Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add moneybadgers domains to wildcard list #492

Conversation

g0d33p3rsec
Copy link
Contributor

@g0d33p3rsec g0d33p3rsec commented Oct 8, 2024

Phishing Domain/URL/IP(s):

https://himosteg.xyz/auth.php 
https://threatdetect.org/auth.php
https://gomlaner.xyz/1Gr/7.html
https://bowigarp.xyz/1/7.html 
https://updatenow.pro/scanning-your-device/
http://securoscans.com/fdgh/gfh54g5fh/dfhgh
https://hirgoles.xyz/1/7.html
https://kositanh.xyz/1/7.html

Impersonated domain

https://www.avast.com
https://norton.com/
https://www.mcafee.com/

Describe the issue

A classmate asked me to look into an unexpected domain, himosteg[.]xyz, that she noticed was blocked by her phone. A scan of the domain led to a login page for "Money Badger$" with the remaining text in Cyrillic. A reverse image search of the logo led to this post, which explained that it was related to a traffic distribution system and fake virus pop-up ads. Looking at the hosting IP on URLScan.io led to related inbound fake virus notifications like those mentioned in the post.

Related external source

https://urlscan.io/result/1bb682cd-e9d8-43fa-8222-ba8effe534fa/
https://urlscan.io/result/df5d07b2-9280-4424-8ea6-8e6000dcecd1/
https://twitter.com/1ZRR4H/status/1685764738121175040
https://urlscan.io/ip/78.129.252.31
https://urlscan.io/result/9c441a7f-25da-4a61-933f-fb30ca0ed0aa/
https://urlscan.io/result/2beab8df-8b1a-4404-83c2-4931dc1da4ef/
https://urlscan.io/result/0529e16c-1d40-4476-9596-d9cb3d576fd0/
https://urlscan.io/result/c12889d4-e97a-4dd8-88fe-1b374876054d/
https://twitter.com/1ZRR4H/status/1685362654712381440

Screenshot

Click to expand

image
9c441a7f-25da-4a61-933f-fb30ca0ed0aa
f091b430-52ea-4912-9e48-7bf0694ce78c
2beab8df-8b1a-4404-83c2-4931dc1da4ef
34f49bae-d695-41c5-b942-d94e54ca18e8
0529e16c-1d40-4476-9596-d9cb3d576fd0

@spirillen spirillen merged commit e67b78d into mitchellkrogza:main Oct 9, 2024
1 check passed
spirillen added a commit to mypdns/matrix that referenced this pull request Oct 9, 2024
- securoscans.com Fixed #MTX-1167
- threatdetect.org Fixed #MTX-1163
- updatenow.pro Fixed #MTX-1166
- bowigarp.xyz Fixed #MTX-1165
- gomlaner.xyz Fixed #MTX-1164
- himosteg.xyz Fixed #MTX-1162
- hirgoles.xyz Fixed #MTX-1168
- kositanh.xyz Fixed #MTX-1169

[//]: # (Github Issues)
Fix #1168
Fix #1167
Fix #1166
Fix #1165
Fix #1164
Fix #1163
Fix #1162
Fix #1161

Rel: mitchellkrogza/phishing#492

Credit: @g0d33p3rsec

---------

Thanks to Jetbrains, for Sponsoring My Privacy DNS with their Open Source software licenses.

Their software helps us develop and maintain My Privacy DNS and other project as they made writing code easier.
spirillen added a commit to mypdns/matrix that referenced this pull request Oct 9, 2024
Fix ^MTX-1171 kalestin.xyz
Fix ^MTX-1172 ragimost.xyz
Fix ^MTX-1173 avgs.fun
Fix ^MTX-1174 daleesh.fun
Fix ^MTX-1175 avastos.fun
Fix ^MTX-1176 firengav.xyz
Fix ^MTX-1177 dolaxabof.xyz
Fix ^MTX-1178 hugabedis.xyz
Fix ^MTX-1179 mabikorst.xyz
Fix ^MTX-1180 worldwidewebshield.info
Fix ^MTX-1181 alhocans.xyz
Fix ^MTX-1182 koruns.xyz
Fix ^MTX-1183 ilertonp.xyz
Fix ^MTX-1184 kusilong.xyz
Fix ^MTX-1185 neburfaw.xyz
Fix #MTX-1186 com-trackahc.top

Rel: mitchellkrogza/phishing#492
Rel: mitchellkrogza/phishing#493

---------

Thanks to Jetbrains, for Sponsoring My Privacy DNS with their Open Source software licenses.

Their software helps us develop and maintain My Privacy DNS and other project as they made writing code easier.

---------

Related GitHub Issues:

- #1169
- #1170
- #1171
- #1172
- #1173
- #1174
- #1175
- #1176
- #1177
- #1178
- #1179
- #1180
- #1181
- #1182
- #1183
- #1184
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants