Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add blueevolution[.]it to wildcard blocklist #489

Conversation

g0d33p3rsec
Copy link
Contributor

Phishing Domain/URL/IP(s):

https://blueevolution.it/M3A1djRvOVI5aDNrNWs= 
https://blueevolution.it/M0s1UjBLMHYyNTVyMVM=
https://blueevolution.it/MzcyMzRWMlY0QzF3ODE=
https://blueevolution.it/M3I1dTJXOGMyMDRjMGg=
https://blueevolution.it/MzUzVTRBMEQxRDVOMXI=
https://blueevolution.it/MzExTzBYOVo4QTJBMzU=
https://blueevolution.it/M1I1MzUyMFAxTzEyNE0=
https://blueevolution.it/M3E1SjNBNlAxbDZkMkE= 
https://blueevolution.it/M1I1cTRQOU4yNDh2MU8=
https://blueevolution.it/M1g1dDREOVY0ZjliM04=

Impersonated domain

https://www.betway.co.za/
https://ff.garena.com/
https://bluvoucher.co.za/
https://play.google.com/store/apps/details?id=com.voicemaker.android&hl=en_US

Describe the issue

This domain is now hosting the phishing kit that previously at draschool[.]org(#488), craigbrimm[.]com(#480), albapietra[.]com[.]br(#479), yanisac[.]com(#478), sbic[.]com[.]br (#477), squad[.]cl(#473), benyex[.]cl (#468), lebomashilo[.]co[.]za (#462), havenhills[.]za[.]com (#459), intrinsicisle[.]za[.]com (#452), reluzformaturas[.]com[.]br (#435), abcmueblesbogota[.]com (#432), ergoterapiacaribu[.]ch (#426), ijconnects[.]com (#421), cbcaps[.]shop (#417), bersowir[.]org (#416), brunotasso[.]com[.]br (#413), wisbechguide[.]uk (#408), pescacancun[.]com (#406), bkengineersindia[.]com (#405), englishplusmore[.]com (#404), carnesboinobre[.]com[.]br (#398), technowide[.]com[.]tr (#396), jestertunes[.]com (#393), safecartusa[.]com (#391), foreverfarley[.]com (#387), azezieldraconous[.]com (#381), westernautomobileassembly[.]com (#376) , littleswanaircon[.]com[.]sg (#372), iwan2travel[.]com (#370), applesforfred[.]com (#369), theaerie[.]ca (#367), nico[.]sa (#366), ajstelecom[.]com[.]mx (#362), and many others.

Related external source

Screenshot

Click to expand

image
image
image
image
image
image
image
image
image
186cebe3-5bdf-4537-b36c-7658f8339590

@g0d33p3rsec
Copy link
Contributor Author

@spirillen should I close #482? The indicators are likely stale by now.

@spirillen spirillen merged commit b46dd8a into Phishing-Database:main Oct 1, 2024
1 check passed
spirillen added a commit to mypdns/matrix that referenced this pull request Oct 1, 2024
@spirillen
Copy link
Contributor

Hmmm why haven't I received a note for that one?? But yes, how make a simple check at first. If still active please give me a ping

And sorry for the delay 😴

iam-py-test added a commit to iam-py-test/my_filters_001 that referenced this pull request Oct 1, 2024
@g0d33p3rsec g0d33p3rsec deleted the add-blueevolution.it-to-wildcard-list branch October 3, 2024 12:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants