Joseph C

1.6K posts

Joseph C

Joseph C

@ThrowAw70207174

Katılım Ocak 2017
27 Takip Edilen5 Takipçiler
Namecheap.com
Namecheap.com@Namecheap·
@ThrowAw70207174 Hello, thank you for the report. We will investigate the matter and the actions will be taken in accordance to our findings.
English
1
0
0
8
Joseph C
Joseph C@ThrowAw70207174·
@Namecheap I see AitM attacks against universities being setup at the following domain api-ac9fc019[.]pdxs[.]emconstruct[.]com mfilssoas[.]pdxs[.]emconstruct[.]com mycainstdi[.]pdxs[.]emconstruct[.]com mycanvas[.]pdxs[.]emconstruct[.]com sso[.]pdxs[.]emconstruct[.]com
English
1
0
0
8
Joseph C
Joseph C@ThrowAw70207174·
@Namecheap I have identified phishing infrastructure being setup to attack universities at the following domain: api-268194b0[.]uhhy[.]margofritz[.]com lvoginucsc[.]uhhy[.]margofritz[.]com myd2csc[.]uhhy[.]margofritz[.]com ux-asset-commercial[.]uhhy[.]margofritz[.]com
English
1
0
0
9
Joseph C
Joseph C@ThrowAw70207174·
@Namecheap I am observing infra setup for AitM attacks against universities. api-ac9fc019[.]pddeop[.]icltextiles[.]com mfilssoas[.]pddeop[.]icltextiles[.]com mycainstdi[.]pddeop[.]icltextiles[.]com mycanvas[.]pddeop[.]icltextiles[.]com sso[.]pddeop[.]icltextiles[.]com
English
1
0
0
8
Joseph C
Joseph C@ThrowAw70207174·
@Namecheap Hello Namecheap, this is phishing infrastructure through Evilginx. As a result, it cannot be viewed without the direct phishing URL. I have been tracking these attacks through CT logs, you can read more about it here j027.net/hunting-evilgi….
English
0
0
0
2
Namecheap.com
Namecheap.com@Namecheap·
@ThrowAw70207174 Hello)) It seems the reported content is no longer available at the links specified. Please check it on your end and let us know if further assistance is required
English
1
0
0
10
Joseph C
Joseph C@ThrowAw70207174·
@Namecheap I am observing AitM attacks against universities using this domain. api-ac9fc019[.]deop[.]icltextiles[.]com mycanvas[.]deop[.]icltextiles[.]com sso[.]deop[.]icltextiles[.]com
English
1
0
0
8
Joseph C
Joseph C@ThrowAw70207174·
@Namecheap I am observing AitM attacks against universities using this domain. api-529aed63[.]ucdr[.]cathcarttrucking[.]com ssoucsb[.]ucdr[.]cathcarttrucking[.]comux-asset-commercial[.]ucdr[.]cathcarttrucking[.]com
English
1
0
0
15
Joseph C
Joseph C@ThrowAw70207174·
@Namecheap I am observing AitM phishing attacks against universities from this domain api-529aed63[.]ucget[.]webschriften[.]com ssoucsb[.]ucget[.]webschriften[.]com ux-asset-commercial[.]ucget[.]webschriften[.]com
English
1
0
0
8
Joseph C
Joseph C@ThrowAw70207174·
@Namecheap I am observing AitM phishing attacks against universities from this namecheap domain api-529aed63[.]ucndn[.]erfolgscodes[.]com ssoucsb[.]ucndn[.]erfolgscodes[.]com ux-asset-commercial[.]ucndn[.]erfolgscodes[.]com
English
1
0
0
7
Joseph C
Joseph C@ThrowAw70207174·
@Namecheap I have provided more information in DM, let me know if it is sufficient.
English
1
0
0
0
Joseph C
Joseph C@ThrowAw70207174·
@Namecheap There's a tech support scam popup redirect at greengooutrr.com from namecheap. Here's a screenshot showing this behavior. This behavior can only be reproduced from a residential ip in the US. Additionally, the domain of popup is from namecheap too.
Joseph C tweet media
English
1
0
0
0
Joseph C
Joseph C@ThrowAw70207174·
@Namecheap The domain 3mkjeepoiiu.xyz from namecheap redirects to a tech support scam popup when visited from a residential ip in the US, here's a screenshot showing this behavior
Joseph C tweet media
English
1
0
0
0