Skip to content

Instantly share code, notes, and snippets.

@ANeilan
Created April 22, 2020 00:04
Show Gist options
  • Save ANeilan/543c0911979dacd3dbd51ad406b71b8c to your computer and use it in GitHub Desktop.
Save ANeilan/543c0911979dacd3dbd51ad406b71b8c to your computer and use it in GitHub Desktop.
stuff i found over the past 24 hours or so, combing through cert data / opendirectories
URL Domain IP Address Threat Actor Email(s)
http://batricka-71.gq/fax/Whyxoffice365%202018.zip batricka-71.gq 35.157.48.36 None (Unconfigured)
http://beethemovies.ml/Ourtime/Ourtime1.zip beethemovies.ml 192.210.199.68 [email protected]
http://bethasda-71.ga/fax/Whyxoffice365%202018.zip bethasda-71.ga 15.223.67.215 None (Unconfigured)
http://bethasda-71.gq/fax/Whyxoffice365%202018.zip bethasda-71.gq 15.223.67.215 None (Unconfigured)
http://binmon.gq/schwab/schwabere.zip binmon.gq 185.244.39.21 [email protected],[email protected]
http://binmon.gq/schwabu.zip binmon.gq 185.244.39.21 [email protected]
http://biology-71.ml/html/excelz.zip biology-71.ml 34.94.190.216 [email protected],[email protected]
http://calibeautysupplies.top/deliver/Onedrive.xx.zip calibeautysupplies.top 91.234.99.210 [email protected]
http://cannont-71.ga/yahoo/yahoologin.zip cannont-71.ga 35.156.61.38 [email protected] (probably unconfigured)
http://chat.wahatsapp.event20.gq/SC%20GRUP%20FRONTAL.zip chat.wahatsapp.event20.gq 212.24.105.169 [email protected]
http://chat.wahatsapp.zord20.gq/SC%20GRUP%20FRONTAL.zip chat.wahatsapp.zord20.gq 212.24.105.169 [email protected]
http://dorsetvarex.top/hsabankV2.zip dorsetvarex.top 35.238.185.184 [email protected],[email protected]
http://dorsetvarex.top/secumd1.zip dorsetvarex.top 35.238.185.184 [email protected],[email protected]
http://farmandt.ga/galbar/office-365.zip farmandt.ga 162.244.94.202 [email protected]
http://farmandt.ga/hangower/office-365.zip farmandt.ga 162.244.94.202 [email protected]
http://farmandt.ga/notificati0n/office-365.zip farmandt.ga 162.244.94.202 [email protected]
http://farmandt.ga/scr.zip farmandt.ga 162.244.94.202 [email protected],[email protected],[email protected]
http://farmandt.ga/scr/office-365.zip farmandt.ga 162.244.94.202 [email protected]
http://gamingcrypto.top/cibcedited.zip gamingcrypto.top 91.234.99.210 [email protected]
http://isitsa-71.ga/ANA(1).zip isitsa-71.ga 192.232.246.34 [email protected]
http://jumpsuit-71.tk/Wemail.zip jumpsuit-71.tk 18.195.148.12 [email protected]
http://kankmitwa.gq/Proposal/page%20(1).zip kankmitwa.gq 192.210.199.68 [email protected]
http://katanzero-71.cf/SSA/Dedicated%20Office-.zip katanzero-71.cf 35.180.210.253 [email protected]
http://katota-71.cf/Dutch.zip katota-71.cf 34.95.193.177 [email protected]
http://katota-71.ml/telus/telus.zip katota-71.ml 34.95.193.177 [email protected],[email protected],[email protected]
http://omeltoa-71.gq/off2020.zip omeltoa-71.gq 35.157.48.36 [email protected], [email protected]
http://pubg.jtacid.com/PubG.zip pubg.jtacid.com 67.222.38.73 N/A
http://pubg4all.ml/PubG.zip pubg4all.ml 67.222.38.73 N/A
http://rororas-71.cf/Ovvice2019.zip rororas-71.cf 35.246.242.26 [email protected]
http://skalton-71.ml/fax/Whyxoffice365%202018.zip skalton-71.ml 35.180.210.253 None (Unconfigured)
http://soowe-71.tk/sfexp/SfExssmine.zip soowe-71.tk 54.248.54.108 [email protected]
http://theorganicsinstitute.top/Firstbank2.zip theorganicsinstitute.top 91.234.99.210 [email protected],[email protected]
http://twoone-71.tk/outlook/Whyxoffice365%202018.zip twoone-71.tk 18.195.148.12 None (Unconfigured)
http://www.crosbyton.tk/box/1drve.zip www.crosbyton.tk 13.231.229.72 [email protected]
http://www.jackndoll.tk/DocuSign.zip www.jackndoll.tk 51.89.21.154 [email protected]
http://www.jackndoll.tk/suntrust%20page.zip.zip www.jackndoll.tk 51.89.21.154 [email protected]
http://www.lavaflow.cf/client.zip www.lavaflow.cf 192.210.199.68 [email protected]
http://www.lavaflow.tk/office/Office365.zip www.lavaflow.tk 192.210.199.68 [email protected]
http://www.login4.customerss.xyz/bof.zip www.login4.customerss.xyz 104.219.248.112 [email protected]
http://www.lyoth.tk/hot/2020Outlook.zip www.lyoth.tk 13.231.229.72 [email protected],[email protected],[email protected]
http://www.mail54357.xyz/online.standardbank.co.za.zip www.mail54357.xyz (not resolving currently) 102.130.115.253 [email protected]
http://www.mail5800.xyz/online.standardbank.co.za.zip www.mail5800.xyz (not resolving currently) 102.130.115.253 [email protected]
http://www.optamenwa.tk/VnOndrv.zip www.optamenwa.tk 192.210.199.68 [email protected]
http://www.recordbirds.top/cgi--bin/office.zip www.recordbirds.top 91.234.99.253 [email protected]
http://xenlene.xyz/txt/txt.zip xenlene.xyz 185.148.147.240 [email protected],[email protected]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment