add havenhills.za.com to add-wildcard-domain #459
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Phishing Domain/URL/IP(s):
Impersonated domain
Describe the issue
This domain is now hosting the phishing kit that previously at intrinsicisle[.]za[.]com (#452), reluzformaturas.com.br (#435), abcmueblesbogota[.]com (#432), ergoterapiacaribu[.]ch (#426), ijconnects[.]com (#421), cbcaps[.]shop (#417), bersowir[.]org (#416), brunotasso[.]com[.]br (#413), wisbechguide[.]uk (#408), pescacancun[.]com (#406), bkengineersindia[.]com (#405), englishplusmore[.]com (#404), carnesboinobre[.]com[.]br (#398), technowide[.]com[.]tr (#396), jestertunes[.]com (#393), safecartusa[.]com (#391), foreverfarley[.]com (#387), azezieldraconous[.]com (#381), westernautomobileassembly[.]com (#376) , littleswanaircon[.]com[.]sg (#372), iwan2travel[.]com (#370), applesforfred[.]com (#369), theaerie[.]ca (#367), nico[.]sa (#366), ajstelecom[.]com[.]mx (#362), and others (more than 130 domains since 2021).
Beginning with the previous domain, I have noticed some scans being blocked by Cloudflare. As an example, see
https://urlscan.io/result/1f5ad61c-6548-4b30-9838-77bfd8412cc1/
. Thus far, all scans seem to be blocked on the current domain. Attempting to access locally returns an error message suggesting a misconfiguration with the .htaccess file. Lacking the screenshots I would normally use to verify a new host for this kit, I have attached some screenshots of recent search results showing attempts to distribute links to the domain via social media watering holes. The site has also been flagged as malicious by Google Safe Browsing.Related external source
Screenshot
Click to expand