add 184.174.97.68 to IP blocklists - Amazon smishing #520
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Phishing Domain/URL/IP(s):
Impersonated domain
https://www.amazon.com
Describe the issue
I received a smishing lure using a shortened link that claimed an unusual charge was made. The server/ CloudFlare returns "NotFound 1001" when attempting to browse from a sandbox but the Amazon favicon can be seen in the screenshot from AnyRun Several other Amazon related domain names can be seen associated with the IP.
Related external source
https://search.censys.io/hosts/184.174.97.68/data/table#80-TCP-HTTP
https://urlscan.io/ip/184.174.97.68
https://app.any.run/tasks/af5d4374-820b-41e0-ace3-ab205f83fda3
https://urlscan.io/result/f1f9aa53-9d19-4a30-89c8-8a719ef8c0c6/#summary
Screenshot
Click to expand