Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add to azezieldraconous[.]com to wildcard-domain list #381

Conversation

g0d33p3rsec
Copy link
Contributor

@g0d33p3rsec g0d33p3rsec commented Apr 22, 2024

Phishing Domain/URL/IP(s):

https://azezieldraconous.com/Mk82RTVaMjg0djE4MVo=
https://azezieldraconous.com/M1czaTBQNmQzUTZnOVM=
https://azezieldraconous.com/M3QzVjBVN1E0YzNSMDQ=
https://azezieldraconous.com/MzYydTVWOGY5WDZTNVo=
https://azezieldraconous.com/M1UydTRlNEMwbzQ4OHA=
https://azezieldraconous.com/M1EyRzZxMVk0aTFnMGY=
https://azezieldraconous.com/M1QxWjVZN3E3aDVKOEo=
https://azezieldraconous.com/M2EzZzA0OFUwRzFTMTU=
https://azezieldraconous.com/M2cyZTZvOGQydjBIOXk=
https://azezieldraconous.com/MzYyNzZMNTM5NzI1N0E=
https://azezieldraconous.com/M3IzWjBtN0MxeDFXM0E=
https://azezieldraconous.com/M1QyTTlkOWczODRyOFg=
https://azezieldraconous.com/M2YyYTVPOU85WTdvNjc=
https://azezieldraconous.com/M20zZTBuN1c4RjhuNGE=
https://azezieldraconous.com/M3oyMTRSNXk3YzFJOXE=
https://azezieldraconous.com/MzgyMjZsN1U2MjR3Nm8=
https://azezieldraconous.com/M3EyeTZGNXQ5YjJONzk=
https://azezieldraconous.com/M2IzNDBQN0gwdTgwOU4=
https://azezieldraconous.com/Mm44MzNsMnI5ajcwODI=
https://azezieldraconous.com/M08xVzlZMmY4ZzJwN0o=
https://azezieldraconous.com/M2YyejViOE85ODVQM1c=
https://azezieldraconous.com/MlY0MzZpN2MyaDgwM3Q=
https://azezieldraconous.com/M3czTTBON3gzZTEwM28=
https://azezieldraconous.com/MzgyUjdUNmk4YjNjOFc=

Impersonated domain

https://facebook.com/
https://www.betway.co.za
https://www.tut.ac.za/
https://www.ufs.ac.za/
https://www.uwc.ac.za/
https://www.wits.ac.za/
https://www.wsu.ac.za/

Describe the issue

This domain is now serving the phishing kit that was previously at westernautomobileassembly[.]com (#376) , littleswanaircon[.]com[.]sg (#372), iwan2travel[.]com(#370 ), applesforfred[.]com (#369), theaerie[.]ca (#367), nico[.]sa (#366), and ajstelecom[.]com[.]mx (#362)

Related external source

Screenshot

Click to expand

image
image
image
image
image
image
image
image
image
image
image
image
image
image
image
image
image
image
image
image
image

@spirillen spirillen merged commit 7f3fa76 into mitchellkrogza:main Apr 22, 2024
@spirillen
Copy link
Collaborator

Thanks again for your commit 🥇

@g0d33p3rsec
Copy link
Contributor Author

Thanks again for your commit 🥇

A pleasure, as always.

@g0d33p3rsec
Copy link
Contributor Author

g0d33p3rsec commented May 19, 2024

@spirillen just a heads up, it looks like this domain is active again. This is the first time I've seen a domain reused.

https://azezieldraconous.com/M2syaDY5MEQyZzFKOTA=
https://azezieldraconous.com/M1YyVTZDOGsyYjA1OU4=
https://azezieldraconous.com/M3AyMDVJOG85bzVsM3I=
https://azezieldraconous.com/MzIyNTVHOUEzaTIzOW8=
https://azezieldraconous.com/M3kyMjVDOG83eTFzNXc=
https://azezieldraconous.com/M1UzQzAxOE04WTl0MGk=
https://azezieldraconous.com/M20zdzB1ODYxYTVGMUI=
https://azezieldraconous.com/M1EzVTRMNkU0RjVYM1k=
https://azezieldraconous.com/M0kzdDRqNWg5cjdCN2U=
https://azezieldraconous.com/MzYxSTc5N0ozeTlaMzM=
https://azezieldraconous.com/MzMzNTBHODMwMTJyMFY=
https://azezieldraconous.com/M3AxejZRNlE1azNLOE8=
Click to expand

image
image
image
image
image
image
image
image
screenshot
image

@g0d33p3rsec
Copy link
Contributor Author

g0d33p3rsec commented May 20, 2024

@spirillen unless I'm missing something, I'm unable to find any record of this domain in the upstream repo. Seeing as this is the first instance where the actor has reused a previous domain, it is causing me more concern than the previous omissions. Should one of us be considering filing an issue upstream?

cc @mitchellkrogza - do you have any suggestions that I could help with?

@spirillen
Copy link
Collaborator

spirillen commented May 21, 2024

I'm unable to find any record of this domain in the upstream repo

Your right... seems to be related to #395, I'm the only project who have this record active...


You can always use this repo to do search on external projects https://github.com/external-sources/hosts-sources?tab=readme-ov-file#external-sources including this one and the upstream

PS: If you know any other that should be included, please just make a PR 😄


@mitchellkrogza + @funilrys , seem the workflow for phishing.database is broken...

GitHub
Script to keep lists of external hosts sources up to date in a raw domain.tld format for easier manipulating date from external sources to search through for known records - external-sources/hosts-...

@g0d33p3rsec
Copy link
Contributor Author

If you know any other that should be included, please just make a PR

I found a second instance of a previous domain being reused without protection and added it to the issue reported in #395. Similar to the previously mentioned domain, this one is also still visible in your list but not in the Phishing Database. If the entries are failing to make their way upstream, what should I change for making a PR? The domains are visible in this repo so I'm failing to see what good a second PR would do, though I'm likely misunderstanding something.

@spirillen
Copy link
Collaborator

what should I change for making a PR?

The simple answer, is nothing, your commits are 100% perfect. The issue isn't in this repo, it lies with phishing.database, hence @mitchellkrogza or @funilrys have to look into it, as I do not have the keys to that door.

spirillen added a commit to external-sources/hosts-sources that referenced this pull request Jul 2, 2024
Do to a bug in Phishing.Database we are not able to do full search in the active files. For that reason we are now importing the `ALL-phishing-links.txt` and strips it down to domain only list in `data/phishing_database/`

Related issues:
- mitchellkrogza/Phishing.Database#840
- mitchellkrogza/Phishing.Database#881
- mitchellkrogza/phishing#381 (comment)
- mitchellkrogza/phishing#396
- mitchellkrogza/phishing#407
- mitchellkrogza/phishing#395
- mypdns/matrix#624
- blocklistproject/Lists#1252
- mitchellkrogza/Phishing.Database#840
- mitchellkrogza/Phishing.Database#722

Trying to use @main for the php installer and using php version 8.4

Added `libdomain-publicsuffix-perl` to the dependencies.sh script as it is required by perl in import.sh. It turns out Perl just anoyingly does it again... 😏
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants