru 2021-07-13 16:51:33 _________________ Was: hgn01.ru. 2701 IN A 186.2.171.3 186.2.171.3 hgn01.com 2021-07-03 03:00:41 186.2.171.3… Читать далее Carding fraud site/forum: hgn01.ru / hgn01.com / hgnstore.to

Spam & cybercrime hosting — reports ignored (escalation)

SBL526426 172.67.163.136 cloudflare.com 2021-07-03 Carding fraud site/forum: carders.team SBL525412 172.67.163.192 cloudflare.com 2021-07-02 darkmarket.cm etc cybercrime forums => kley.maxivanov3421.workers.dev SBL525163 172.67.163.89 cloudflare.com 2021-06-16 Carding fraud site/forum: uniccshop.ms (cclub.su / uniccbazar.vip / dumpscrew.com / unicc.am / cardpin.org / dumpshop.net)

Russian carding fraud site/forum: fullzinfo.pw

fullzinfo.pw. 299 IN A 104.21.76.154 fullzinfo.pw. 299 IN A 172.67.197.42 ____________________ Was: fullzinfo.pw. 299 IN A 198.251.89.63 198.251.89.63 fullzinfo.pw 2021-03-18 198.251.89.63 bnkiranmelat.vip 2021-03-12 198.251.89.63 irabnkmelat.vip 2021-03-04 198.251.89.63 mellater.vip 2021-02-17 198.251.89.63 banmellater.vip 2021-02-09 198.251.89.63 irbankmelat.vip 2021-02-08 198.251.89.63 irmellatbank.vip 2021-02-04 198.251.89.63 bankmelatir.vip 2021-02-02 198.251.89.63 iranmellat.vip 2021-01-20 ____________________ Was: fullzinfo.pw. 299 IN A 188.165.232.109 https://fullzinfo.pw/login.php https://fullzinfo.pw/register.php https://fullzinfo.pw/captcha/captcha.php https://fullzinfo.pw/king.jpg… Читать далее Russian carding fraud site/forum: fullzinfo.pw

Spam and cybercrime hosting (reports ignored — escalation)

SBL528542 172.67.69.116 cloudflare.com 2021-07-27 Cybercrime site/forum: ssn24.hi.cn SBL518210 172.67.69.100 cloudflare.com 2021-03-06 Carding fraud site/forum: UNICC.VC (uniccshop.cm / cardpin.org / crdshop.su / cclub.su / unicc.am / csu.su / abusehost.pro / dumpscrew.com / chindadump.su / dumpshop.net / dumpshop.cc) SBL490965 172.67.69.125 cloudflare.com 2021-05-18 Spammer hosting @172.67.69.125