Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

free.fr phishing group: badware #22765

Closed
10 of 11 tasks
orbotimn75 opened this issue Mar 5, 2024 · 26 comments
Closed
10 of 11 tasks

free.fr phishing group: badware #22765

orbotimn75 opened this issue Mar 5, 2024 · 26 comments

Comments

@orbotimn75
Copy link

orbotimn75 commented Mar 5, 2024

Prerequisites

  • This is NOT a YouTube, Facebook or Twitch report. These sites MUST be reported by clicking their respective links.
  • I read and understand the policy about what is a valid filter issue.
  • I verified that this issue is not a duplicate. (Use this button to find out.)
  • I did not remove any of the default filter lists, or I have verified that the issue was not caused by removing any of the default lists.
  • I did not enable additional filter lists, or I have verified that the issue still occurs without enabling additional filter lists.
  • I do not have custom filters/rules, or I have verified that the issue still occurs without custom filters/rules.
  • I am not using uBlock Origin along with other content blockers.
  • I have verified that the web browser's built-in blocker or DNS blocking (standalone or through a VPN) is not causing the issue.
  • I have verified that other extensions are not causing the issue.
  • If this is about a breakage or detection, I have verified that it is caused by uBlock Origin and isn't a site issue.
  • I did not answer truthfully to ALL the above checkboxes.

URL address of the web page

https://espacefidelitefree.fr/

Category

badware

Description

This site https://espacefidelitefree.fr/ is a phishing campaign against customers Free mobile.

The legitimate page can be found at : https://mobile.free.fr/

Other extensions used

none

Screenshot(s)

Screenshot(s)

Configuration

uBlock Origin: 1.56.0
Firefox: 123
filterset (summary):
 network: 135955
 cosmetic: 52462
 scriptlet: 18976
 html: 1739
listset (total-discarded, last-updated):
 default:
  user-filters: 10-1, never
  ublock-filters: 37378-181, 27m Δ
  ublock-badware: 7750-14, 27m Δ
  ublock-privacy: 739-0, now
  ublock-unbreak: 2293-0, 27m Δ
  easylist: 82229-915, 27m Δ
  easyprivacy: 50327-1064, 27m Δ
  urlhaus-1: 4165-0, now
  plowe-0: 3779-1, now
  FRA-0: 22821-110, now
  ublock-quick-fixes: 142-1, 27m Δ
filterset (user): [array of 10 redacted]
trustedset:
 added: [array of 25 redacted]
 removed:
  about-scheme
switchRuleset:
 added: [array of 2 redacted]
userSettings: [none]
hiddenSettings: [none]
supportStats:
 allReadyAfter: 1292 ms (selfie)
 maxAssetCacheWait: 153 ms
 cacheBackend: indexedDB
popupPanel:
 blocked: 0
@ItsProfessional ItsProfessional changed the title espacefidelitefree.fr: [unknown] espacefidelitefree.fr: badware Mar 5, 2024
@iam-py-test
Copy link
Contributor

It seems they are using shopflarehub.com for their payments: https://tria.ge/240305-2bg53abb8x/behavioral1 (CloudFlared). It appears to be malicious and is detected by 10 security vendors on VirusTotal.
Thank you

mapx- added a commit that referenced this issue Mar 8, 2024
Co-authored-by: mapx <10303732+mapx-@users.noreply.github.com>
@orbotimn75
Copy link
Author

New phishing site http://mobile.i-free.fr

The legitimate page can be found at : https://mobile.free.fr/

@stephenhawk8054
Copy link
Member

http://mobile.i-free.fr/

Hmm... The link returns 403 error for me

image

Same as https://www.gatekeeperapp.net/gatekeeper/https%3A%2F%2Fwww.gatekeeperapp.net%2Fgatekeeper%2Fhttps%253A%252F%252F5qin.muelo.fr%252F, it redirects to https://5qin.muelo.fr/ which returns 403 too.

@orbotimn75
Copy link
Author

orbotimn75 commented Mar 14, 2024

if you are a Free mobile customer, this is what appears when you click on the link :

Screenshot_20240314-121129_Firefox

stephenhawk8054 added a commit that referenced this issue Mar 14, 2024
@orbotimn75
Copy link
Author

phishing site https://free-mobil.hubside.fr/

The legitimate page can be found at : https://zimbra.free.fr/ or https://webmail.free.fr/ or https://mobile.free.fr/

stephenhawk8054 added a commit that referenced this issue Mar 18, 2024
@orbotimn75
Copy link
Author

phishing site https://web-mail-free-org.hubside.fr/

The legitimate page can be found at : https://zimbra.free.fr/ or https://webmail.free.fr/

@stephenhawk8054
Copy link
Member

Hmm... Is the whole domain hubside.fr a phishing domain? If so, we can block the whole domain instead of each subdomain.

stephenhawk8054 added a commit that referenced this issue Mar 20, 2024
@orbotimn75
Copy link
Author

solution@hubside.com suggests using the abuse form below, but it doesn't seem very effective :

Nous vous remercions pour votre email.
Pour prendre en charge votre demande, nous vous invitons à remplir le formulaire dédié que vous trouverez ici

Thank you for your email.
To process your request, please fill in the dedicated form here ici

@ItsProfessional
Copy link
Member

Hmm... Is the whole domain hubside.fr a phishing domain? If so, we can block the whole domain instead of each subdomain.

6b0971d#commitcomment-138936944

@ItsProfessional ItsProfessional changed the title espacefidelitefree.fr: badware free.fr phishing group: badware Mar 21, 2024
@orbotimn75
Copy link
Author

new phishing from domain hubside.fr => https://free-service.hubside.fr/

The legitimate page can be found at : https://zimbra.free.fr/ or https://webmail.free.fr/

stephenhawk8054 added a commit that referenced this issue Mar 22, 2024
@orbotimn75
Copy link
Author

orbotimn75 commented Mar 25, 2024

Phishing from domain https://www.hubside.com/ =>

https://freezimail.hubside.fr/
https://zimbrafreemail.hubside.fr/
https://zimbra-inbox.hubside.fr/
https://free-mobile241.hubside.fr/
https://compte-free.hubside.fr/

The legitimate page can be found at : https://zimbra.free.fr/ or https://webmail.free.fr/

@orbotimn75
Copy link
Author

phishing site https://pointsfreemobile.com/fr/

The legitimate page can be found at : https://mobile.free.fr/

stephenhawk8054 added a commit that referenced this issue Mar 25, 2024
@orbotimn75
Copy link
Author

Phishing => https://free-mob2584.hubside.fr/

The legitimate page can be found at : https://zimbra.free.fr/ or https://webmail.free.fr/

stephenhawk8054 added a commit that referenced this issue Mar 27, 2024
@orbotimn75
Copy link
Author

orbotimn75 commented Mar 28, 2024

stephenhawk8054 added a commit that referenced this issue Mar 28, 2024
@orbotimn75
Copy link
Author

orbotimn75 commented Mar 28, 2024

@ItsProfessional ItsProfessional added the ongoing ongoing issue label Mar 28, 2024
@ItsProfessional
Copy link
Member

These phishing sites for free.fr are being created very frequently; keep the issue open.

JobcenterTycoon added a commit that referenced this issue Mar 30, 2024
@orbotimn75
Copy link
Author

orbotimn75 commented Apr 2, 2024

Phishing :

The legitimate page can be found at : https://zimbra.free.fr/ or https://webmail.free.fr/

JobcenterTycoon added a commit that referenced this issue Apr 2, 2024
@orbotimn75
Copy link
Author

phishing site :

https://free-mobi20i2582.hubside.fr/
https://zimbra-free-email.hubside.fr/
https://freezimbra.hubside.fr/

The legitimate page can be found at : https://zimbra.free.fr/ or https://webmail.free.fr/ or https://mobile.free.fr/

iam-py-test added a commit to iam-py-test/my_filters_001 that referenced this issue Apr 3, 2024
JobcenterTycoon added a commit that referenced this issue Apr 3, 2024
@JobcenterTycoon
Copy link
Contributor

Do you work for free.fr and from where do you get all the domains?

@orbotimn75
Copy link
Author

Yes i work for free.fr, these are users and subscribers free.fr who sends us the phishing emails received . You can see an example below :

INFO MAIL

Cher Utilisateur Zimbra,

Zimbra vous informe de la désactivation de votre compte conformément aux règlements si vous ne confirmez pas votre identifiant.
Car passé la date du Lundi 1 Avril 2024 votre compte sera verrouillé.

Identifiez-vous en cliquant sur le bouton ci-dessous:

Réactiver mon compte
Merci de votre confiance

@orbotimn75
Copy link
Author

phishing :

shortlink https://appurl.io/kJA_ItlhkW redirect to https://web0mail.hubside.fr/

JobcenterTycoon added a commit that referenced this issue Apr 4, 2024
iam-py-test added a commit to iam-py-test/my_filters_001 that referenced this issue Apr 4, 2024
@orbotimn75
Copy link
Author

Phishing : https://free-mobile0021547.hubside.fr/

The legitimate page can be found at : https://zimbra.free.fr/ or https://webmail.free.fr/

JobcenterTycoon added a commit that referenced this issue Apr 5, 2024
iam-py-test added a commit to iam-py-test/my_filters_001 that referenced this issue Apr 6, 2024
JobcenterTycoon added a commit that referenced this issue Apr 10, 2024
@orbotimn75
Copy link
Author

New phishing sites from domain hubside.fr/

https://freema.hubside.fr/

https://free-zimbra.hubside.fr/

https://free-mobile1540478.hubside.fr/

https://freewebzim.hubside.fr/

http://acceder-a-mon-free.hubside.fr/

The legitimate page can be found at : https://zimbra.free.fr/ or https://webmail.free.fr/ https://subscribe.free.fr/login/

JobcenterTycoon added a commit that referenced this issue Apr 16, 2024
@orbotimn75
Copy link
Author

phishing site from domain hubside.fr/

https://my-acount-free.hubside.fr/

The legitimate page can be found at : https://zimbra.free.fr/ or https://webmail.free.fr/ https://subscribe.free.fr/login/

JobcenterTycoon added a commit that referenced this issue Apr 18, 2024
@JobcenterTycoon JobcenterTycoon removed the ongoing ongoing issue label May 24, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants