Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Removing baky.com.br #407

Merged
merged 2 commits into from
Jul 2, 2024
Merged

Removing baky.com.br #407

merged 2 commits into from
Jul 2, 2024

Conversation

gersonfs
Copy link
Contributor

@gersonfs gersonfs commented Jun 3, 2024

Phishing Domain/URL/IP(s):

baky.com.br

Impersonated domain

baky.com.br

Describe the issue

Malicious files were created on this domain due to the use of an outdated version of laravel. We removed the files and did a general update of the site.

Related external source

Screenshot

Click to expand

@spirillen
Copy link
Contributor

I don't see the problem. Closing

image

dsearch baky.com.br

Search result from External Hosts-Sources

@mypdns's External Hosts-Sources can be found here

Sorted result

Search result from easylist

Search in Matrix

Search results from Matrix blacklist project

Did not find any matching RPZ records

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+ Thanks to My Privacy DNS for this knowledge
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Drilling for baky.com.br

baky.com.br. 3600 IN NS ns2.onehost.com.br.
baky.com.br. 3600 IN NS ns1.onehost.com.br.
baky.com.br. 14400 IN A 189.113.6.130

@spirillen
Copy link
Contributor

in response to Phishing-Database/Phishing.Database#897

In which lists do you see the domain??

@spirillen spirillen reopened this Jul 2, 2024
@spirillen
Copy link
Contributor

Ok, I have found your domain now in the https://raw.githubusercontent.com/mitchellkrogza/Phishing.Database/master/ALL-phishing-links.txt which seems NOT to be synced properly with https://raw.githubusercontent.com/mitchellkrogza/Phishing.Database/master/ALL-phishing-domains.txt

I have added it to my import tool, then we will have to see if it can handle URI's

@spirillen
Copy link
Contributor

Can you please rebase your fork.

And keep in mind, there is no guaranties it will remove the domain from Phishing.Database, please see https://github.com/mitchellkrogza/phishing/issues/395

@spirillen spirillen added the ReBase This Merge request need to be rebased from master label Jul 2, 2024
@spirillen spirillen self-requested a review July 2, 2024 11:49
@gersonfs
Copy link
Contributor Author

gersonfs commented Jul 2, 2024

@spirillen rebase done

@spirillen spirillen merged commit bad74fc into Phishing-Database:main Jul 2, 2024
spirillen added a commit to external-sources/hosts-sources that referenced this pull request Jul 2, 2024
Do to a bug in Phishing.Database we are not able to do full search in the active files. For that reason we are now importing the `ALL-phishing-links.txt` and strips it down to domain only list in `data/phishing_database/`

Related issues:
- https://github.com/mitchellkrogza/Phishing.Database/issues/840
- https://github.com/mitchellkrogza/Phishing.Database/issues/881
- Phishing-Database/phishing#381 (comment)
- Phishing-Database/phishing#396
- Phishing-Database/phishing#407
- https://github.com/mitchellkrogza/phishing/issues/395
- mypdns/matrix#624
- blocklistproject/Lists#1252
- https://github.com/mitchellkrogza/Phishing.Database/issues/840
- Phishing-Database/Phishing.Database#722

Trying to use @main for the php installer and using php version 8.4

Added `libdomain-publicsuffix-perl` to the dependencies.sh script as it is required by perl in import.sh. It turns out Perl just anoyingly does it again... 😏
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ReBase This Merge request need to be rebased from master
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants