mypdns / matrix

My Privacy DNS #Matrix lists for blacklisting
https://mypdns.org/
Other
74 stars 10 forks source link

pages.dev #607

Closed g0d33p3rsec closed 2 weeks ago

g0d33p3rsec commented 1 month ago

Comments

While following up on the subdomains mentioned in https://github.com/mitchellkrogza/phishing/pull/422, I discovered additional malicious subdomains that were being primarily hosted at pages[.]dev along with additional related sites with the same signature.

more details are available at https://github.com/mitchellkrogza/phishing/pull/423

Wildcard domain records

null

Sub-Domain records

adobe-jhhkwjrnfjadenfrskbgjlsnfgjdfn.pages.dev|phishing
adobeli.pages.dev|phishing
ariamanonux03p.pages.dev|malicious
att-mail.pages.dev|phishing
begincellcdn.pages.dev|phishing
blurverse.pages.dev|phishing
borsbrietjblrenlgbrlenhjt.pages.dev|phishing
cfgxgfxf.pages.dev|phishing
chainsrectify.pages.dev|phishing
claim-pork.pages.dev|phishing
clfpages2.pages.dev|phishing
dappsyncrectify.pages.dev|phishing
debanksdefi.pages.dev|phishing
decentralizedappauth.pages.dev|phishing
decentrausdchartfil.pages.dev|phishing
diamond-hands-halo.pages.dev|phishing
doctored.pages.dev|phishing
dogecoin20-st.web.app|phishing
fq703w52zt.pages.dev|malicious
iengjwklengkhwebhfceref.pages.dev|phishing
ixs.pages.dev|malicious,phishing
ixs.pages.dev|malicious|phishing
jgeb6c8queuspv.pages.dev|phishing
jkrngjkernghernhgtehjnhk.pages.dev|phishing
livedappsrestore.pages.dev|phishing
looksrare-d1x.pages.dev|phishing
lourdesthompsonnf1r6.pages.dev|malicious
mi-d1m.pages.dev|phishing
micro-service-alertc0277sb-dev-err.pages.dev|phishing
micro-service-alertc0277sb-erro.pages.dev|phishing
micro-soft-failed-error.pages.dev|phishing
micro-soft-virus-alert-warning.pages.dev|phishing
microsoft-error-pages-check-errors.pages.dev|phishing
microsoft-help-and-services.pages.dev|phishing
microsoft-sales-hhgdygfg-asd.pages.dev|phishing
microsoft-suppor-number.pages.dev|phishing
microsoft-support-alrt-altr-fds-098.pages.dev|phishing
microsoft-support-alrt-altr-fds.pages.dev|phishing
microsoft-support-alrt-altr87785.pages.dev|phishing
microsoft-terms-policyalr.pages.dev|phishing
mykeruais-assets-cubu45.pages.dev|phishing
newwork-6oy.pages.dev|phishing
nodesappfix-io.pages.dev|phishing
oscarcampbellb1eoi.pages.dev|malicious
pandoraprejeangw6.pages.dev|phishing
paperhander.pages.dev|phishing
paperhands-portfoliotracker-wallet.pages.dev|phishing
pooh-moneydapps.pages.dev|phishing
portal-platform.pages.dev|phishing
proxysync.pages.dev|phishing
pub-fa147a3cddd04e9588b0d0a71d6d87fb.r2.dev|phishing
rpcrecoveryhub.pages.dev|phishing
sd-74h.pages.dev|phishing
sontungmtpmaidinhnhe.pages.dev|phishing
spacexlaunch.pages.dev|phishing
swiftblockresolve.pages.dev|phishing
sync-7xr.pages.dev|phishing
syncblockrectification.pages.dev|phishing
teach-work-onlines2222177.pages.dev|phishing
tesla-2ju.pages.dev|phishing
tl-4-vente-privee-b1j.pages.dev|phishing
ueajflnjejdrwklnvkenrwjgnlvrjldf.pages.dev|phishing
uni-swap-protocols.pages.dev|phishing
verifyandfixdapp.pages.dev|phishing
webaqunarmail.pages.dev|phishing
webmial.pages.dev|phishing
win-defender-sec-64csvxxvxxvxx0x665.pages.dev|phishing
woow-seguro-de-viajes.pages.dev|phishing
1-67c.pages.dev|malicious
2-3a2.pages.dev|malicious
accept-altlayer.pages.dev|malicious
airdropsaltlayer.pages.dev|malicious
allocation-satoshivm.pages.dev|malicious
alpha-satoshvmio.pages.dev|malicious
alt-e7v.pages.dev|malicious
altlayer.pages.dev|malicious
altlayer-ejy.pages.dev|malicious
altltlsadlfasdasdf.pages.dev|malicious
bonus-8u0.pages.dev|malicious
claim-altlayer.pages.dev|malicious
claim-starknet.pages.dev|malicious
claima.pages.dev|malicious
coins-satoshivm.pages.dev|malicious
create-dymensionxyz.pages.dev|malicious
defi-starkne.pages.dev|malicious
discover-manta.pages.dev|malicious
diving-mantanetwork.pages.dev|malicious
dym-ehu.pages.dev|malicious
dymension.pages.dev|malicious
enlist-altlayer.pages.dev|malicious
exploremanta.pages.dev|malicious
frame-6i5.pages.dev|malicious
framecom.pages.dev|malicious
framezap.pages.dev|malicious
getmanta.pages.dev|malicious
governance-mantanetwork.pages.dev|malicious
gratitude-satoshivm.pages.dev|malicious
kri90r23rk2ikr32.pages.dev|malicious
linea-mirrorxyz.pages.dev|malicious
linealxp.pages.dev|malicious
mainnet-lineabuild.pages.dev|malicious
mainnet-satoshivmio.pages.dev|malicious
mainnet-satoshivmio-1cp.pages.dev|malicious
manta-1c8.pages.dev|malicious
manta-network.pages.dev|malicious
mantanetwork-8tn.pages.dev|malicious
mantax.pages.dev|malicious
maxethxyz.pages.dev|malicious
mine-framexyz.pages.dev|malicious
mine-mantanetwork.pages.dev|malicious
new-framexyz.pages.dev|malicious
new-lineabuild.pages.dev|malicious
new-manta.pages.dev|malicious
obtain-manta.pages.dev|malicious
obtainmanta.pages.dev|malicious
qualifymanta.pages.dev|malicious
receive-altlayerio.pages.dev|malicious
registry-linea.pages.dev|malicious
registryzetachain.pages.dev|malicious
satoshi-364.pages.dev|malicious
stake1.pages.dev|malicious
support-manta.pages.dev|malicious
take-satoshivm.pages.dev|malicious
visit-dymension.pages.dev|malicious
visit-lineabuild.pages.dev|malicious
web-fix.pages.dev|malicious
web3-manta.pages.dev|malicious
whitelist-altlayerom.pages.dev|malicious
whitelistalt.pages.dev|malicious
zk-manta-airdrop.pages.dev|malicious

Hosts (RFC:953) specific records, not used by DNS RPZ firewalls

No response

SeafeSearch records

No response

Screenshots

Screenshot ![342395546-7ce1647d-a86c-422e-9d3b-7be2068f5226](https://github.com/mypdns/matrix/assets/108126637/544617e9-a76a-48ae-b741-346ba1665fe3) ![342395642-ca27178d-e565-4f77-b433-85e79dad9100](https://github.com/mypdns/matrix/assets/108126637/3b7b2d02-c17e-4c08-9a00-d43e764893c3) ![342395757-18df36ea-690d-46d3-b409-7efc6e92cafa](https://github.com/mypdns/matrix/assets/108126637/00bb9b3a-f9cc-4fed-8b0a-a2edff6b8475) ![342396527-0f7a2ed0-5a33-4d47-844b-3e0574d3be97](https://github.com/mypdns/matrix/assets/108126637/a811147f-b44d-4b36-ae99-a27e3c8c7e18) ![342397478-d8752d23-b147-427e-b148-c565c46ea759](https://github.com/mypdns/matrix/assets/108126637/351afaab-95d7-4d22-8bff-342b95306475)

Links to external sources

No response

logs from uBlock Origin

N/A

spirillen commented 1 month ago

:+1: added in https://github.com/mypdns/matrix/commit/5316feb21a067a196c500fe9fff5dd1f9e7eb361

g0d33p3rsec commented 1 month ago

🎁

ariamanonux03p.pages.dev|malicious|phishing
att-mail.pages.dev|phishing
begincellcdn.pages.dev|phishing
blurverse.pages.dev|phishing
cfgxgfxf.pages.dev|phishing
chainsrectify.pages.dev|phishing
claim-pork.pages.dev|phishing
clfpages2.pages.dev|phishing
dappsyncrectify.pages.dev|phishing
debanksdefi.pages.dev|phishing
decentralizedappauth.pages.dev|phishing
decentrausdchartfil.pages.dev|phishing
diamond-hands-halo.pages.dev|phishing
doctored.pages.dev|phishing
dogecoin20-st.web.app|phishing
fq703w52zt.pages.dev|malicious|phishing
ixs.pages.dev|malicious|phishing
jgeb6c8queuspv.pages.dev|phishing
livedappsrestore.pages.dev|phishing
looksrare-d1x.pages.dev|phishing
lourdesthompsonnf1r6.pages.dev|malicious|phishing
mykeruais-assets-cubu45.pages.dev|phishing
newwork-6oy.pages.dev|phishing
nodesappfix-io.pages.dev|phishing
oscarcampbellb1eoi.pages.dev|malicious|phishing
pandoraprejeangw6.pages.dev|phishing
paperhander.pages.dev|phishing
paperhands-portfoliotracker-wallet.pages.dev|phishing
pooh-moneydapps.pages.dev|phishing
portal-platform.pages.dev|phishing
proxysync.pages.dev|phishing
rpcrecoveryhub.pages.dev|phishing
sontungmtpmaidinhnhe.pages.dev|phishing
spacexlaunch.pages.dev|phishing
swiftblockresolve.pages.dev|phishing
sync-7xr.pages.dev|phishing
syncblockrectification.pages.dev|phishing
tesla-2ju.pages.dev|phishing
tl-4-vente-privee-b1j.pages.dev|phishing
uni-swap-protocols.pages.dev|phishing
verifyandfixdapp.pages.dev|phishing
webaqunarmail.pages.dev|phishing
webmial.pages.dev|phishing
woow-seguro-de-viajes.pages.dev|phishing
spirillen commented 1 month ago

This one do not Belong here :smirk:

pub-fa147a3cddd04e9588b0d0a71d6d87fb.r2.dev|phishing
g0d33p3rsec commented 3 weeks ago

additional phishing subdomains

84918e83348-reviewpage.pages.dev|phishing
84913240098-reviewpage.pages.dev|phishing
83910840-reviewpages.pages.dev|phishing
24715454098-reviewpages.pages.dev|phishing
738592845-review-pages.pages.dev|phishing
admin-ery.pages.dev|phishing
adobe-jkwefnewkjnfkjewnfkejwnfkjew.pages.dev|phishing
api-webchainfix.pages.dev|phishing
app-dappfix.pages.dev|phishing
decentralizationserver.pages.dev|phishing
defi-encrypt.pages.dev|phishing
diamondschoolss.pages.dev|phishing
g98765xfghjk654wrt.pages.dev|phishing
harambe-claim.pages.dev|phishing
multichaindexauth.pages.dev|phishing
multichainsolutionsfix.pages.dev|phishing
myid-cubu75674.pages.dev|phishing
onedrive-19e.pages.dev|phishing
page-time0t1frr13.pages.dev|phishing
page-time65463fdhsr.pages.dev|phishing
page-timehfy63535.pages.dev|phishing
page-timereyrgebrg.pages.dev|phishing
resdgsbvcfghgt67uhj89ikjnhgvcxcfghttyu3wsgzfc3bhytfcvvcfhz.pages.dev|phishing
steam-trader-tool.pages.dev|phishing
syncfulldap.pages.dev|phishing
update345.pages.dev|phishing
ww-wellsfargo.pages.dev|phishing

external sources

https://urlscan.io/result/9e52e82d-c324-4468-afe4-3790f93b2967/
https://urlscan.io/result/6a13f579-b7ba-4f56-b762-676359c84fea/
https://www.virustotal.com/gui/url/fda6b313eac6fa58ec064accf2f428a41b48259e27c09191e656afe197ad4915
https://urlscan.io/result/83ea0cdd-bb53-4349-ae2d-0db918605d7c/
https://www.virustotal.com/gui/url/7cdb0aa7b26bec35f94178982f79e04272e58e23e3ce05b829c675ce3689bfe4
https://urlscan.io/result/45a67c49-5ec9-474f-9806-3c0c9a0062a9/
https://www.virustotal.com/gui/url/8e3d6310afd0d21548d66b2e83b1d6225d57b2edad9781c61afa934e45988eca
https://urlscan.io/result/237f9116-c645-42e5-8b02-0430b47e3efc/
https://www.virustotal.com/gui/url/8e620774c6952cac83d9b81655088f7078c22bab75a88b932f4dd2a0c7979ff4
https://urlscan.io/result/90945e9c-35f7-4a40-912f-e39feae0a2ba/
https://www.virustotal.com/gui/url/3f061345e63b46a4d1207b35b5790a56088ebf718e333cc949a6cc824b1aa0a4
https://urlscan.io/result/dd437647-63a3-4417-8a37-1bc80b181f76/
https://www.virustotal.com/gui/url/77304ced249eedfe82f2e227af1e6465fc7b06c7a56f4652edbe605ea40758ec
https://urlscan.io/result/3835eb6c-0e18-44ae-b181-6cfa2058cae3/
https://www.virustotal.com/gui/url/326066aa9960401efbe7d20df557c7e546576ac25ad4bbe4dcb78113619355e8
https://urlscan.io/result/36a03552-6ffe-4399-b852-0fc16d320ab9/
https://urlscan.io/result/299cd0dd-5855-4d96-8247-44ce3ef67e2e/
https://www.virustotal.com/gui/url/2181c5f83d23706b9223b2bb394ceee68de357b4756a02c09eed61c43e3cb944
https://urlscan.io/result/21fbc6ec-9cfc-4049-89e0-96d4a3b13bd7/
https://www.virustotal.com/gui/url/49f9e5b92158a39302f9f763fa6e6f4aa2d4f841194ebcc6fa5495fe5004b858
https://urlscan.io/result/3c7ede2d-f909-4245-b3be-5713758006c9/
https://www.virustotal.com/gui/url/58b0319ee0fb0ae79f4a55b6877d85f57b375daa3cb2b8066700d2de0d44a288
https://urlscan.io/result/e8df736d-225d-45ea-b323-649768989874/
https://www.virustotal.com/gui/url/5ebc9658f4f3c39f94b8c27cae96b9f9cbbfc9e0ee8d0c86a59542e0d36e4d48
https://urlscan.io/result/5edffa13-4846-49c1-bc4d-5e70b74b9a24/
https://www.virustotal.com/gui/url/ddeaf01d4a369fa0300d8b8ea5198b966cf7f0aec29b4e1c3120d784716b66b4
https://urlscan.io/result/2b584eb1-8f44-47e7-936d-8442b12e2178/
https://www.virustotal.com/gui/url/9ed57a6f7c955a52415076cd936e42ff4ebfc8fd1cadc5db709d319cd4692e0f
https://urlscan.io/result/61e4ad2e-89bd-4d8e-ac7c-ce8b4e173fab/
https://www.virustotal.com/gui/url/c61e2aaa5eec746e82747e5d82cad9e27ebf209e0798ed2153a8dd9affc95933
https://urlscan.io/result/c07ec522-d63c-4203-866a-f6918fb2bcf3/
https://www.virustotal.com/gui/url/e0c5a4ccebe42265a22b742b77b4ca1bd432226cfd68fdc452cfb2d9a8da3f12
https://urlscan.io/result/7c94b522-f284-4ad3-9411-c4d974b0e95f/
https://www.virustotal.com/gui/url/3783e297ad4fb43af77a1e422c43cc20399fa6fdebc097a31c0b1094f143d19a
https://urlscan.io/result/b1baa499-dbe4-4d99-a185-6704ea8b9edc/
https://www.virustotal.com/gui/url/465418d7cca9235217deffeec33629d7262b68668ad22e38ffcc75c8942cf5b5
https://urlscan.io/result/d092fe81-71eb-40b6-b5b1-d378e3940146/
https://www.virustotal.com/gui/url/1b51f305b5952ec2bf2cc103e7f04a037f8e93ab5db14ae0710d60c5940e74cd
https://urlscan.io/result/51f1da20-7c5c-4b0c-9b33-a6cab4d8b6b2/
https://www.virustotal.com/gui/url/4a583a3d24915c29c4ccdf1b0bb5588afb903423444dd43716c263af4b3b2c3d
https://urlscan.io/result/bbe0c172-e7e8-40da-9503-21bf1a61c729/
https://www.virustotal.com/gui/url/71907f83dca9b4f379f58c9042349075f40d62473f49e7fed2af68a8b9aa257f
https://urlscan.io/result/5fbe6560-c476-4756-911b-1cc02158e863/
https://urlscan.io/result/649576ac-178e-4dcc-bd36-361476eb0696/
https://www.virustotal.com/gui/url/b0b791d5741b3cee3d9cf4d873f4952ab4857420b2531a436c1145fbd85d8417
https://urlscan.io/result/0c571018-98a9-4af8-97d4-aa701c568e08/
https://www.virustotal.com/gui/url/8752165cba3af5133d349f97f4661eb17b4e2671ac8173ab1908543f924838c2
https://urlscan.io/result/7dee5822-6e5b-4ea6-b054-60c2a28ce4ac/
https://www.virustotal.com/gui/url/ea089b08151d8be8a2808b3a24c8a0141a1f39057285890e4bc4e764f4dd4dd1
https://urlscan.io/result/2193e742-d9bd-4ddc-819c-1d9b69178cb0/
https://www.virustotal.com/gui/url/7d6a08e4828868ab57fa9a7f7347726d7e7d8b6aef07036b3c35575e3b45c5a5

Screenshots

Click to expand ![346211862-b42ef5ac-d266-4bf5-9690-ec9b772608e6](https://github.com/mypdns/matrix/assets/108126637/4de750ee-4ae7-47d4-a120-37a4500d5297) ![346216166-a561bfee-c27b-4f11-8a71-59592ad572d9](https://github.com/mypdns/matrix/assets/108126637/2fbc19c8-486e-4842-aef3-d4997368c57d) ![346216298-09d69ec0-6731-4bd6-8a22-e9fd81b6c76c](https://github.com/mypdns/matrix/assets/108126637/f2f27731-c1d4-4b06-bd7e-f21835ed10b8) ![346216377-907369fe-cc40-4944-bd5f-8ed5fe3e383c](https://github.com/mypdns/matrix/assets/108126637/138c14ba-5e2c-4644-9829-57065100215e) ![346216595-44c59305-3739-4540-977f-7da2bea80040](https://github.com/mypdns/matrix/assets/108126637/e379ee7c-c220-427b-8b05-623c5beb5a43) ![346216784-ea58c41c-182f-44d8-b60f-3ce3054eb426](https://github.com/mypdns/matrix/assets/108126637/9f220a2d-f737-4bd8-8233-17730d50551a) ![346217065-21ca89b0-bcd3-4fec-a1c0-9bf736ece316](https://github.com/mypdns/matrix/assets/108126637/47e008e0-5f95-4efb-819b-2f0c11be76b0) ![346217265-517eeb59-030a-40cd-9674-3e13e9089b03](https://github.com/mypdns/matrix/assets/108126637/2e4696cf-aa64-497a-b75b-0dd767d0df12) ![346217429-47d84742-afb6-4d82-bf9e-c2f1a2938c3a](https://github.com/mypdns/matrix/assets/108126637/9878e3e2-1a74-4a5f-9b59-523462223c35) ![346217464-fa25c142-b81f-4f12-af49-2eb66428ea0f](https://github.com/mypdns/matrix/assets/108126637/6a287ab9-cc20-4640-9541-9cfcd565df9f) ![346217620-98d7dcb4-757d-49db-8296-3c7e49fc900e](https://github.com/mypdns/matrix/assets/108126637/ad104ab8-51ee-487e-bbe5-051595788be5) ![346218482-f859fc88-7a8d-4af0-be36-c1cabf44f45e](https://github.com/mypdns/matrix/assets/108126637/3798c8cd-5e29-432c-9974-480270bb28bf) ![346218635-68fe04e7-51ee-4fac-a8b0-ac01f104fff7](https://github.com/mypdns/matrix/assets/108126637/9ce243f8-eb1c-4173-93f4-106eccb3bfba) ![346218842-c481cac7-3127-4706-b341-52546e50d23c](https://github.com/mypdns/matrix/assets/108126637/61a777b6-2dc5-427a-9344-a737d80b37ba) ![346218916-4c0a8da3-7256-4231-9bb7-4fb0d8a4db1a](https://github.com/mypdns/matrix/assets/108126637/e51ba1b1-18f7-486a-b240-bd95c72d9364) ![346220550-9dbb3d0f-15be-410c-bf03-7fcf60600361](https://github.com/mypdns/matrix/assets/108126637/c0fb3f3f-e826-4234-9237-05499762bbb6) ![346221179-a5ddc5e6-bade-420d-a9d6-37804931c5a2](https://github.com/mypdns/matrix/assets/108126637/829ca39c-c7af-4f47-85b0-fb9af3301f11) ![346221235-46e2de80-9bd8-4746-a8e1-a898a4e48e18](https://github.com/mypdns/matrix/assets/108126637/2f34f9f0-a6b3-402e-b738-dd2f267979a0) ![346221389-77a0a6c6-2492-4425-a83c-d3e7ee21f4c0](https://github.com/mypdns/matrix/assets/108126637/708af717-c8c6-4052-9074-23cd1033a256) ![346221661-6a1d3ae4-c6f7-447d-bbca-aed172fff100](https://github.com/mypdns/matrix/assets/108126637/fa71a0c8-4d32-42d0-8edd-6c1837da922a)

See also: https://github.com/mitchellkrogza/phishing/pull/442

spirillen commented 3 weeks ago

Any particular reason for why we haven't called for Mjølner yet?

image

g0d33p3rsec commented 3 weeks ago

Any particular reason for why we haven't called for Mjølner yet?

It's not quite time for the hammer yet but I did break out the e-crime fighting version of programming socks IMG_20240705_212203335_HDR(1)

spirillen commented 3 weeks ago

ROFL-Emoticon

Yeah I mean it doesn't looks to much that they are ready to handle the wheel:whells yet, maybe if we could find there account here we could help them by drawing there attention towards these lists..

g0d33p3rsec commented 2 weeks ago

See also: https://github.com/mitchellkrogza/phishing/pull/448

1-67c.pages.dev|malicious
2-3a2.pages.dev|malicious
accept-altlayer.pages.dev|malicious
airdropsaltlayer.pages.dev|malicious
allocation-satoshivm.pages.dev|malicious
alpha-satoshvmio.pages.dev|malicious
alt-e7v.pages.dev|malicious
altlayer.pages.dev|malicious
altlayer-ejy.pages.dev|malicious
altltlsadlfasdasdf.pages.dev|malicious
bonus-8u0.pages.dev|malicious
claim-altlayer.pages.dev|malicious
claim-starknet.pages.dev|malicious
claima.pages.dev|malicious
coins-satoshivm.pages.dev|malicious
create-dymensionxyz.pages.dev|malicious
defi-starkne.pages.dev|malicious
discover-manta.pages.dev|malicious
diving-mantanetwork.pages.dev|malicious
dym-ehu.pages.dev|malicious
dymension.pages.dev|malicious
enlist-altlayer.pages.dev|malicious
exploremanta.pages.dev|malicious
frame-6i5.pages.dev|malicious
framecom.pages.dev|malicious
framezap.pages.dev|malicious
getmanta.pages.dev|malicious
governance-mantanetwork.pages.dev|malicious
gratitude-satoshivm.pages.dev|malicious
kri90r23rk2ikr32.pages.dev|malicious
linea-mirrorxyz.pages.dev|malicious
linealxp.pages.dev|malicious
mainnet-lineabuild.pages.dev|malicious
mainnet-satoshivmio.pages.dev|malicious
mainnet-satoshivmio-1cp.pages.dev|malicious
manta-1c8.pages.dev|malicious
manta-network.pages.dev|malicious
mantanetwork-8tn.pages.dev|malicious
mantax.pages.dev|malicious
maxethxyz.pages.dev|malicious
mine-framexyz.pages.dev|malicious
mine-mantanetwork.pages.dev|malicious
new-framexyz.pages.dev|malicious
new-lineabuild.pages.dev|malicious
new-manta.pages.dev|malicious
obtain-manta.pages.dev|malicious
obtainmanta.pages.dev|malicious
qualifymanta.pages.dev|malicious
receive-altlayerio.pages.dev|malicious
registry-linea.pages.dev|malicious
registryzetachain.pages.dev|malicious
satoshi-364.pages.dev|malicious
stake1.pages.dev|malicious
support-manta.pages.dev|malicious
take-satoshivm.pages.dev|malicious
visit-dymension.pages.dev|malicious
visit-lineabuild.pages.dev|malicious
web-fix.pages.dev|malicious
web3-manta.pages.dev|malicious
whitelist-altlayerom.pages.dev|malicious
whitelistalt.pages.dev|malicious
zk-manta-airdrop.pages.dev|malicious

Fixing some stale IOCs from Cisco's reporting.

This morning, Cisco's Talos Intelligence Group released a report How do cryptocurrency drainer phishing scams work? which included a list of Indicators of Compromise (IOCs). Unfortunately, most of the IOCs listed are no longer active and of little tactical value. Fortunately, searching for the indicators on URLscan.io and then viewing the "similar" results yields many related active sites.

Listed IOCs that are still active

spirillen commented 2 weeks ago

This is insane... they seems to do nothing like in nada, zip, zero, null to protect the domain, this makes it a risky to keep it open to my POV, would you like to reconsider the hammer?

g0d33p3rsec commented 2 weeks ago

This is insane... they seems to do nothing like in nada, zip, zero, null to protect the domain, this makes it a risky to keep it open to my POV, would you like to reconsider the hammer?

It is getting to that point. I hate to slam a site that offers free hosting but at this point the threat outweighs any benefit. On the other hand, they seem to police their platform better than Cloudfare.

spirillen commented 2 weeks ago

ok, but next time I believe this is going to be changed into a wildcard blocking, as CF are well known to hosts and protect scam/spam/phishing/malicious/POP and so on. So if you find something on worker.dev... add them as wildcard. anything else would requires automatisation code, which we do not have for know.