Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add 184.174.97.68 to IP blocklists - Amazon smishing #520

Conversation

g0d33p3rsec
Copy link
Contributor

Phishing Domain/URL/IP(s):

184.174.97.68
amazoncrx.com
amazoncrw.com
amazonwwj.com
amazoncvo.co
amazonczf.co
amazonctg.com
amazoncth.com

Impersonated domain

https://www.amazon.com

Describe the issue

I received a smishing lure using a shortened link that claimed an unusual charge was made. The server/ CloudFlare returns "NotFound 1001" when attempting to browse from a sandbox but the Amazon favicon can be seen in the screenshot from AnyRun Several other Amazon related domain names can be seen associated with the IP.

Related external source

https://search.censys.io/hosts/184.174.97.68/data/table#80-TCP-HTTP
https://urlscan.io/ip/184.174.97.68
https://app.any.run/tasks/af5d4374-820b-41e0-ace3-ab205f83fda3
https://urlscan.io/result/f1f9aa53-9d19-4a30-89c8-8a719ef8c0c6/#summary

Screenshot

Click to expand

Screenshot_20241129-130646
image
image
image

@spirillen spirillen merged commit efed336 into Phishing-Database:main Nov 30, 2024
1 check passed
spirillen added a commit to mypdns/matrix that referenced this pull request Nov 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants