Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cpth-aprv.com #64052

Open
g0d33p3rsec opened this issue Jan 27, 2025 · 0 comments
Open

cpth-aprv.com #64052

g0d33p3rsec opened this issue Jan 27, 2025 · 0 comments
Labels
Malicious Domains used for Malicious software

Comments

@g0d33p3rsec
Copy link
Collaborator

g0d33p3rsec commented Jan 27, 2025

Comments

Domain is being used to serve the first stage of a multistage payload. For more information see Phishing-Database/phishing#724

Wildcard domain records

cpth-aprv.com|malicious

Sub-Domain records


Hosts (RFC:952) specific records, not used by DNS RPZ firewalls


Safe Search records


Screenshots

Screenshot, click to expand

Image

Links to external sources

https://cpth-aprv.com/verify.ps1

Name servers

leah.ns.cloudflare.com.
uriah.ns.cloudflare.com.

logs from uBlock Origin

N/A

@g0d33p3rsec g0d33p3rsec added the Malicious Domains used for Malicious software label Jan 27, 2025
This was referenced Jan 27, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Malicious Domains used for Malicious software
Projects
None yet
Development

No branches or pull requests

1 participant