Dridex + Emotet botnet controller hosted here: $ telnet 45.79.33.48 443 Trying 45.79.33.48… Connected to 45.79.33.48. Escape character is ‘^]’. $ telnet 45.79.33.48 8080 Trying 45.79.33.48… Connected to 45.79.33.48. Escape character is ‘^]’.
Phishing origination against Nordea Bank (Nordic countries)
Received: from cloud-623403.managed-vps.net (cloud-623403.managed-vps.net [188.166.94.138]) by x (Postfix) with ESMTPS id x for <x>; Thu, 18 Nov 2021 ##:##:## +0100 (CET) Received: from [185.212.81.49] (port=52990) by cloud-623403.managed-vps.net with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from <service@nordea.caixaapproval.com>) id x for x; Thu, 18 Nov 2021 ##:##:## +0200 From: «Nordea» <service@nordea.caixaapproval.com> or Received: from cloud-b023e2.managed-vps.net (cloud-b023e2.managed-vps.net [206.189.1.229])… Читать далее Phishing origination against Nordea Bank (Nordic countries)
Phishing origination against Nordea Bank (Nordic countries)
Received: from cloud-623403.managed-vps.net (cloud-623403.managed-vps.net [188.166.94.138]) by x (Postfix) with ESMTPS id x for <x>; Thu, 18 Nov 2021 ##:##:## +0100 (CET) Received: from [185.212.81.49] (port=52990) by cloud-623403.managed-vps.net with esmtpsa (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from <service@nordea.caixaapproval.com>) id x for x; Thu, 18 Nov 2021 ##:##:## +0200 From: «Nordea» <service@nordea.caixaapproval.com> or Received: from cloud-b023e2.managed-vps.net (cloud-b023e2.managed-vps.net [206.189.1.229])… Читать далее Phishing origination against Nordea Bank (Nordic countries)
BitRAT botnet controller @20.115.149.198
The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse. Malware botnet controller located at 20.115.149.198 on port 2222 TCP: $ telnet 20.115.149.198 2222 Trying 20.115.149.198… Connected to 20.115.149.198. Escape character… Читать далее BitRAT botnet controller @20.115.149.198
spam emitter @159.203.44.154
Received: from mail.busyelite.me (159.203.44.154) From: «Charlotte, BitcoinTrader» <contact@busyelite.me> Subject: [], du har penger på kontoen din Date: Wed, 17 Nov 2021 04:0x:xx -0800 https://withdrawalupdating.page.link/moke
Loki botnet controller @172.67.148.74
The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse. Loki botnet controller located at 172.67.148.74 on port 80 (using HTTP POST): hXXp://aboliki.xyz/five/fre.php $ dig +short aboliki.xyz 172.67.148.74 Other malicious domain names hosted on this IP address:… Читать далее Loki botnet controller @172.67.148.74
Malware botnet controller @162.255.117.78
The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse. Malware botnet controller located at 162.255.117.78 on port 80 (using HTTP POST): hXXp://requestimedout.com/xenocrates/zoroaster $ dig +short requestimedout.com 162.255.117.78 $ nslookup 162.255.117.78 nc-ph-0580-18.trackpressure.website Referencing malware binaries (MD5 hash):… Читать далее Malware botnet controller @162.255.117.78
spam support (domains)
domain used in spam operation wolfdigitals.co.uk… 143.198.65.77
spam emitters
Received: from s8.megojom.ru (megojom.ru [94.26.250.157]) Date: Wed, 17 Nov 2021 15:0x:xx +0000 From: Aleksandr <info@s8.megojom.ru> Subject: Предложение 94.26.250.114 kroshem.ru 94.26.250.115 opengmon.ru 94.26.250.116 jombengon.ru 94.26.250.117 alomengo.ru 94.26.250.118 veromeng.ru 94.26.250.154 eseneno.ru 94.26.250.155 derwerer.ru 94.26.250.156 yeremont.ru 94.26.250.157 megojom.ru 94.26.250.158 uwentos.ru
Botnet spammed phishing domains: Phishing Google & Facebook users
tag-manager.net. 600 IN A 45.8.124.251 _______________ Was: tag-manager.net. 600 IN A 193.42.114.54 _______________ Was: 185.207.137.113 artitam.com 2020-11-21 04:33:33 185.207.137.113 googlemanagerapi.com 2021-11-16 01:41:10 185.207.137.113 tag-manager.net 2021-11-16 01:30:47 185.207.137.113 traxtibidox.net 2021-11-14 03:50:23 _______________ Was: 213.183.59.219 googlemanagerapi.com 2021-11-14 02:20:54 213.183.59.219 tag-manager.net 2021-11-14 18:56:05 _______________ Was: 45.138.25.29 tag-manager.net 2021-09-27 16:08:32 _______________ Was: 5.188.88.4 fraudlabzpros.com 2021-09-23 23:11:14 5.188.88.4 googlemanagerapi.com 2021-09-24… Читать далее Botnet spammed phishing domains: Phishing Google & Facebook users