mitchellkrogza / phishing

Central Repository for Adding Domains / Links to the Phishing.Database project - https://github.com/mitchellkrogza/Phishing.Database/
49 stars 212 forks source link

Add 45.9.74.36 to ip blocklist #466

Closed g0d33p3rsec closed 3 months ago

g0d33p3rsec commented 3 months ago

Phishing Domain/URL/IP(s):

45.9.74.36
http://45.9.74.36:8888/
http://cloudslimit.com:8888/15582296527056.dll
http://dailywebstats.com:8888/28208068589.dll 
http://hertrud.shop:8888/235713873942.dll
http://hexcrippler.shop:8888/234647089425.dll 
http://hiltrunde.shop:8888/1905070293923.dll
http://iankian.shop:8888/235132567015030.dll
http://ironturner.shop:8888/721256141486.dll
http://kloisa.shop:8888/247102099110965.dll
http://leopolfa.shop:8888/219162541119066.dll 
http://liferacer.shop:8888/16407240006521.dll
http://commodityprocess.top:8888/25028894717122.dll 
http://insights.today-time.sitefind.top:8888/126951871630094.dll

Impersonated domain

Describe the issue

This IP and the related domains are being used to distribute StrellaStealer. This is a sibling of #453

Related external source

https://urlscan.io/search/#page.domain%3A45.9.74.36
https://search.censys.io/hosts/45.9.74.36/data/table#80-TCP-HTTP
https://www.virustotal.com/gui/file/0a075ad634639f5b99b2764f05f364884115ebf4ffeaff54342a25d04befaaef
https://urlscan.io/search/#page.domain%3Acloudslimit.com
https://urlscan.io/search/#page.domain%3Adailywebstats.com
https://urlscan.io/search/#page.domain%3Ahexcrippler.shop
https://urlscan.io/search/#page.domain%3Ahiltrunde.shop
https://urlscan.io/search/#page.domain%3Aiankian.shop
https://urlscan.io/search/#page.domain%3Aironturner.shop
https://urlscan.io/search/#page.domain%3Akloisa.shop
https://urlscan.io/search/#page.domain%3Aleopolfa.shop
https://urlscan.io/search/#page.domain%3Aliferacer.shop
https://urlscan.io/search/#page.domain%3Acommodityprocess.top
https://urlscan.io/search/#sitefind.top

Screenshot

Click to expand ![image](https://github.com/user-attachments/assets/a9809bc0-75cc-4503-a8fe-2dfafa0a0f38)