Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update add-domain habitatbroward.org #269

Closed
wants to merge 1 commit into from

Conversation

WebworkrNet
Copy link
Contributor

Domain/URL/IP(s) where you have found the Phishing:

Email spam

Impersonated domain

Probably kaufland.de (German supermarket) - I did not call any of the links for security reasons.

Related external source

https://www.virustotal.com/gui/url/f04c0c760ae219a0a06df084988615ffc907e542985da9ae07ec665d19ca72c7?nocache=1

Describe the issue

https://habitatbroward.org/imaglinks/redirect22.html

Subject
🧺🧺Holen Sie sich IHR kostenloses iPhone 15 Pro#94599🧺🧺

Body

[Anlässlich des Kaufland-Jubiläums erhalten Sie das](https://habitatbroward.org/imaglinks/redirect22.html)


[iPhone 15 Pro](https://habitatbroward.org/imaglinks/redirect22.html)[ #311696](https://habitatbroward.org/imaglinks/redirect22.html)







[[t-online]](https://dl.asnapieu.com/binary/public/IMvSoQVITKCaCmEUJTnfgQ/b977fe6e-d3bc-46df-8156-9ec99e2edf4a)


[[Bild-Link]](https://habitatbroward.org/imaglinks/Kaufland%2015-%20.png)



[[t-online]](https://dl.asnapieu.com/binary/public/IMvSoQVITKCaCmEUJTnfgQ/b977fe6e-d3bc-46df-8156-9ec99e2edf4a)





























=============== ===============758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ
758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ
758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ
758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ
758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ
758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ
758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ
758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ
758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ
758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ
758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ
758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ
758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ
758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ
758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ

 

<ApplEt> <p><span style="color: #ECECEC; background-color: #F2F2F2;"><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong></span></p> <p> </p> <oBjeCt> <TitLe> <ApplEt> <p><span style="color: #ECECEC; background-color: #F2F2F2;"><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong><br /><strong>758SijH2fX24IokXWJyHCmF2lOX4GhW8NkI MRhMJ</strong></span></p> <p> </p>

Screenshot

Click to expand

Screenshot_20230915_142002_Firefox Nightly

@spirillen spirillen added the ReBase This Merge request need to be rebased from master label Oct 15, 2023
@spirillen
Copy link
Collaborator

@WebworkrNet

A couple of tricks or tools to work with these dubious things is curl, drill, lynx, pyfunceble and virtual machines. I do know @iam-py-test have the knowledge for an online service you can use, he might be better to write a simple guide for how to do this.

Maybe he will post to matrix.rocks or a gist here on GH


https://habitatbroward.org/imaglinks/redirect22.html redirects to REFRESH(0 sec): https://directorystir.com/0/0/0/2f188ddceac09a6e15293303495552c6/1234567 (lynx)

The target url is dead

image

image
image
image
image
image

However the domain it self seems dubious, so I agree to add it as phishing by domain, but your are missing a couple of involved phishing domains to this MR

asnapieu.com
directorystir.com

Please @rebase

@iam-py-test
Copy link

habitatbroward.org

Seems (superficially) to be the legitimate Habitat For Humanity of Broward website. Maybe they were hacked (or I'm wrong about them being legitimate).
Thanks

@spirillen
Copy link
Collaborator

habitatbroward.org

Seems (superficially) to be the legitimate Habitat For Humanity of Broward website. Maybe they were hacked (or I'm wrong about them being legitimate). Thanks

If you take a peak at the first screendump vs the last one with only to lines of text and a "newsletter" sing up, there are something that seems to match, when you see the site through lynx.

Could you share a alternative dump please

@iam-py-test
Copy link

I don't have a screenshot, I just looked them up.
Thanks

@WebworkrNet
Copy link
Contributor Author

@spirillen It's not entirely clear to me what you want from me.
Should I open a new pull request with the two missing domains?

@spirillen
Copy link
Collaborator

Should I open a new pull request with the two missing domains?

From a lazy hand... yes, that is faster and quicker than rebasing 😏

@spirillen
Copy link
Collaborator

Closed for inactivity

@spirillen spirillen closed this Dec 7, 2023
@spirillen spirillen added the wontfix This will not be worked on label Dec 7, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ReBase This Merge request need to be rebased from master todo 🗒️ wontfix This will not be worked on
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants