The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse. Malware botnet controller located at 49.12.34.17 on port 33715 TCP: $ telnet 49.12.34.17 33715 Trying 49.12.34.17… Connected to 49.12.34.17. Escape character… Читать далее RedLineStealer botnet controller @49.12.34.17
Spam Emitter (najmed.info) (OMICS)
This IP address hosts the A and MX records for teh domain najmed.info, which appears as a dropbox email address in message bodies of spam. These email addresses are often the only contact points with the spammer. The owner of this domain is OMICS, aka Remedy Publications, Austin Publishers. OMICS publishes a range of open… Читать далее Spam Emitter (najmed.info) (OMICS)
phishing server
20.119.232.171|key-support.org|2021-12-23 20:01:16 20.119.232.171|netlfix.us|2021-12-24 06:11:31 20.119.232.171|tracking-usps.us|2021-12-24 23:55:53
Malware distribution @194.87.185.80
The host at this IP address is currently being used to distribute malware. Malware distribution located here: hXXp://petknorra.com/index.php petknorra.com. 600 IN A 194.87.185.80
phishing server
34.106.120.76|secure01z-chase.com|2021-12-24 20:36:00 34.106.120.76|secure02z-chase.com|2021-12-24 19:51:11 34.106.120.76|secure03z-chase.com|2021-12-24 20:36:23 34.106.120.76|secure04z-chase.com|2021-12-24 21:31:07 34.106.120.76|secure05z-chase.com|2021-12-24 20:26:02 34.106.120.76|secure06z-chase.com|2021-12-24 19:50:58 34.106.120.76|wells-secure01w.com|2021-12-24 21:56:06 34.106.120.76|wells-secure03w.com|2021-12-24 21:56:00 34.106.120.76|wells-secure04w.com|2021-12-24 22:06:39
Spam Emitter (clinofsurgyoa.com) (OMICS)
This IP address is sending spam for OMICS (aka Remedy Publishing, aka Austin Publishing, and others) advertising its «open-access» journals. The spam is sent to scraped, purchased, or appended lists. OMICS claims that these journals are peer-reviewed, but they are of dubious reputation. DigitalOcean: OMICS appears to be running riot in your VPS ranges. Please… Читать далее Spam Emitter (clinofsurgyoa.com) (OMICS)
Snowshoe spam ranges
52.18.169.171 m30.esputnik.com «m30.esputnik.com» 2021-12-24T06:40:00Z (+/-10 min) 52.18.169.171/32 (52.18.169.171 .. 52.18.169.171) 52.19.99.54 m79.esputnik.com «m79.esputnik.com» 2021-12-24T06:40:00Z (+/-10 min) 52.19.99.54/32 (52.19.99.54 .. 52.19.99.54) 52.49.237.51 m32.esputnik.com «m32.esputnik.com» 2021-12-24T06:50:00Z (+/-10 min) 52.49.237.51/32 (52.49.237.51 .. 52.49.237.51) 52.50.69.120 m45.esputnik.com «m45.esputnik.com» 2021-12-24T06:40:00Z (+/-10 min) 52.50.69.120/32 (52.50.69.120 .. 52.50.69.120) 52.50.205.175 m43.esputnik.com «m43.esputnik.com» 2021-12-24T06:50:00Z (+/-10 min) 52.50.205.175/32 (52.50.205.175 .. 52.50.205.175) 52.50.233.247 m42.esputnik.com «m42.esputnik.com» 2021-12-24T06:40:00Z (+/-10… Читать далее Snowshoe spam ranges
Snowshoe spam ranges
52.18.169.171 m30.esputnik.com «m30.esputnik.com» 2021-12-24T06:40:00Z (+/-10 min) 52.18.169.171/32 (52.18.169.171 .. 52.18.169.171) 52.19.99.54 m79.esputnik.com «m79.esputnik.com» 2021-12-24T06:40:00Z (+/-10 min) 52.19.99.54/32 (52.19.99.54 .. 52.19.99.54) 52.49.237.51 m32.esputnik.com «m32.esputnik.com» 2021-12-24T06:50:00Z (+/-10 min) 52.49.237.51/32 (52.49.237.51 .. 52.49.237.51) 52.50.69.120 m45.esputnik.com «m45.esputnik.com» 2021-12-24T06:40:00Z (+/-10 min) 52.50.69.120/32 (52.50.69.120 .. 52.50.69.120) 52.50.205.175 m43.esputnik.com «m43.esputnik.com» 2021-12-24T06:50:00Z (+/-10 min) 52.50.205.175/32 (52.50.205.175 .. 52.50.205.175) 52.50.233.247 m42.esputnik.com «m42.esputnik.com» 2021-12-24T06:40:00Z (+/-10… Читать далее Snowshoe spam ranges
Snowshoe spam ranges
52.18.169.171 m30.esputnik.com «m30.esputnik.com» 2021-12-24T06:40:00Z (+/-10 min) 52.18.169.171/32 (52.18.169.171 .. 52.18.169.171) 52.19.99.54 m79.esputnik.com «m79.esputnik.com» 2021-12-24T06:40:00Z (+/-10 min) 52.19.99.54/32 (52.19.99.54 .. 52.19.99.54) 52.49.237.51 m32.esputnik.com «m32.esputnik.com» 2021-12-24T06:50:00Z (+/-10 min) 52.49.237.51/32 (52.49.237.51 .. 52.49.237.51) 52.50.69.120 m45.esputnik.com «m45.esputnik.com» 2021-12-24T06:40:00Z (+/-10 min) 52.50.69.120/32 (52.50.69.120 .. 52.50.69.120) 52.50.205.175 m43.esputnik.com «m43.esputnik.com» 2021-12-24T06:50:00Z (+/-10 min) 52.50.205.175/32 (52.50.205.175 .. 52.50.205.175) 52.50.233.247 m42.esputnik.com «m42.esputnik.com» 2021-12-24T06:40:00Z (+/-10… Читать далее Snowshoe spam ranges
Snowshoe spam ranges
52.18.169.171 m30.esputnik.com «m30.esputnik.com» 2021-12-24T06:40:00Z (+/-10 min) 52.18.169.171/32 (52.18.169.171 .. 52.18.169.171) 52.19.99.54 m79.esputnik.com «m79.esputnik.com» 2021-12-24T06:40:00Z (+/-10 min) 52.19.99.54/32 (52.19.99.54 .. 52.19.99.54) 52.49.237.51 m32.esputnik.com «m32.esputnik.com» 2021-12-24T06:50:00Z (+/-10 min) 52.49.237.51/32 (52.49.237.51 .. 52.49.237.51) 52.50.69.120 m45.esputnik.com «m45.esputnik.com» 2021-12-24T06:40:00Z (+/-10 min) 52.50.69.120/32 (52.50.69.120 .. 52.50.69.120) 52.50.205.175 m43.esputnik.com «m43.esputnik.com» 2021-12-24T06:50:00Z (+/-10 min) 52.50.205.175/32 (52.50.205.175 .. 52.50.205.175) 52.50.233.247 m42.esputnik.com «m42.esputnik.com» 2021-12-24T06:40:00Z (+/-10… Читать далее Snowshoe spam ranges