Malware botnet controller @67.207.84.82

Malware botnet controller hosted here: $ dig +short folded.in 178.62.204.81 151.236.220.210 194.195.117.167 67.207.84.82 $ telnet 67.207.84.82 1025 Trying 67.207.84.82… Connected to 67.207.84.82. Escape character is ‘^]’.

phishing server

164.92.78.233|fidelityalerts.com|2022-03-12 23:30:53 164.92.78.233|fidelityuser.com|2022-03-17 00:51:41

spam emitter @137.184.177.85

Received: from mail.jalabia.live ([137.184.177.85]) From: «Jennings, Klanten Manager» <contact@jalabia.live> Subject: ✅ U bent succesvol ingediend Date: Wed, 16 Mar 2022 08:2x:xx +0000 https://investplann.page.link/GMQ7 https://tomorrowisthedayaftertoday.biz/[] 18.195.174.160 https://chargetraqing.com/investment_plan/nl?[] 185.70.187.117 https://bronzespoon.com/api/v3/offer/80?aff_sub2=[]&aff_sub3=CH&affiliate_id=2&url_id=81 185.161.209.194 https://lobsterolifa.com/api/v1/leads-workflow/geo/1/1?tp_hash=[]&tp_offer_id=80&tp_affiliate_id=2&device_brand=Apple&device_model=&device_os=Mac&userIp=[]&country_code=NL&tp_advertiser_id=1&tp_source=&tp_aff_sub=&tp_aff_sub2=[]&tp_aff_sub3=CH&tp_aff_sub4=&tp_aff_sub5= 185.161.209.182 https://protos-offers.com/bitcoin-era/index-nl.html?d=[] 104.21.2.84 https://login.magazinenews9000.com/signin.php?lid=2695248&token=[] 172.67.158.194 https://client.europatradecapital.com/en-US/Dashboard/Provider 188.114.96.0

phishing server

167.172.22.195|citieseconlinebn9.com|2022-03-13 02:01:20 167.172.22.195|citisupportsec8.com|2022-03-13 02:51:41

Spam Hosting (peertechz.com) (PeertechZ) (OMICS)

This IP address hosts the A record and website of the domain peertechz.com. This domain belongs to PeertechZ, alias OMICS. OMICs has over 200 current and previous SBL listings. This is an aggressive spam operation that uses many business names. Received: from kintex.ptechzmail.com (kintex.ptechzmail.com [64.44.41.4]) Received: from sys-PC (unknown [110.235.225.3]) Date: 11 Mar 2022 09:##:##… Читать далее Spam Hosting (peertechz.com) (PeertechZ) (OMICS)

Spam MX Services (peertechz.us) (PeertechZ) (OMICS)

This IP address hosts the A and MX records for the domain peertechz.us. this domain belongs to PeerTechZ, aka OMICS. OMICS is a publisher of «open-access» journals that solicits contributions and (by implication) fees and/or subscriptions, through spam sent to scraped, purchased or appended lists. OMICS has more than 200 current and previous SBL listings.… Читать далее Spam MX Services (peertechz.us) (PeertechZ) (OMICS)

phishing server

165.227.232.123|checkinformations.online|2022-03-09 12:47:13 165.227.232.123|memberdirectupdates.online|2022-03-09 13:09:59 165.227.232.123|protectionusercontrolupdates.online|2022-03-09 13:09:27 165.227.232.123|usercustomerverifinformation.online|2022-03-09 13:31:07 165.227.232.123|viewconfrimationcustomerupdate.online|2022-03-10 02:51:33 165.227.232.123|viewupdatecustomeraccount.online|2022-03-10 02:26:29

Spamvertised website

2022-03-10 astraloched.site. 60 IN A 147.182.187.73 Received: from varilokaminadere.org.uk (varilokaminadere.org.uk. [158.51.98.177]) Date: Wed, 02 Mar 2022 07:1x:xx +0000 From: «Surge MasterCard» <contact@varilokaminadere.org.uk> Subject: The perfect credit card for all credit types. http://astraloched.site/track/[] 159.89.228.34 https://rockpriority.com/0/0/0/[] 195.133.83.235 https://warmenbrace.com/?s1=350676&s2=[]&s3=2357&s4=0&ow=&s10=739 188.114.96.0 https://stagningtrump.com/[] 104.21.2.162 https://beatxup.com/click?s2=[]&s1=350676&s3=2357&trvid=10561&s4=0&ow=36 111.90.158.39 https://coupvariant.com/?a=162&c=4035&s2=[]&s1=350676 104.21.37.240 https://ama.yourstrulynow.com/nl-nl/?o=4076&r=[]&a=162&sa=350676 188.114.96.0 https://payment.terr3fick.com/0ab9e/gateway.html?sid=[] 188.114.96.0