You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
g0d33p3rsec opened this issue
Feb 1, 2025
· 0 comments
Labels
MaliciousDomains used for Malicious softwarePhishingPhishing is the fraudulent attempt to obtain sensitive information or data, such as usernames, passw
When exploring AS215540 earlier, I came across http://5.181.3.225:8080/ which is an open directory for guardianviewer.com. The site hosts an attack chain for an info stealer http://guardianviewer.com/html/dl/Form%20I-19.pdf.url -> https://guardianviewer.com/docu/Form%20I-19.pdf.lnk -> http://guardianviewer.com/box/setup.msi -> stolen information exfiltrated to sysoieaosgwoeesa.xyz. See also: Phishing-Database/phishing#734
Wildcard domain records
sysoieaosgwoeesa.xyz|malicious,phishing
Sub-Domain records
Hosts (RFC:952) specific records, not used by DNS RPZ firewalls
The text was updated successfully, but these errors were encountered:
g0d33p3rsec
added
Malicious
Domains used for Malicious software
Phishing
Phishing is the fraudulent attempt to obtain sensitive information or data, such as usernames, passw
labels
Feb 1, 2025
MaliciousDomains used for Malicious softwarePhishingPhishing is the fraudulent attempt to obtain sensitive information or data, such as usernames, passw
Comments
When exploring AS215540 earlier, I came across
http://5.181.3.225:8080/
which is an open directory forguardianviewer.com
. The site hosts an attack chain for an info stealerhttp://guardianviewer.com/html/dl/Form%20I-19.pdf.url
->https://guardianviewer.com/docu/Form%20I-19.pdf.lnk
->http://guardianviewer.com/box/setup.msi
-> stolen information exfiltrated tosysoieaosgwoeesa.xyz
. See also: Phishing-Database/phishing#734Wildcard domain records
Sub-Domain records
Hosts (RFC:952) specific records, not used by DNS RPZ firewalls
Safe Search records
Screenshots
Screenshot, click to expand
Links to external sources
Name servers
logs from uBlock Origin
N/A
The text was updated successfully, but these errors were encountered: