hXXp://130.61.253.157/Update.bat
phishing server
$ host citibank-secure-profiles.com citibank-secure-profiles.com has address 129.213.113.88 $ host citibank-secure-profile.com citibank-secure-profile.com has address 129.213.113.88
phishing server
confirmmycard.com has address 132.226.31.109 confirmlogonline.com has address 132.226.31.109 confirmidentitylive.com has address 132.226.31.109
phishing server
systemlogalert.com has address 129.146.198.110 systemlivealert.com has address 129.146.198.110 hXXps://systemlogalert.com/citizensbank/
phishing server
mysystemonlinealert.com has address 132.226.127.173 © Copyright 2020 Citizens Financial Group, Inc. All rights reserved. Citizens Bank is a brand name of Citizens Bank, N.A. (NMLS ID# 433960). mylogliveform.com has address 132.226.127.173 mylogform.com has address 132.226.127.173 mysystemlivealert.com has address 132.226.127.173
spam emitter @152.70.181.66
Received: from bravo-pass.com (152.70.181.66) Date: Mon, 13 Sep 2021 18:5x:xx +0100 From: Walmart <freetrial@NJQ.affpartners.com> Subject: 𝐖𝐚𝐥𝐦𝐚𝐫𝐭 𝐇𝐚𝐬 𝐀 𝐁𝐢𝐠 𝐒𝐮𝐫𝐩𝐫𝐢𝐬𝐞 𝐅𝐨𝐫 𝐘𝐨
Spamvertised website
Received: from voluptatesogajh.static.206.123.90.157.clients.your-server.de (51.104.245.202) Date: Tue, 14 Sep 2021 20:1x:xx +0000 From: 💕MeetRussianLady💕 <news@your-server.de> Subject: 🔥[]🔥,Russiske piger søger ægte kærlighed http://blotto.biz/track/[] 146.56.169.102 https://www.incorport.com/J55PK4D/QZX6914/?sub1=7&sub2=[] 173.255.248.174 https://www.russianwomanlove.com/index.php/promote/click?aid=1484&oid=CP230172&qpid_offer_id=[]&qpid_subid=9343&source_tag=7&qpid_clickid=[] 52.40.246.237 https://www.charmdate.com/my/register_do.php 52.197.172.138
Malware botnet controller @152.67.253.163
The host at this IP address is obviously operated by cybercriminals. It is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse. Malware botnet controller located at 152.67.253.163 on port 5300 TCP: $ telnet 152.67.253.163 5300 Trying 152.67.253.163… Connected to 152.67.253.163. Escape character… Читать далее Malware botnet controller @152.67.253.163
Malware botnet controller @140.238.181.20
The host at this IP address is running a malware botnet controller which is being used to control infected computers (bots) around the globe using a trojan horse. Malware botnet controller located at 140.238.181.20 on port 80 (using HTTP GET): hXXp://140.238.181.20/2021/
phishing server
site07b1-signonrequest.com has address 168.138.90.73 uslink1b.online has address 168.138.90.73 websecur1.online has address 168.138.90.73 onlinemail1s.com has address 168.138.90.73