Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add yotpo[.]com to add-wildcard-domain #511

Merged

Conversation

g0d33p3rsec
Copy link
Contributor

Phishing Domain/URL/IP(s):

http://em.yotpo.com/ls/click?upn=u001.-2FemWfc87t0MOUEjl1SkAEoimo91FmpUR-2BKpXpfKlemNaYngWWk3jyI7OnE0kJZoWkzybE6M7gtHzmXTNtkwX3vXZf0wHukhCbip4awKsMfmbGJqpeyBK9YCXZooChhIiBTapBcfWBHBF-2B2sl8AYw9xjytQ0tn8Qx2zl8m7ZIzXexAmM4ORRuw1kd63DPVGoPm1PoZX1ZopNNHfTKdRlOSmNx-2FDN-2FVo7s2lDxjQpHmWs-3DbTar_X-2FbAZB1iEW9akNSX35oqPA-2FbffOO3ULBYayntBYqrf85-2FLMKCX5iMCMHgc2C3vwQHj-2BMjCD3rZr3YENAO-2F62E78Fq5EB-2FNq5dR3jbBoOZ9UWUWFcoROHoEHGxm0XJMaqHy0-2BNdOleI3Hlo2b7NzuIrJ21EMK0SzPJ6gVKF83pTS2ykmf2sF4WlTZYXq5jzi9RzS3i-2F0Ef3ZDyok9KsiFfWroNXOECKf68ZjIY2PMaTsjFz6a6VDFMN-2Bm2CTjr0q2SYwA1jt2InPNrrgetXjONRBJzkgKErV8G4ElqBSijZmeRFfEoyFRuY7E9V0iKxo5ZZfepveEqaMbvSu5HpdI4ZdMKVsSwxCzpkb4Ed-2BVBle0CWwIHM-2F-2BREN6mWoa6dfz1qkC88-2BT3hNvrRJQOCE-2BXBytbGkiejtndg70SxBkyXYzZ0LtSQHlDPNxldUqEqXvr-2BjH7EqUIoS5ybmTr5LJZmZVDEXTUKRj5UyG9Zx-2FC8FVUkpuCS294RwWhYsv8Hnc1vqDmNMOMC36Ii2LD93GQgI38-2BJNQ23swH8rPHwAR8KbOr69fMP7TfYB1g7pIkThtBFU7Hr7ZGmmbJeAVOizxxSIqYtS6yonx-2FfMKrRLI8Y-3D

Impersonated domain

https://metamask.io/

Describe the issue

Domain is being used for phishing MetaMask users. The domain is being protected by Cloudfare and redirects to Wikipedia when scanned from a sandbox but has a documented history. The related posts are included in the additional resources.

Related external source

https://urlscan.io/result/52284e24-388a-4d59-a08e-c643881aa5bb/
https://www.virustotal.com/gui/url/a4bb23d70ee59646068216dd25a1670d5384092233996208129ace595d2ca459
https://app.any.run/tasks/a16fe9a1-a656-4266-91ec-5c2782c6b3f9
https://www.reddit.com/r/BinanceUS/comments/1awq4zx/believe_i_got_a_phishing_scam_regarding_metamask/
https://www.tokentrace.com/post/metamask-phishing-email-protect-your-crypto-assets
https://any.run/report/2131d0f2b16f534275a7150f49ff750ec92c695ecd5e2c88189a48ea4e653710/72484f09-bcde-4dd6-806b-5386c194e4ed
https://any.run/report/886659a97808099c0e2566cc0c63f814d5709283804953ce14f538c145c18adc/53ebc68d-e763-4749-82bb-ce31e591ba45

Screenshot

Click to expand

Screenshot 2024-11-21 174636
Screenshot 2024-11-21 175037
image

domain used for metamask phishing
@spirillen spirillen merged commit c6df107 into Phishing-Database:main Nov 22, 2024
1 check passed
spirillen added a commit to mypdns/matrix that referenced this pull request Nov 23, 2024
Fix #1375 #MTX-1377
Fix #1376 #MTX-1378
Fix #1377 #MTX-1379
Fix #1378 #MTX-1380
Fix #1318
Fix #1319
Fix #1320
Fix #1321
Fix #1322
Fix #1323
Fix #1324
Fix #1325
Fix #1326
Fix #1327
Fix #1328
Fix #1329
Fix #1330
Fix #1331
Fix #1332
Fix #1333
Fix #1334
Fix #1335
Fix #1336
Fix #1337
Fix #1338
Fix #1339
Fix #1340
Fix #1341
Fix #1342
Fix #1343
Fix #1344
Fix #1345
Fix #1346
Fix #1347
Fix #1348
Fix #1349
Fix #1350
Fix #1351
Fix #1352
Fix #1353
Fix #1354
Fix #1355
Fix #1356
Fix #1357
Fix #1358
Fix #1359
Fix #1360
Fix #1361
Fix #1362
Fix #1363
Fix #1364
Fix #1365
Fix #1366
Fix #1367
Fix #1368
Fix #1369
Fix #1370
Fix #1371
Fix #1372
Fix #1373
Fix #1374

Rel: Phishing-Database/phishing#510
Rel: Phishing-Database/phishing#511
Rel: Phishing-Database/phishing#513

## Added the following records as phishing

- 32.57.71.153.43
- 142.171.209.174
- 192.3.55.217
- amazonsin.co
- 59.97.174.184
- amazoncik.com
- amazoncil.com
- amazonceb.com
- amazoncog.com
- amazonczh.com
- amazoncwb.com
- amazoncdb.com
- amazoncwg.com
- amazonctl.com
- amazoncra.com
- amazonczk.co
- amazoncdq.com
- amazoncve.com
- amazonczr.com
- amazoncim.com
- amazonces.com
- amazoncwq.com
- postman-vip.top
- yotpo.com
- amazonvrn.co
- postman-vip.icu
- postoffice-com.icu
- postman-vip.life
- postman-vip.xyz
- parcel-vip.icu
- parcel-vip.help
- parcel-vip.click
- parcel-vip.xyz
- parcel-vip.top
- postman-vip.help
- postofficu.top
- postoffico.xyz
- postoffico.icu
- postoffice-vip.icu
- postoffice-vip.help
- postoffice-com.top
- postoffice-vip.xyz
- postoffice-vip.top
- com-expresa.top
- postoffico.help
- com-expresd.top
- com-expresf.top
- com-expresq.top
- com-expresk.top
- com-expresl.top
- com-expresj.top
- com-expresm.top
- vip-expresg.top
- com-expresh.top
- vip-expresw.top
- vip-expresq.top
- vip-expresh.top
- vip-expresj.top
- vip-expresm.top
- vip-expresd.top
- vip-expresf.top

## My Privacy DNS Issues

https://kb.mypdns.org/issue/MTX-1377/32.57.71.153.43 Closed
https://kb.mypdns.org/issue/MTX-1379/142.171.209.174 Closed
https://kb.mypdns.org/issue/MTX-1378/192.3.55.217 Closed
https://kb.mypdns.org/issue/MTX-1339/amazonsin.co  Closed
https://kb.mypdns.org/issue/MTX-1380/59.97.174.184 Closed
https://kb.mypdns.org/issue/MTX-1331/amazoncik.com Closed
https://kb.mypdns.org/issue/MTX-1320/amazoncil.com Closed
https://kb.mypdns.org/issue/MTX-1326/amazonceb.com Closed
https://kb.mypdns.org/issue/MTX-1323/amazoncog.com Closed
https://kb.mypdns.org/issue/MTX-1322/amazonczh.com Closed
https://kb.mypdns.org/issue/MTX-1321/amazoncwb.com Closed
https://kb.mypdns.org/issue/MTX-1325/amazoncdb.com Closed
https://kb.mypdns.org/issue/MTX-1324/amazoncwg.com Closed
https://kb.mypdns.org/issue/MTX-1328/amazonctl.com Closed
https://kb.mypdns.org/issue/MTX-1327/amazoncra.com Closed
https://kb.mypdns.org/issue/MTX-1330/amazonczk.co Closed
https://kb.mypdns.org/issue/MTX-1329/amazoncdq.com Closed
https://kb.mypdns.org/issue/MTX-1332/amazoncve.com Closed
https://kb.mypdns.org/issue/MTX-1334/amazonczr.com Closed
https://kb.mypdns.org/issue/MTX-1333/amazoncim.com Closed
https://kb.mypdns.org/issue/MTX-1336/amazonces.com Closed
https://kb.mypdns.org/issue/MTX-1335/amazoncwq.com Closed
https://kb.mypdns.org/issue/MTX-1340/postman-vip.top Closed
https://kb.mypdns.org/issue/MTX-1338/yotpo.com Closed
https://kb.mypdns.org/issue/MTX-1337/amazonvrn.co Closed
https://kb.mypdns.org/issue/MTX-1342/postman-vip.icu Closed
https://kb.mypdns.org/issue/MTX-1341/postoffice-com.icu Closed
https://kb.mypdns.org/issue/MTX-1344/postman-vip.life Closed
https://kb.mypdns.org/issue/MTX-1343/postman-vip.xyz Closed
https://kb.mypdns.org/issue/MTX-1347/parcel-vip.icu Closed
https://kb.mypdns.org/issue/MTX-1346/parcel-vip.help Closed
https://kb.mypdns.org/issue/MTX-1345/parcel-vip.click Closed
https://kb.mypdns.org/issue/MTX-1349/parcel-vip.xyz Closed
https://kb.mypdns.org/issue/MTX-1348/parcel-vip.top Closed
https://kb.mypdns.org/issue/MTX-1351/postman-vip.help Closed
https://kb.mypdns.org/issue/MTX-1350/postofficu.top Closed
https://kb.mypdns.org/issue/MTX-1353/postoffico.xyz Closed
https://kb.mypdns.org/issue/MTX-1352/postoffico.icu Closed
https://kb.mypdns.org/issue/MTX-1356/postoffice-vip.icu Closed
https://kb.mypdns.org/issue/MTX-1355/postoffice-vip.help Closed
https://kb.mypdns.org/issue/MTX-1354/postoffice-com.top Closed
https://kb.mypdns.org/issue/MTX-1358/postoffice-vip.xyz Closed
https://kb.mypdns.org/issue/MTX-1357/postoffice-vip.top Closed
https://kb.mypdns.org/issue/MTX-1360/com-expresa.top Closed
https://kb.mypdns.org/issue/MTX-1359/postoffico.help Closed
https://kb.mypdns.org/issue/MTX-1363/com-expresd.top Closed
https://kb.mypdns.org/issue/MTX-1362/com-expresf.top Closed
https://kb.mypdns.org/issue/MTX-1361/com-expresq.top Closed
https://kb.mypdns.org/issue/MTX-1365/com-expresk.top Closed
https://kb.mypdns.org/issue/MTX-1364/com-expresl.top Closed
https://kb.mypdns.org/issue/MTX-1367/com-expresj.top Closed
https://kb.mypdns.org/issue/MTX-1366/com-expresm.top Closed
https://kb.mypdns.org/issue/MTX-1369/vip-expresg.top Closed
https://kb.mypdns.org/issue/MTX-1368/com-expresh.top Closed
https://kb.mypdns.org/issue/MTX-1372/vip-expresw.top Closed
https://kb.mypdns.org/issue/MTX-1371/vip-expresq.top Closed
https://kb.mypdns.org/issue/MTX-1370/vip-expresh.top Closed
https://kb.mypdns.org/issue/MTX-1374/vip-expresj.top Closed
https://kb.mypdns.org/issue/MTX-1373/vip-expresm.top Closed
https://kb.mypdns.org/issue/MTX-1375/vip-expresd.top Closed
https://kb.mypdns.org/issue/MTX-1376/vip-expresf.top Closed

## Credit:

- @g0d33p3rsec

---------

You can always be following My Privacy DNS at https://kb.mypdns.org/issues?u=1

Sponsor us by Donate to My Privacy DNS https://kb.mypdns.org/articles/MTX-A-3/DONATION
@g0d33p3rsec g0d33p3rsec deleted the add-yotpo.com-to-wildcard-list branch November 23, 2024 17:47
@g0d33p3rsec
Copy link
Contributor Author

@spirillen check out the timezone in the lure email xD

image
image

@spirillen
Copy link
Contributor

I'm not surprised. The Chinese are coming after you, they won't not just a piece of the pot, they wont the entire pot for them self

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants