Advertisement
DhiaLite

Phishing & Spam on 198.27.111.96-127 - Dec 15, 2013

Dec 14th, 2013
559
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.47 KB | None | 0 0
  1. Sat, Dec 14 2013
  2. #DhiaLite - Facebook live phishing domains on 198.27.111.124
  3.  
  4. and entire range 198.27.111.96 to 198.27.111.127 used for phishing and spam
  5.  
  6. Currently 80+ phishing domains are on 198.27.111.124
  7.  
  8. They are under the .pw 2LDs below all registered between Dec 9th and 15th
  9.  
  10. geel3.pw 2013-12-15
  11. geel2.pw 2013-12-15
  12. geel1.pw 2013-12-15
  13. feel3.pw 2013-12-14
  14. feel2.pw 2013-12-14
  15. feel1.pw 2013-12-14
  16. meex5.pw 2013-12-12
  17. deel2.pw 2013-12-12
  18. deel1.pw 2013-12-12
  19. meex3.pw 2013-12-10
  20. meex2.pw 2013-12-10
  21. meex1.pw 2013-12-10
  22. yeel4.pw 2013-12-09
  23. yeel3.pw 2013-12-09
  24. yeel2.pw 2013-12-09
  25. yeel1.pw 2013-12-09
  26.  
  27. Furthermore the range 198.27.111.96 to 198.27.111.127 has been hosting spam and phishing domains since Sep 17th 2013.
  28.  
  29. Currently 6770+ domains have been hosted on this range under the 2LDs shown below
  30.  
  31. One of these 2LD etdht.com has been registered by a registrant with the email greg.oberman@yahoo.com
  32.  
  33. That email address is associated with a profile that registered a lot of other spam domains as shown in http://www.spamhaus.org/rokso/evidence/ROK10048/millionairenetwork.com/partner-in-spam-greg-oberman-oel-media
  34.  
  35. #List of 2LDs of domains on 198.27.111.96 to 198.27.111.127 registered between Sep 17th and Dec 15th 2013
  36. 0x7777.info
  37. 0x8888.info
  38. accountverifikation.com
  39. accountverifikation.de
  40. bdh1.pw
  41. bvbvb.pw
  42. cfn1.pw
  43. chromeserver.us
  44. cnn-money.pw
  45. cnn-news.pw
  46. dbcnetworks.com
  47. dealnetworker.com
  48. deel1.pw
  49. deel2.pw
  50. disonss.pw
  51. dmsoms.pw
  52. easoms.pw
  53. erere.pw
  54. ermsos.pw
  55. esosms.pw
  56. etdht.com
  57. fasmos.pw
  58. fasosc.pw
  59. fasosm.pw
  60. fcsmos.pw
  61. feel1.pw
  62. feel2.pw
  63. feel3.pw
  64. fesmsm.pw
  65. financial-news09.com
  66. financial-news9.com
  67. fox-news.pw
  68. frabum.com
  69. ftyhr.pw
  70. geel1.pw
  71. geel2.pw
  72. geel3.pw
  73. hostingjs.com
  74. jifmd.pw
  75. kunden-verifizierungen.de
  76. masoss.pw
  77. meex1.pw
  78. meex2.pw
  79. meex3.pw
  80. meex5.pw
  81. meine-verifizierung.net
  82. mk2s.pw
  83. mok2.pw
  84. no-ip.info
  85. obfuscationlabs.com
  86. online-safer.net
  87. online-verifizierungen.de
  88. paypal-pruefung.com
  89. paypal-verifizierungen.de
  90. ployu.pw
  91. pruefung-paypal.de
  92. rasoms.pw
  93. ricksnetworks.com
  94. rismso.pw
  95. samsos.pw
  96. securecheck-verificationservice.com
  97. secure-safer.net
  98. sfr4.pw
  99. sichererer-paypal.com
  100. sicherere-zahlung.de
  101. sicherer-paypal.com
  102. sicherheit-kunden.com
  103. starfriend.pw
  104. utynt.pw
  105. verifikation-paypal.info
  106. verifizierungen-paypal.com
  107. verifizierungen-paypal.de
  108. vsemso.pw
  109. vssmos.pw
  110. web-kundenservice.com
  111. wmsish.pw
  112. xfj2.pw
  113. xsc3.pw
  114. xsh1.pw
  115. xsusm.pw
  116. xusms.pw
  117. yeel1.pw
  118. yeel2.pw
  119. yeel3.pw
  120. yeel4.pw
  121. yhruf.pw
  122. zns2.pw
  123. zwq1.pw
  124. #end
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement