phishing server

verifyacademy.com has address 64.225.50.108 Getting started — Online Enrollment — chase.com

phishing server

137.184.84.40|online03a-citi-secure-login-site.com|2021-12-04 19:05:51 137.184.84.40|online03c-citi-secure-login-site.com|2021-12-04 19:35:53 137.184.84.40|online04a-citi-secure-login-site.com|2021-12-04 19:58:32 137.184.84.40|online04c-citi-secure-login-site.com|2021-12-04 20:11:11

phishing server

online-citi-secure-panel-secure-site.com 2021-11-30 19:36:31 online-citi-secure-panel-secure-recovery.com 2021-11-30 19:55:13

spam emitter @143.198.53.108

Received: from mail.omsking.me (143.198.53.108) From: «BTC Kontosaldo» <contact@omsking.me> Subject: [], saldoen din er klar for utbetaling i dag Date: Tue, 30 Nov 2021 07:4x:xx -0800

Attack Server

Exploit scanner 1638207204.833 0 206.189.131.7 TCP_DENIED/403 4019 GET http://X.X.X.X/pma2019/index.php? — HIER_NONE/- text/html 1638207205.398 0 206.189.131.7 TCP_DENIED/403 4007 GET http://X.X.X.X/pma/index.php? — HIER_NONE/- text/html 1638207205.974 0 206.189.131.7 TCP_DENIED/403 4042 GET http://X.X.X.X/admin/sqladmin/index.php? — HIER_NONE/- text/html 1638207206.616 0 206.189.131.7 TCP_DENIED/403 4019 GET http://X.X.X.X/PMA2021/index.php? — HIER_NONE/- text/html 1638207207.207 0 206.189.131.7 TCP_DENIED/403 4019 GET http://X.X.X.X/PMA2016/index.php? — HIER_NONE/- text/html 1638207207.699 0 206.189.131.7… Читать далее Attack Server

phishing server

128.199.10.234|secure05-update-citi.com|2021-11-24 15:56:26 128.199.10.234|secure07-citiupdate.com|2021-11-23 20:31:14 128.199.10.234|secure07bciti.com|2021-11-27 17:55:40 128.199.10.234|secure08-citisecurity.com|2021-11-27 00:15:56 128.199.10.234|server-citizns01b.com|2021-11-26 17:01:12 128.199.10.234|server01bciti.com|2021-11-26 19:06:44 128.199.10.234|server02b-citi.com|2021-11-26 21:10:52 128.199.10.234|server03b-citi03b.com|2021-11-26 23:06:27 128.199.10.234|updatecitizns01b.com|2021-11-26 17:36:55

spam support (domains)

domain used in spam opration Subject: 5OusdHomeDePot.ReVVarD.PticiationRequirD truefint.com [165.227.27.17]

Spamvertised bitcoin scam.

Was SBL537336 91.202.5.69 Was SBL537239 31.42.177.99 bitforte.net has address 164.90.195.160 www.bitforte.net has address 164.90.195.160 www.fortcoin.net has address 164.90.195.160 fortcoin.net has address 164.90.195.160 sbk.foundation has address 31.42.177.99 <— abandoned? 91.202.5.69 bitforte.net 91.202.5.69 www.bitforte.net 91.202.5.69 www.coinrow.net 91.202.5.69 coinrow.net 91.202.5.69 www.fortcoin.net 91.202.5.69 fortcoin.net 91.202.5.69 www.coinforte.net 91.202.5.69 coinforte.net 31.42.177.99 bitforte.net 31.42.177.99 www.bitforte.net 31.42.177.99 www.fortcoin.net 31.42.177.99 fortcoin.net 31.42.177.99 sbk.foundation 31.42.177.99… Читать далее Spamvertised bitcoin scam.