Spammer hosting @172.67.185.108

Spammer hosting located here: http://www.google.com/url?q=http%3A%2F%2Fgo.tipirock4.com%2F0e42&sa=D&Hg=X -> http://go.tipirock4.com/0e42 —> http://de.bitcoin-now.tipirock4.com/?session=X $ dig +short de.bitcoin-now.tipirock4.com 172.67.185.108 104.21.59.234 Spam sample =========================================== Received: from sv1344.xserver.jp (sv1344.xserver.jp [183.90.250.45]) by X (Postfix) with ESMTPS id X for <X>; Sat, 19 Jun 2021 11:26:11 +0000 (UTC) Received: from virusgw10.xserver.jp (virusgw10.xserver.jp [183.90.250.243]) by sv1344.xserver.jp (Postfix) with ESMTP id X for <X>; Sat, 19… Читать далее Spammer hosting @172.67.185.108

Spammer hosting @172.67.218.115

Spammer hosting located here: $ dig +short www.defenderz.co 172.67.218.115 104.21.70.25 Spam sample ============================================== Received: from s3nwryuna.defenderz.co (unknown [157.52.231.142]) by X (Postfix) with ESMTP id X for <X>; Sat, 19 Jun 2021 11:47:36 +0000 (UTC) Received: from 052d02ed.s3nwryuna.defenderz.co ([127.0.0.1]:11450 helo=s3nwryuna.defenderz.co) by s3nwryuna.defenderz.co with ESMTP id X; for <X>; Sat, 19 Jun 2021 X Date: Sat, 19… Читать далее Spammer hosting @172.67.218.115

darkmarket.cm etc cybercrime forums => kley.maxivanov3421.workers.dev

Stolen credit card and other cybercrime forum: https://darkmarket.cm/ >>> https://kley.maxivanov3421.workers.dev/ kley.maxivanov3421.workers.dev. 299 IN A 104.21.10.167 kley.maxivanov3421.workers.dev. 299 IN A 172.67.163.192 https://darkmarket.vc/ >>> https://darkmarket.sh/ darkmarket.vc. 299 IN A 185.238.169.206 darkmarket.cm. 299 IN A 172.67.188.208 darkmarket.cm. 299 IN A 104.21.8.233 darkmarket.at. 299 IN A 172.67.182.193 darkmarket.at. 299 IN A 104.21.18.167 darkmarket.vc. 299 IN A 104.21.5.43 darkmarket.vc. 299… Читать далее darkmarket.cm etc cybercrime forums => kley.maxivanov3421.workers.dev

Carding fraud site/forum: darkmoney.be / darkmoney.de / darkmoney.pl (DNS)

Sites mostly dedicated to cashing out stolen credit-cards. Providing DNS: darkmoney.pl. 21599 IN NS hugh.ns.cloudflare.com. darkmoney.pl. 21599 IN NS yolanda.ns.cloudflare.com. darkmoney.de. 21599 IN NS hugh.ns.cloudflare.com. darkmoney.de. 21599 IN NS yolanda.ns.cloudflare.com. darkmoney.de. 299 IN A 181.174.164.105 181.174.164.105 darkmoney.de 2021-06-16 17:21:26 181.174.164.105 darkmoney.pl 2021-06-15 15:27:23 darkmoney.pl. 299 IN A 213.227.131.212 ___________________ Was: darkmoney.be. 3599 IN A 99.83.175.80… Читать далее Carding fraud site/forum: darkmoney.be / darkmoney.de / darkmoney.pl (DNS)

Spamvertised domain/redirector hosting

Return-Path: []@mail.groupage.today> Received: from mars.groupage.today (host-193.17.7.68.meric.net.tr [193.17.7.68] (may be forged)) by [] (8.14.7/8.14.7) with ESMTP id [] for []; Sun, 20 Jun 2021 15:[]:[] -0400 Authentication-Results: [] DKIM-Signature: [] DomainKey-Signature: [] Mime-Version: 1.0 Content-Type: multipart/alternative; boundary=»[]» Date: Sun, 20 Jun 2021 21:[]:[] +0200 From: «Fruit For Eyes» <visioncare@groupage.today> Reply-To: «Fruit For Eyes» <visioncare@groupage.today> Subject: Bible… Читать далее Spamvertised domain/redirector hosting

Spamvertised domain/redirector hosting

Return-Path: []@mail.victuran.today> Received: from anthe.victuran.today (host-193.17.7.80.meric.net.tr [193.17.7.80] (may be forged)) by [] (8.14.7/8.14.7) with ESMTP id [] for []; Sun, 20 Jun 2021 13:[]:[] -0400 Authentication-Results: [] DKIM-Signature: [] DomainKey-Signature: [] Mime-Version: 1.0 Content-Type: multipart/alternative; boundary=»[]» Date: Sun, 20 Jun 2021 19:[]:[] +0200 From: «Slow Metabolism» <dietarysupplement@victuran.today> Reply-To: «Slow Metabolism» <dietarysupplement@victuran.today> Subject: Doctor Reveals REAL… Читать далее Spamvertised domain/redirector hosting

Spamvertised domain/redirector hosting

Return-Path: []@mail.econixis.today> Received: from styx.econixis.today (scl-0044.mails—servers.org [185.239.242.43] (may be forged)) by [] (8.14.7/8.14.7) with ESMTP id [] for []; Sat, 19 Jun 2021 14:[]:[] -0400 Authentication-Results: [] DKIM-Signature: [] DomainKey-Signature: [] Mime-Version: 1.0 Content-Type: multipart/alternative; boundary=»[]» Date: Sat, 19 Jun 2021 20:[]:[] +0200 From: «Excruciating Back Pain» <newsletter@econixis.today> Reply-To: «Excruciating Back Pain» <newsletter@econixis.today> Subject: Arthritis… Читать далее Spamvertised domain/redirector hosting

Spamvertised website

Received: from wcipstk.com (46.16.128.54) From: JIM <info@wcipstk.com> Subject: Bliv en del af Bitcoin-koden Date: Sun, 20 Jun 2021 20:3x:xx +0000 http://wcipstk.com/[] => http://webcourtyard.com/?hitid= => http://speedotechs.com/?hitid= wcipstk.com. 2929 IN A 46.16.128.54 webcourtyard.com. 300 IN A 104.21.70.81 webcourtyard.com. 300 IN A 172.67.221.213 speedotechs.com. 300 IN A 172.67.142.91 speedotechs.com. 300 IN A 104.21.87.76

Spamvertised website

Received: from wcipstk.com (46.16.128.54) From: JIM <info@wcipstk.com> Subject: Bliv en del af Bitcoin-koden Date: Sun, 20 Jun 2021 20:3x:xx +0000 http://wcipstk.com/[] => http://webcourtyard.com/?hitid= => http://speedotechs.com/?hitid= wcipstk.com. 2929 IN A 46.16.128.54 webcourtyard.com. 300 IN A 104.21.70.81 webcourtyard.com. 300 IN A 172.67.221.213 speedotechs.com. 300 IN A 172.67.142.91 speedotechs.com. 300 IN A 104.21.87.76

Carding fraud site/forum: uniccshop.pw (unicc.cx / unicc.com.cm / crdshop.su / cclub.su / cardpin.org / unicc.am / csu.su / abusehost.pro / dumpscrew.com / chindadump.su / dumpshop.net / dumpshop.cc)

Stolen credit card data websites. https://www.google.com/search?q=csu.su https://uniccshop.pw/ >>> https://unicc.cx/ uniccshop.pw. 299 IN A 172.67.209.74 uniccshop.pw. 299 IN A 104.21.82.239 unicc.com.cm. 43200 IN A 51.195.108.176 cclub.su. 2159 IN A 45.88.3.48 _______________ Was: www.uniccshop.market. 299 IN A 185.132.132.139 uniccshop.support. 299 IN A 185.132.132.139 uniccshop.support. 299 IN A 185.132.132.139 unicc.com.cm. 299 IN A 185.132.132.139 uniccshop.pw. 299 IN A… Читать далее Carding fraud site/forum: uniccshop.pw (unicc.cx / unicc.com.cm / crdshop.su / cclub.su / cardpin.org / unicc.am / csu.su / abusehost.pro / dumpscrew.com / chindadump.su / dumpshop.net / dumpshop.cc)