Exposing a Domains Portfolio Courtesy of Breached Forum Team Members - An OSINT Analysis
0Interesting domains include:
hxxp://secured-logins.online
hxxp://microsoftupdale.com
hxxp://amzn-offer.com.ng
hxxp://paypalcustomerservices.com
Sample domains known to have been involved in the campaign include:
hxxp://biunj[.]top
hxxp://wzmxec[.]cn
hxxp://semainedelapopphilosophie[.]fr
hxxp://haileybeauty[.]fr
hxxp://kellyblake[.]us
hxxp://securitylab[.]hk
hxxp://texasaction[.]us
hxxp://kazuko[.]us
hxxp://purgestresser[.]xyz
hxxp://bagipokemon[.]com
hxxp://moneymatterswitheric[.]com
hxxp://idriss[.]fr
hxxp://bluesteelcraft[.]net
hxxp://phohangcu[.]com
hxxp://kookwinkels[.]net
hxxp://mediumsonja[.]net
hxxp://ukmshops[.]com
hxxp://makebelief[.]science
hxxp://depressioncure[.]science
hxxp://aisukoneko[.]net
hxxp://82flex[.]club
hxxp://ssri[.]science
hxxp://snri[.]science
hxxp://gadjahmada[.]org
hxxp://keralacultural[.]science
hxxp://internetmarketergroup[.]com
hxxp://sampitroda[.]science
hxxp://apjabdulkalam[.]science
hxxp://floatingmind[.]science
hxxp://neurotransmission[.]science
hxxp://sunitawilliams[.]science
hxxp://teslamemorial[.]science
hxxp://moodregulation[.]science
hxxp://antipsychotic[.]science
hxxp://originofearth[.]science
hxxp://wardenclyffetower[.]science
hxxp://antidepressant[.]science
hxxp://chuvabravasolfeliz[.]com
hxxp://vasthu[.]science
hxxp://resumosparaprovas[.]com[.]br
hxxp://ultra1337s[.]pro
hxxp://indiancultural[.]science
hxxp://resuminhosparaprovas[.]com
hxxp://benchfee[.]net
hxxp://homijbhabha[.]science
hxxp://blunder[.]science
hxxp://paradisusloscabos[.]com
hxxp://meums[.]edu[.]ly
hxxp://serinformatico[.]com
hxxp://gs-france[.]fr
hxxp://modaparatodo[.]com[.]br
hxxp://proshoponline[.]com[.]br
hxxp://sr-ken1[.]com
hxxp://iltdamktdigital[.]com[.]br
hxxp://meums[.]ly
hxxp://sportday[.]com[.]br
hxxp://chauffeur24[.]ma
hxxp://shoukai-system[.]net
hxxp://fuertedestination[.]com
hxxp://bykvu[.]com
hxxp://f-gmail[.]com
hxxp://marsoul-tech[.]ly
hxxp://alanosempre[.]com
hxxp://esercizi-e-rimedi[.]com
hxxp://whdhwfawla[.]com
hxxp://vectorofdream[.]club
hxxp://p-at-g[.]info
hxxp://recruitmentsourcing[.]us
hxxp://koisit[.]com
hxxp://your-candle[.]com
hxxp://woshilaosijikuaishangche[.]xyz
hxxp://casadipasta[.]fr
hxxp://connectionloop[.]jp
hxxp://osamathabet[.]com
hxxp://capl[.]com[.]sg
hxxp://puccinis[.]us
hxxp://allinfotoday[.]us
hxxp://btler[.]kz
hxxp://aventerpriseindia[.]com
hxxp://smart99sendai[.]com
hxxp://mgo777[.]us
hxxp://ced-guitare34[.]fr
hxxp://suntech[.]com[.]pa
hxxp://merhawitravels[.]com
hxxp://weknownothingpodcast[.]com
hxxp://purehempsoap[.]ca
hxxp://organia[.]com[.]ua
hxxp://lnwgame[.]com
hxxp://vikingventures[.]us
hxxp://vygoranie[.]su
hxxp://my-mail-gmail[.]com
hxxp://login-mail-gmail[.]com
hxxp://fundaciondeespecialistas[.]com
hxxp://market365[.]com[.]ua
hxxp://lindsayfashions[.]com
hxxp://jornaldosbairrosonline[.]com[.]br
hxxp://petirketarketir[.]vip
hxxp://siam1[.]net
hxxp://hi9765[.]com
hxxp://fathersclub[.]us
hxxp://account-my-mail-gmail[.]com
hxxp://myaccount-my-mail-gmail[.]com
hxxp://goodgirls101[.]com
hxxp://freender[.]us
hxxp://myaccounts-mail-gmail[.]com
hxxp://hot-auto[.]com[.]ua
hxxp://ygu-1[.]net
hxxp://xn--jn2a86s[.]tw
hxxp://kvadrat-m[.]com
hxxp://curriculo2022[.]com
hxxp://vishakafoundation[.]com
hxxp://app12123[.]com
hxxp://donnaree[.]net
hxxp://e-standart[.]com
hxxp://neposidko[.]com
hxxp://mgo55[.]us
hxxp://bidiknews24[.]com
hxxp://mosclub[.]su
hxxp://iniq[.]us
hxxp://mfenno[.]com
hxxp://2t[.]gs
hxxp://deesign[.]co[.]kr
hxxp://mail-gmail[.]com
hxxp://iorganicpetshop[.]com
hxxp://iorganichouse[.]com
hxxp://humresource[.]com
hxxp://ko-bo-440[.]com
hxxp://hayao0819[.]com
hxxp://hog-lab[.]com
hxxp://hi12123[.]com
hxxp://hshealt[.]com
hxxp://myaccounts-my-mail-gmail[.]com
hxxp://findabitch[.]info
hxxp://my-account-mail-gmail[.]com
hxxp://gosspcrepair[.]com
hxxp://my-accounts-mail-gmail[.]com
hxxp://lizihost[.]com
hxxp://copticsite[.]com
hxxp://petenjess[.]com
hxxp://shinobu[.]kr
hxxp://shinbou[.]co[.]kr
hxxp://hamptoonu[.]com
hxxp://cryptbits[.]us
hxxp://cryptoskope[.]us
hxxp://blockhodl[.]us
hxxp://cryptomonist[.]us
hxxp://cityofcrypto[.]us
hxxp://chainofthings[.]us
hxxp://hesapcibaba[.]com
hxxp://emeraldenzosculptures[.]com
hxxp://gh-herbals[.]us
hxxp://hallareview[.]com
hxxp://solnyshko-2022[.]kz
hxxp://amzn-offer[.]com[.]ng
hxxp://rce[.]net[.]cn
hxxp://arol[.]us
hxxp://consejoscomunalesparaladefensaintegral[.]xyz
hxxp://noticiasnaweb[.]net
hxxp://quick2pey[.]us
hxxp://microsoftupdale[.]com
hxxp://sribiosys[.]com
hxxp://proxmoxve[.]cn
hxxp://whmcsservices[.]cn
hxxp://virtualizor[.]cn
hxxp://goodealhosting[.]cn
hxxp://fetomagduruaileler[.]net
hxxp://28subatvefetomagduruaileler[.]net
hxxp://zjmftheme[.]cn
hxxp://shieyingxiong[.]cn
hxxp://whmcshelp[.]com
hxxp://habersilvangazetesi[.]com
hxxp://dusunce360[.]com
hxxp://hurtakipci[.]com
hxxp://urfahurhaber[.]com
hxxp://dieq41[.]com
hxxp://arminarekaperdanahalim[.]com
hxxp://cains[.]party
hxxp://topsalestoday[.]us
hxxp://stuartpowell[.]us
hxxp://animu[.]su
hxxp://cleanconnect[.]us
hxxp://truthtrend[.]us
hxxp://milina[.]jp
hxxp://pchd[.]one
hxxp://ricambiauto[.]us
hxxp://rachelmorton[.]us
hxxp://shopauro[.]us
hxxp://sppt[.]us
hxxp://effectivtech[.]us
hxxp://careerchanger[.]us
hxxp://jleon-automation[.]us
hxxp://johnlwaite[.]com
hxxp://lakeshore[.]tw
hxxp://no-no-no-no[.]com
hxxp://alisonjones[.]us
hxxp://segner[.]us
hxxp://charliem[.]us
hxxp://valuation[.]co[.]il
hxxp://no-no[.]com
hxxp://trumpersonly[.]us
hxxp://posten-no-no[.]com
hxxp://totallyavir[.]us
hxxp://kathypizzino[.]us
hxxp://wildburger[.]us
hxxp://cfodesk[.]co[.]il
hxxp://whisky-a-no-no[.]com
hxxp://trevorhill[.]us
hxxp://charliemoore[.]us
hxxp://no-no-no[.]com
hxxp://michaelstamerfarms[.]com
hxxp://voidedparadox[.]com
hxxp://my-no-no[.]com
hxxp://zeromatter[.]us
hxxp://cuntmode[.]com
hxxp://figyak[.]com
hxxp://oht[.]com[.]tw
hxxp://herbalhongkong[.]com
hxxp://mo-no-no[.]com
hxxp://jumphost[.]kz
hxxp://nana-no-no[.]com
hxxp://liveearth-no-no[.]com
hxxp://candronepilotcoop[.]com
hxxp://celebrity-no-no[.]com
hxxp://escobarproductions[.]us
hxxp://yasu-no-no[.]com
hxxp://vjdiamonds[.]co[.]il
hxxp://burkardt[.]us
hxxp://buy-no-no[.]com
hxxp://makabaka[.]us
hxxp://me-no-no[.]com
hxxp://pnrsyntax[.]us
hxxp://big-no-no[.]com
hxxp://visentagroup[.]com
hxxp://aki-no-no[.]com
hxxp://carte-vital-notification[.]fr
hxxp://epichi[.]us
hxxp://vpnsvr[.]top
hxxp://verification-amazon-fr[.]fr
hxxp://laurencecouture[.]fr
hxxp://it-serve[.]pro
hxxp://thefeelgoodhood[.]com
hxxp://bookrichandsassy[.]com
hxxp://pio-no-no[.]com
hxxp://apt4[.]kr
hxxp://minjs[.]us
hxxp://demandredesign[.]org
hxxp://riches-elenas[.]kz
hxxp://test-ryhall-dns-is-us-test-gmail[.]com
hxxp://try-no-no[.]com
hxxp://eliteautoloans[.]ca
hxxp://akixi-test-gmail[.]com
hxxp://get-no-no[.]com
hxxp://fatemzassl[.]com[.]ng
hxxp://aryamatbaa[.]com
hxxp://official-no-no[.]com
hxxp://thizastore[.]com[.]br
hxxp://everydayweplay365new[.]com
hxxp://curiousq[.]info
hxxp://hgarbaglobalventures[.]com[.]ng
hxxp://dafdfeafeae[.]com
hxxp://facebooksexlist[.]com
hxxp://attavitacons[.]com
hxxp://test-bh-staging-domain28082021025944[.]com
hxxp://politics-is-a[.]science
hxxp://alexcohen[.]us
hxxp://esv[.]jp
hxxp://wagnitzsoftware[.]com
hxxp://cdcysj[.]cn
hxxp://demonslayerswords[.]net
hxxp://wolftecno[.]com
hxxp://epic-hi[.]us
hxxp://outletku[.]com
hxxp://serialmail[.]net
hxxp://oh-no-no[.]com
hxxp://cysj1[.]cn
hxxp://skjdnsn[.]com
hxxp://sallybestor[.]com
hxxp://hotelfortkolesnik[.]com
hxxp://birdy[.]com[.]tw
hxxp://ebiz[.]co[.]il
hxxp://youngfaith[.]us
hxxp://vitejambe[.]com
hxxp://kittybox[.]us
hxxp://artech-a[.]fr
hxxp://jrspipesandtubes[.]com
hxxp://herbsandnature[.]us
hxxp://tlftest[.]us
hxxp://laboratorioedn[.]com
hxxp://subprimary[.]com
hxxp://cyrusmedia[.]ca
hxxp://trogdor-test-teststs-devee[.]com
hxxp://leenuts[.]com
hxxp://gmo-test-2022-05-05-ishitoya01[.]com
hxxp://dd9[.]co[.]kr
hxxp://smsvg[.]com
hxxp://s-proj[.]co[.]il
hxxp://spartanguild[.]com
hxxp://becysj[.]cn
hxxp://test-bh-staging-domain06092021131217[.]com
hxxp://tjcysj[.]cn
hxxp://thanushcreations[.]com
hxxp://cartevitale-am[.]fr
hxxp://piephomedia[.]com
hxxp://theinquiryhub[.]com
hxxp://smsnh[.]com
hxxp://yuanayu[.]com
hxxp://plusswagath[.]com
hxxp://asukaindonesia[.]com
hxxp://smsrb[.]com
hxxp://maacademia[.]com
hxxp://topfactsglobal[.]com
hxxp://prakrie[.]com
hxxp://i-socialapp[.]com
hxxp://luzxd[.]us
hxxp://findmyiphone-view[.]com
hxxp://ipklll[.]us
hxxp://ip-pbx[.]su
hxxp://terminodador[.]com
hxxp://test1122[.]net
hxxp://manurnu[.]com
hxxp://testingdomainwsuite12345[.]net
hxxp://jorcustoms[.]com
hxxp://testingdomainwsuite123456[.]net
hxxp://0br[.]us
hxxp://yandex-toloka[.]ru[.]com
hxxp://dollpls[.]com
hxxp://weeblycombo2[.]com
hxxp://whcysj[.]cn
hxxp://weeblycombotesting1[.]com
hxxp://programadorweb[.]net
hxxp://aaravidevelopers[.]com
hxxp://44518[.]cn
hxxp://inviz[.]host
hxxp://kz123[.]cn
hxxp://collectifpolar[.]fr
hxxp://naromedia[.]space
hxxp://secandosemparar[.]com
hxxp://steemdice[.]online
hxxp://uvlfastmarket[.]com
hxxp://trackblogexperthealth[.]space
hxxp://changyouworld[.]cn
hxxp://weeblycombo[.]com
hxxp://lovepets[.]fr
hxxp://gombong[.]asia
hxxp://lei-nuo[.]com[.]cn
hxxp://runhr[.]us
hxxp://kaya-bunga[.]com
hxxp://dimensionengiservices[.]com
hxxp://thomashcliu[.]com
hxxp://ttglobaladvisory[.]net
hxxp://0xe[.]us
hxxp://underarmourstore[.]us
hxxp://friendsland[.]pp[.]ua
hxxp://eoczy[.]host
hxxp://qualiteletrica[.]com[.]br
hxxp://heskes[.]info
hxxp://quemseduzconquista[.]com
hxxp://nitix[.]biz
hxxp://starhelectricalservicesllc[.]com
hxxp://2xlipat[.]com
hxxp://mugyuphotoworks[.]com
hxxp://exroot[.]us
hxxp://promicom[.]ma
hxxp://ibracket[.]net
hxxp://compteabonnement[.]fr
hxxp://gotowka-doreki[.]info
hxxp://pamyu-pamyu[.]com
hxxp://ismarcoscastro[.]com
hxxp://a-gmail[.]com
hxxp://doremi-hochouki[.]com
hxxp://hahapetshop[.]com
hxxp://joshuahatten[.]com
hxxp://reza-najafi[.]com
hxxp://lloyds-area[.]com
hxxp://fibvo[.]com
hxxp://codenific[.]com
hxxp://linhtinhcenter[.]com
hxxp://zo1984[.]com
hxxp://lifevantagethai-nrf2[.]com
hxxp://greenenershop[.]com
hxxp://gaytravelcrowd[.]com
hxxp://aythotellock[.]com
hxxp://doooectb[.]com
hxxp://gratiasmarthome[.]com
hxxp://myrenttoownhomes[.]us
hxxp://voxchronicle[.]com
hxxp://cloudtest[.]asia
hxxp://teedin789[.]org
hxxp://car789[.]org
hxxp://alarmmoney[.]info
hxxp://cctvnon[.]com
hxxp://ouvoleravecmondrone[.]com
hxxp://vtechwriter[.]com
hxxp://greenmage321[.]com
hxxp://avtoremont36[.]xyz
hxxp://carav[.]us
hxxp://flowerwseb[.]info
hxxp://cjford[.]org
hxxp://ouvoleravecmondrone[.]net
hxxp://suns-vip[.]com
hxxp://mindyshousecleaners[.]com
hxxp://gaytravelcrowd[.]biz
hxxp://healthlantern[.]us
hxxp://greens333[.]com
hxxp://vacation-crowd[.]com
hxxp://blockpays[.]info
hxxp://rem971verslesucces[.]com
hxxp://nsr-sys[.]com
hxxp://aminpour[.]info
hxxp://ba2b[.]xyz
hxxp://nwtgck[.]xyz
hxxp://classhelper[.]us
hxxp://dustbinservices[.]com
hxxp://checkiclouds[.]info
hxxp://lclsecuret[.]com
hxxp://toretto[.]host
hxxp://antoinetbt[.]host
hxxp://ecomyparty[.]com
hxxp://vil-diesel[.]host
hxxp://ontime-a[.]com
hxxp://canlammotteam[.]host
hxxp://dominic-toretto[.]host
hxxp://semailaanhem[.]host
hxxp://badromance[.]host
hxxp://cd-storage-reviews[.]com
hxxp://antoinegriezmann[.]host
hxxp://seeyouagain[.]host
hxxp://mrtbt[.]host
hxxp://line-dn[.]com
hxxp://eklink[.]org
hxxp://emlakhaberleri[.]org
hxxp://eklink[.]info
hxxp://legendturk[.]biz
hxxp://secured-logins[.]online
hxxp://64bitcongnghe[.]com
hxxp://pocket0077[.]com
hxxp://dallaporte[.]com
hxxp://etchmall[.]com
hxxp://accounts-my-mail-gmail[.]com
hxxp://account-mail-gmail[.]com
hxxp://accounts-mail-gmail[.]com
hxxp://art-photo-story[.]com
hxxp://azarter[.]com
hxxp://youractiontoys[.]com
hxxp://sil21[.]com
hxxp://indicatorchoice[.]com
hxxp://myaccount-mail-gmail[.]com
hxxp://teamkill[.]pro
hxxp://mdhanastha[.]com
hxxp://smpplugin[.]com
hxxp://smp-plugin[.]com
hxxp://todaymagazine[.]xyz
hxxp://thecouponparty[.]com
hxxp://todayradio[.]xyz
hxxp://serva4ok[.]pro
hxxp://forteam[.]pro
hxxp://facebuilder[.]xyz
hxxp://irandirectory[.]xyz
hxxp://mixandmastering[.]xyz
hxxp://nameforbaby[.]xyz
hxxp://justpayforshipping[.]biz
hxxp://justpayforshipping[.]org
hxxp://justpayforshipping[.]info
hxxp://lambdaf[.]info
hxxp://herdiesel-santoso[.]com
hxxp://keywordriches[.]org
hxxp://energybodyart[.]com
hxxp://floresemangola[.]com
hxxp://sonyatour[.]com
hxxp://doktorhatasi[.]biz
hxxp://probono123[.]org
hxxp://personalitynetwork[.]org
hxxp://gold4money[.]us
hxxp://odt[.]moscow
hxxp://okget[.]xyz
hxxp://mixedfire[.]com
hxxp://batikidalestari[.]com
hxxp://frugalandresponsibleliving[.]com
hxxp://makrandownload[.]com
hxxp://yfilatov[.]xyz
hxxp://artbodyart[.]com
hxxp://meme-generator[.]info
hxxp://delhitransport[.]info
hxxp://trisnoidamanbatik[.]com
hxxp://modadhanasta[.]com
hxxp://okemoviezone[.]com
hxxp://gowanusindustrial[.]org
hxxp://ydafmc[.]com
hxxp://books-mania[.]com
hxxp://buettner[.]science
hxxp://vdeserve[.]com
hxxp://k-u-n-s-t-s-t-o-f-f[.]com
hxxp://f-f[.]com
hxxp://f-l-u-f-f[.]com
hxxp://a-f-f[.]com
hxxp://t-a-f-f[.]com
hxxp://b-f-f[.]com
hxxp://k-f-f[.]com
hxxp://f-f-f[.]com
hxxp://m-f-f[.]com
hxxp://g-f-f[.]com
hxxp://p-u-f-f[.]com
hxxp://s-t-a-f-f[.]com
hxxp://okrok[.]info
hxxp://d-i-f-f[.]com
hxxp://roukio[.]info
hxxp://t-f-f[.]com
hxxp://teotio[.]info
hxxp://s-u-n-o-f-f[.]com
hxxp://s-t-i-f-f[.]com
hxxp://okrok[.]org
hxxp://w-f-f[.]com
hxxp://teotio[.]org
hxxp://h-f-f[.]com
hxxp://pokere[.]org
hxxp://v-f-f[.]com
hxxp://roukio[.]org
hxxp://f-a-c-e-o-f-f[.]com
hxxp://s-u-f-f[.]com
hxxp://take-o-f-f[.]com
hxxp://u-s-f-f[.]com
hxxp://qeou[.]online
hxxp://u-f-f[.]com
hxxp://karatsu-f-f[.]com
hxxp://j-f-f[.]com
hxxp://l-f-f[.]com
hxxp://o-f-f[.]com
hxxp://f--f[.]com
hxxp://e-f-f[.]com
hxxp://gardener-f-f[.]com
hxxp://i-f-f[.]com
hxxp://p-j-f-f[.]com
hxxp://y-f-f[.]com
hxxp://s-f-f[.]com
hxxp://c-f-f[.]com
hxxp://boulangerie-dupont-f-f[.]com
hxxp://s-t-f-f[.]com
hxxp://n-u-f-f[.]com
hxxp://ca-f-f[.]com
hxxp://sts-rci-rogers[.]ca
hxxp://p-f-f[.]com
hxxp://scholarlysources[.]com
hxxp://f-f-f-f[.]com
hxxp://globalrealez[.]com
hxxp://df-we-4234-f-we-fw-4234-f-we-f-f[.]com
hxxp://iconarise[.]com
hxxp://hamad-f-f[.]com
hxxp://toplifedailylive[.]com
hxxp://n-f-f[.]com
hxxp://s-o-f-f[.]com
hxxp://p-i-s-s-o-f-f[.]com
hxxp://c-u-f-f[.]com
hxxp://d-f-f[.]com
hxxp://z-f-f[.]com
hxxp://r-i-f-f[.]com
hxxp://r-f-f[.]com
hxxp://innovationoffice[.]org
hxxp://mindsxchange[.]com
hxxp://marketresearchcolloquium[.]com
hxxp://danielles-f-f-f[.]com
hxxp://x-f-f[.]com
hxxp://q-f-f[.]com
hxxp://platformxchange[.]com
hxxp://d-i-l-l-i-g-a-f-f[.]com
hxxp://c-i-f-f[.]com
hxxp://k-y-f-f[.]com
hxxp://kairosteknoloji[.]download
hxxp://enesaldemir[.]net
hxxp://tenadesign[.]net
hxxp://shyfzorg[.]com
hxxp://disdikbud-papua[.]org
hxxp://al-azharaslichmughny[.]org
Continue reading →Sample description of the service:
"Samourai Wallet is the most feature rich and advanced bitcoin wallet available on Android today. It has been created from the ground up by privacy activists to be extremely portable, highly secure, and lead the pack in protecting the privacy of bitcoin users.
- Full Segwit Support for the most efficient transactions and lowest miner fees
- You control your private keys on your device, they are never communicated with any server
- Best in class dynamic miner fee estimation and custom fee settings
- STONEWALL for increasing the privacy of your transactions
- Ricochet spend for mitigation against address clustering attacks
- Send and receive Stealth Payments directly into your wallet with PayNym (BIP47)
- Deterministic sorting of input/outputs to prevent the wallet from leaving a discernible block chain fingerprint (BIP69)
- Bump a stuck transaction with full Replace By Fee (RBF) and Child Pays for Parent (CPFP) support
- Route outgoing transactions via your own trusted node
- No addresses are reused to help manage metadata leakage
- Standard import/export functionality. Compatible with any other BIP44/BIP49/BIP84 wallet.
- Stealth mode hides the wallet on the device. Dial a secret code to access your wallet.
- Enable remote SMS commands to regain access to your funds if you lose your phone
- Block Explorer support for all popular services
- Passphrase protection by default (BIP39)
- Fully encrypted client side and offline
- Connect via your preferred VPN
- Connect via Tor (Socks5 proxy)"
Primary domains involved in the campaign include:
hxxp://samourai.io
hxxp://samouraiwallet.com
hxxp://samourai.support
Sample responding IPs:
68[.]65[.]123[.]241
198[.]27[.]104[.]163
37[.]143[.]131[.]158
162[.]255[.]119[.]8
82[.]221[.]130[.]110
37[.]143[.]131[.]230
52[.]203[.]48[.]25
162[.]255[.]119[.]42
136[.]243[.]224[.]53
193[.]29[.]187[.]225
82[.]221[.]131[.]139
82[.]221[.]139[.]204
172[.]67[.]194[.]72
206[.]253[.]90[.]229
104[.]21[.]68[.]107
193[.]29[.]187[.]21
Sample responding IPs:
68[.]65[.]123[.]241
198[.]27[.]104[.]163
37[.]143[.]131[.]158
162[.]255[.]119[.]8
82[.]221[.]130[.]110
37[.]143[.]131[.]230
52[.]203[.]48[.]25
162[.]255[.]119[.]42
136[.]243[.]224[.]53
193[.]29[.]187[.]225
82[.]221[.]131[.]139
82[.]221[.]139[.]204
172[.]67[.]194[.]72
206[.]253[.]90[.]229
104[.]21[.]68[.]107
193[.]29[.]187[.]21
Related responding IPs:37[.]143[.]131[.]158
160[.]19[.]51[.]112
82[.]221[.]131[.]27
185[.]165[.]170[.]172
99[.]83[.]154[.]118
185[.]165[.]170[.]173
82[.]221[.]131[.]139
188[.]214[.]30[.]147
192[.]95[.]12[.]14
162[.]255[.]119[.]161
37[.]143[.]131[.]195
185[.]165[.]170[.]143
Related domains known to have been involved in the campaign include:
hxxp://oxtresearch.com
hxxp://nextblock.is
hxxp://samourai.email
Sample social media accounts:
hxxp://twitter.com/SamouraiWallet
Android application URL:
hxxp://play.google.com/store/apps/details?id=com.samourai.wallet&hl=en_US
hxxp://www.youtube.com/c/Samouraiwallet
hxxp://www.facebook.com/samouraiwallet
hxxp://github.com/Samourai-Wallet
The group behind the cryptocurrency mixing service also maintains several other domains:
hxxp://paynym.is - 193.29.187.225; 192.95.12.14; 188.214.30.147
hxxp://oxt.me
hxxp://sovereign.ly
hxxp://mule.tools
Sample known responding IPs:
13[.]56[.]33[.]8
54[.]243[.]255[.]92
54[.]225[.]158[.]198
50[.]19[.]120[.]203
199[.]73[.]55[.]35
188[.]114[.]96[.]6
23[.]217[.]138[.]108
188[.]114[.]97[.]3
198[.]54[.]117[.]218
188[.]114[.]96[.]0
198[.]54[.]117[.]217
104[.]21[.]65[.]40
192[.]64[.]119[.]152
188[.]114[.]97[.]29
23[.]202[.]231[.]167
I'll continue monitoring the campaign and will post updates as soon as new developments take place.
Continue reading →Dear blog readers,
In this analysis I'll discuss and provide actionable intelligence on Wassim Gerges Dahdan’s Advanced Web Tech’s (AWT) Al-Manar Hosting Provider.
Name: Khalil Abbas
Company: Advanced Web Tech
Site URL: hxxp://awt.com.lb
Email: webmaster[.]awt.com.lb
Phone: 009613481199
Current domain registrations:
hxxp://lcg-lb.com
Related domain registrations:
hxxp://almanartv.news
hxxp://fastpublish.net
hxxp://app-news.org
hxxp://manar.news
hxxp://manartv.news
hxxp://lcg-lb.com
hxxp://awt-lb.com
hxxp://awt-lb.org
hxxp://awt-lb.net
hxxp://dar-almanar.org
hxxp://almanar-tv.net
hxxp://dar-almanar.net
hxxp://dar-almanar.com
Related domain registrations:
hxxp://almanartv.news
hxxp://fastpublish.net
hxxp://app-news.org
hxxp://manar.news
hxxp://manartv.news
hxxp://lcg-lb.com
hxxp://awt-lb.com
hxxp://awt-lb.org
hxxp://awt-lb.net
hxxp://dar-almanar.org
hxxp://almanar-tv.net
hxxp://dar-almanar.net
hxxp://dar-almanar.com
Related Advanced Web Tech domain registrations:
hxxp://itweetpe.com
hxxp://itweetpe.org
hxxp://theswaonline.com
hxxp://sbbarista.com
hxxp://sendateacherca.com
hxxp://fastpublish.net
hxxp://phikappapsidepaul.com
hxxp://outertides.com
hxxp://sendateacher.com
hxxp://supportbaa.com
hxxp://app-news.org
hxxp://my-tgraphics.com
hxxp://lcg-lb.com
hxxp://awt-lb.com
hxxp://awt-lb.org
hxxp://awt-lb.net
hxxp://dar-almanar.net
hxxp://dar-almanar.com
hxxp://advancedleases.com
hxxp://wsidigitalinternet.com
hxxp://wsisimpledigitalweb.com
hxxp://dar-almanar.org
Continue reading →
In this analysis I'll take an in-depth look inside the MOLERaTS cyber threat actor in terms of actionable intelligence and the gang's online and Internet-connected infrastructure.
Related URLs:
hxxp://bitly[.]com/1YRoIPX
hxxp://mafy[.]2waky[.]com
Related known responding IPs:
192[.]52[.]167[.]118
204[.]152[.]203[.]99
192[.]161[.]48[.]59
192[.]52[.]167[.]118
185[.]82[.]202[.]207
173[.]254[.]236[.]130
168[.]235[.]86[.]156
167[.]160[.]36[.]101
107[.]191[.]47[.]42
84[.]200[.]68[.]163
72[.]11[.]148[.]147
23[.]229[.]3[.]70
84[.]200[.]68[.]163
23[.]229[.]3[.]70
204[.]152[.]203[.]99
192[.]52[.]167[.]118
168[.]235[.]86[.]156
167[.]160[.]36[.]101
Related primary group's URLs:
hxxp://gaza-hacker[.]com
hxxp://hacker[.]ps
hxxp://gaza-hacker[.]net
hxxp://gaza-hack[.]org
hxxp://gaza-hack[.]info
hxxp://xhackerx[.]com
hxxp://gaza-hack[.]com
hxxp://gaza-Hackers[.]com
Personally identifiable email address account:
moayy2ad[.]hotmail.com
Related MD5s:
b1071ab4c3ef255c6ec95628744cfd3d
77d6e2068bb3367b1a46472b56063f10
Related C&Cs:
hxxp://mrayesh[.]blogspot[.]com
hxxp://education-support[.]space
hxxp://falcondefender[.]com
hxxp://support-update[.]ml
hxxp://such[.]market
Related known responding IPs:
84[.]200[.]68[.]163
23[.]229[.]3[.]70
204[.]152[.]203[.]99
192[.]52[.]167[.]118
168[.]235[.]86[.]156
167[.]160[.]36[.]101
Related MD5s:
59bab785127418972dda9da5571b73fd
07dae7dada9ec3fa22507dfa5921c993
4bd6a959cce13d1f5b5511a428e88c9c
2ba0e52b885cabfbcd88866ab4072f54
1d922e183418ac087933c526f7bd06c1
3ce39f8afce9463c6d90c00ce72edb86
77fd78042407a7318dba388da00700cc
Related C&C URLs:
hxxp://smail.otzo[.]com/W/Gfsdfsdfsrydkfpsdmfpsadsdfsdfsdfsdfdfsp.php
hxxp://smail.otzo[.]com/y/analysis--hezbollah.rar
hxxp://drive.google[.]com/uc?export=download&id=0B7XzN8DNbJKiQlFNRHdVTmpCd0U
hxxp://drive.google[.]com/uc?export=download&id=0BxaUrWGCqlWLMTQzMVFNOENIUFk
hxxp://drive.google[.]com/uc?export=download&id=0B7n4BFDObRocdm1uS2J4SWVUNWc
hxxp://drive.google[.]com/uc?export=download&id=0ByjYVMTYJB0saHlTalJ6ZWlWWGM
hxxp://support.mafy-koren[.]online/reg-update
hxxp://support.mafy-koren[.]online/UFeed.php
hxxp://may2008[.]dyndns[.]info
hxxp://menu[.]dyndns[.]biz
hxxp://flashsoft[.]no-ip[.]biz
hxxp://monagameel[.]chickenkiller[.]com
hxxp://hatamaya[.]chickenkiller[.]com
hxxp://powerhost[.]zapto[.]org
hxxp://helpme[.]no-ip[.]biz
hxxp://mjed10[.]no-ip[.]info
hxxp://good[.]zapto[.]org
hxxp://hint[.]zapto[.]org
hxxp://hint1[.]zapto[.]org
hxxp://natco1[.]no-ip[.]net
hxxp://natco2[.]no-ip[.]net
hxxp://natco3[.]no-ip[.]net
hxxp://natco4[.]no-ip[.]net
hxxp://loading[.]myftp[.]org
hxxp://skype[.]servemp3[.]com
hxxp://test[.]cable-modem[.]org
hxxp://idf[.]blogsite[.]org
hxxp://javaupdate[.]no-ip[.]info
hxxp://lokia[.]mine[.]nu
hxxp://hint-sms[.]com
hxxp://owner[.]no-ip[.]biz
hxxp://remoteback[.]no-ip[.]biz
hxxp://ramadi[.]no-ip[.]biz
Related MD5s:
A5DE87646EE943CD1F448A67FDBE2817
F982401E46864F640BCAEDC200319109
EC5B360F5FF6251A08A14A2E95C4CAA4
97576FA7A236679DBE3ABE1A4E852026
C1EC435E97A4A4C5585392D738B5879F
2559FE4EB88561138CE292DF5D0E099F
0ABF3FA976372CBC8BF33162795E42A8
1f1e9958440d773c34415d9eb6334b25
0B3B1E2E22C548D8F53C2AA338ABD66E
0AA7B256D2DCC8BD3914F895B134B225
B455426811B82CB412952F63D911D2A8
E431634699D7E5025ECDF7B51A800620
FF8E19CA8A224CC843BF0F2F74A3274E
7C5272F3F24ACB225270DDED72CFC1D4
8AEAA0C81A36449EC9613CA846E196F2
FC17F3B2E2C7F5F24D35899D95B8C4A6
926235FCF7B91442A405B5760A0729EB
963BFAE19B3DA5BECE081DFF1D1E3EF9
EBC9BDF9FDF0A9773899D96D24AC46F4
4A06D9989A8C3A9967C2011E5BAF3010
4DC0BCDCFB3F3D794175B21872A76079
998F30457BC48A1A6567203E0EC3282E
91FC9D1B635FDEE4E56AEC32688A0E6C
940B3ACDF1E26FCCCF74A5A0359FB079
cebc8b51d51e442e2af8c86e70c8adf4
31F96ADD841594D35E6E97376114E756
6E416C45A833F959A63785892042595A
0DC102CFB87C937EEFFE01A06F94E229
B7DF947B4A67A884C751840F83C4405E
2EB1503751A7C74890096B1837C7BD81
C21D7165B25CAF65D7F92FF758C1B5B1
0A67F9CC30083AFB7E1F8295AE152BB6
15FC009D9CAAA8F11D6C3DA2B69EA06E
D9D1B0C467FA4999DEF6CD53447F1221
E9823B61E6CE999387DE821DFBF6E741
2AAD951DBECB6D4715B306B337CA5C34
ED53831468DDF4220E1DC3C3398F7F39
66DDF27517985A75B2317231B46A6F62
86BE5F0D2303FB4A8A8E297A53AC0026
A1187DE4C4B88E560D46940B820A6228
D14E0A3D408065B1551F2827B50B83CA
B6C8A6D6C35428779C5C65C1B273EBA0
841565C67006E6A0A450C48054CF348C
C8202523F35295E8BC8CC1731EDB0559
C03B5985F2504939DA9874246A439E25
216689B2CA82F16A0CAB3A2712C27DA6
5B740B4623B2D1049C0036A6AAE684B0
9C39D6F52E1E1BE5AE61BAB90971D054
E7E05001A294EBFE8A012DD3BCE78E96
F68F85B0FBCA450F0D5C8828063AD30D
3DA8C22F5340850EE5A2C25B1D17FC27
9D144A828F757A90B86976EF0C906B3F
DBE2AC744A3947B6306E13EBCCB718BF
861C90536B3B5A4A8309ADBBFD5C4713
947557A55267DFFB3F85E0D7496A3679
2BFE41D7FDB6F4C1E38DB4A5C3EB1211
2BCDC5091C446E8B6888D802A3589E09
72FD6074915F8F123EB44B3DD475D36B
41454B390B73A45004B916B96C693312
Continue reading →hxxp://circles.bz - support@circles.bz
Nadezhda Ropleva -> hxxp://lighthousesystem.net
52.29.174.30 -> ec2-52-29-174-30.eu-central-1.compute.amazonaws.com -> hxxp://vulcan-club-online.com52.59.17.122
52.57.237.76
52.59.25.179
52.59.84.176
52.58.213.184
97.74.215.85
50.87.144.136
46.107.239.88
118.169.224.5
hxxp://tracksystem.info87.121.58.6
46.107.239.141
87.121.58.4
46.107.239.89
46.107.239.12
hxxp://nac-2013.us - Email: dimitar.markov@circles.bz
hxxp://globalhubcom.com - Email: YyhplaFwhvhlp@hotmail.com - Email: nadia.ropleva@circles.bz
46.107.239.88 -> hxxp://worldsupport.info
AS60097
hxxp://vulcan-club-online.com -> hxxp://vlk-casino-club.com
Social media accounts:
hxxp://www.facebook.com/nadia.ropleva
hxxp://www.slideshare.net/nadiaropleva
Sample screenshots:
Related sample screenshots:
Stay tuned.



























.png)
.png)

RSS Feed