<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Ducks</title>
    <link>https://infosec.press/ducks/</link>
    <description></description>
    <pubDate>Sat, 30 May 2026 18:02:33 +0000</pubDate>
    <item>
      <title>3nf3vi.com</title>
      <link>https://infosec.press/ducks/3nf3vi-com</link>
      <description>&lt;![CDATA[3nf3vi.com&#xA;&#xA;Mostly note to self:&#xA;Summer 2025 a crypto mining scam setup was made.&#xA;dlmining.com, dlmining.net and dldefi.com&#xA;Probably advertised through a kind of affiliate network.&#xA;This network apparently paid websites for promoting the scam.&#xA;Many apparently legal websites.&#xA;The setup seems to have disappeared around early march 2026.&#xA;&#xA;dldefi.com seems to have used a chat support at 3nf3vi.com.&#xA;Which now can be found at 34.49.197.197 (googleusercontent.com) together with a buttload of &#34;6 chars&#34; domains.&#xA;Have not checked further so I don&#39;t know if this are domains used solely for scams or they are domains used by a &#34;legitimate&#34; support .services&#xA;&#xA;3nf3vi.com&#xA;5beixs.com&#xA;64p7r3.com&#xA;832tfj.com&#xA;a8av4j.com&#xA;arx8q6.com&#xA;b3xcab.com&#xA;c7n2w8.com&#xA;cch4s3.com&#xA;dqwh7c.com&#xA;e8ndtg.com&#xA;egu8wh.com&#xA;f5guu4.com&#xA;g3zu5v.com&#xA;g5wpcg.com&#xA;hdfy7i.com&#xA;i4z3by.com&#xA;imxtm3.com&#xA;ix3hj4.com&#xA;j4ky5m.com&#xA;jffute.com&#xA;k9tnjg.com&#xA;kj2r6m.com&#xA;ngkymv.com&#xA;pzgfpd.com&#xA;qp8k3p.com&#xA;rkc2ph.com&#xA;sb26uv.com&#xA;sz2att.com&#xA;th5at3.com&#xA;ticp6s.com&#xA;u3kitd.com&#xA;ua7tm8.com&#xA;v4ru2c.com&#xA;vbyr5j.com&#xA;x7t5ct.com&#xA;xsxeg4.com&#xA;xwuu4r.com&#xA;y3qdgq.com&#xA;yrmdfz.com&#xA;z9pv3v.com&#xA;&#xA;b&#xA;]]&gt;</description>
      <content:encoded><![CDATA[<p>3nf3vi.com</p>

<p>Mostly note to self:
Summer 2025 a crypto mining scam setup was made.
dlmining.com, dlmining.net and dldefi.com
Probably advertised through a kind of affiliate network.
This network apparently paid websites for promoting the scam.
Many apparently legal websites.
The setup seems to have disappeared around early march 2026.</p>

<p>dldefi.com seems to have used a chat support at 3nf3vi.com.
Which now can be found at 34.49.197.197 (googleusercontent.com) together with a buttload of “6 chars” domains.
Have not checked further so I don&#39;t know if this are domains used solely for scams or they are domains used by a “legitimate” support .services</p>

<p>3nf3vi.com
5beixs.com
64p7r3.com
832tfj.com
a8av4j.com
arx8q6.com
b3xcab.com
c7n2w8.com
cch4s3.com
dqwh7c.com
e8ndtg.com
egu8wh.com
f5guu4.com
g3zu5v.com
g5wpcg.com
hdfy7i.com
i4z3by.com
imxtm3.com
ix3hj4.com
j4ky5m.com
jffute.com
k9tnjg.com
kj2r6m.com
ngkymv.com
pzgfpd.com
qp8k3p.com
rkc2ph.com
sb26uv.com
sz2att.com
th5at3.com
ticp6s.com
u3kitd.com
ua7tm8.com
v4ru2c.com
vbyr5j.com
x7t5ct.com
xsxeg4.com
xwuu4r.com
y3qdgq.com
yrmdfz.com
z9pv3v.com</p>

<p>b</p>
]]></content:encoded>
      <guid>https://infosec.press/ducks/3nf3vi-com</guid>
      <pubDate>Wed, 25 Mar 2026 22:40:28 +0000</pubDate>
    </item>
    <item>
      <title>The enablers</title>
      <link>https://infosec.press/ducks/the-enablers</link>
      <description>&lt;![CDATA[The hosts. And the templates for the cryptoscammers, the &#34;cargospammers&#34;, the fake bank scammers etc are being made by someone(s). You name it. Have given up on the hosts. Seems we have to settle with &#34;name and shame&#34;.&#xA;And then we have the brokers. And the spammers, the &#34;affiliate&#34; networks.&#xA;We sometimes stumble over all kinds of these, should start to make a list.&#xA;&#xA;gogowebsites.store &#xA;https://www.gogowebsites.store/&#xA;Creation Date: 2025-03-24 (namecheap)&#xA;hosted at 198.251.88.162 (Frantech/Ponynet)&#xA;]]&gt;</description>
      <content:encoded><![CDATA[<p>The hosts. And the templates for the cryptoscammers, the “cargospammers”, the fake bank scammers etc are being made by someone(s). You name it. Have given up on the hosts. Seems we have to settle with “name and shame”.
And then we have the brokers. And the spammers, the “affiliate” networks.
We sometimes stumble over all kinds of these, should start to make a list.</p>

<h3 id="gogowebsites-store">gogowebsites.store</h3>

<p><a href="https://www.gogowebsites.store/" rel="nofollow">https://www.gogowebsites.store/</a>
Creation Date: 2025-03-24 (namecheap)
hosted at 198.251.88.162 (Frantech/Ponynet)</p>
]]></content:encoded>
      <guid>https://infosec.press/ducks/the-enablers</guid>
      <pubDate>Sun, 09 Nov 2025 03:14:00 +0000</pubDate>
    </item>
    <item>
      <title>From 49.12.82.250 to 195.201.173.222</title>
      <link>https://infosec.press/ducks/from-49-12-82-250-to-195-201-173-222</link>
      <description>&lt;![CDATA[From 49.12.82.250 to 195.201.173.222&#xA;Lots of domains moved , both ips in Hetzner space.&#xA;Many of the domains are fake crypto investing sites #cryptoscam.&#xA;And other scam sites.]]&gt;</description>
      <content:encoded><![CDATA[<p>From 49.12.82.250 to 195.201.173.222
Lots of domains moved , both ips in Hetzner space.
Many of the domains are fake crypto investing sites <a href="/ducks/tag:cryptoscam" class="hashtag" rel="nofollow"><span>#</span><span class="p-category">cryptoscam</span></a>.
And other scam sites.</p>
]]></content:encoded>
      <guid>https://infosec.press/ducks/from-49-12-82-250-to-195-201-173-222</guid>
      <pubDate>Tue, 03 Dec 2024 18:39:42 +0000</pubDate>
    </item>
    <item>
      <title>Crypto refund scams</title>
      <link>https://infosec.press/ducks/crypto-refund-scams-fnyh</link>
      <description>&lt;![CDATA[More and more sites popping up.&#xA;Some results from urlscan.io as of today (8. nov. 2024):&#xA;advokatiks.info&#xA;advokats.blog&#xA;advokats.info&#xA;canada-pol.best&#xA;canada-pol.biz&#xA;canada-pol.site&#xA;cyber-payback.pro&#xA;cyber-police.site&#xA;cyberfundreturn.pics&#xA;cyberfundreturn.pro&#xA;cyberreturnfund.digital&#xA;cyberpl.info&#xA;digital-recover.cyou&#xA;digital-recovery.autos&#xA;digital-recover.best&#xA;digital-recovery.best&#xA;digital-recovery.blog&#xA;digital-recovery.bond&#xA;digital-recovery.site&#xA;digital-recovery.xyz&#xA;digitalrecovery.autos&#xA;digitalrecovery.cam&#xA;digitalrecovery.site&#xA;digitalrefund.apicil.group&#xA;euro-pol.art&#xA;euro-polc.blog&#xA;euro-polc.site&#xA;europol-eu.com&#xA;europol-police.pro&#xA;europol-refund.info&#xA;europolonline.net&#xA;germam-pol.xyz&#xA;german-police.blog&#xA;germanic-pol.auction&#xA;gretcomp-invest.com&#xA;gretcomp-invest.com&#xA;interfundreturned.digital&#xA;internet-cyberpolice.network&#xA;queenscreekcapital.com&#xA;refunds-money.site&#xA;secureinvestments.cfd&#xA;uk-advokats.site&#xA;uk-pol.site&#xA;Some of those are probably gone  when you read this.&#xA;&#xA;If you are registered at urlscan.io, here is a list with &#34;dynamic&#34; results based on one common file :&#xA;https://urlscan.io/search/#filename:%22bg-important2.png%22&#xA;There are some duplicates and maybe a few not related.&#xA;And there is probably better ways to find more related domains.&#xA;&#xA;One example of whois info. Somehow we mistrust the registrant info, one may wonder about globaldomaingroup.com and its resellers. They seem to be involved in several of these domains.&#xA;This domain was registered on Sept. 24 this year and is still alive as of Nov. 8 (2024):&#xA;whois advokatiks.info (some info skipped for readability)&#xA;organisation: Identity Digital Limited&#xA;(included in administrative contact info)&#xA;contact:      administrative&#xA;name:         Vice President, Engineering&#xA;organisation: Identity Digital Limited&#xA;address:      10500 NE 8th Street, Suite 750&#xA;address:      Bellevue WA 98004&#xA;address:      United States of America (the)&#xA;phone:        +1.425.298.2200&#xA;fax-no:       +1.425.671.0020&#xA;e-mail:       tldadmin@identity.digital&#xA;contact:      technical&#xA;(included in administrative contact  info)&#xA;nserver:      A0.INFO.AFILIAS-NST.INFO 199.254.31.1 2001:500:19:0:0:0:0:1&#xA;nserver:      A2.INFO.AFILIAS-NST.INFO 199.249.113.1 2001:500:41:0:0:0:0:1&#xA;nserver:      B0.INFO.AFILIAS-NST.ORG 199.254.48.1 2001:500:1a:0:0:0:0:1&#xA;nserver:      B2.INFO.AFILIAS-NST.ORG 199.249.121.1 2001:500:49:0:0:0:0:1&#xA;nserver:      C0.INFO.AFILIAS-NST.INFO 199.254.49.1 2001:500:1b:0:0:0:0:1&#xA;nserver:      D0.INFO.AFILIAS-NST.ORG 199.254.50.1 2001:500:1c:0:0:0:0:1&#xA;ds-rdata:     5104 8 2 1af7548a8d3e2950c20303757df9390c26cfa39e26c8b6a8f6c8b1e72dd8f744&#xA;whois:        whois.nic.info&#xA;whois.globaldomaingroup.com&#xA;Domain Name: ADVOKATIKS.INFO&#xA;Registry Domain ID: 977211288a584007a5ea216ae869c497-DONUTS&#xA;Registrar WHOIS Server: whois.globaldomaingroup.com&#xA;Registrar URL: http://www.globaldomaingroup.com&#xA;Updated Date: 2024-09-25T09:24:07.0Z&#xA;Creation Date: 2024-09-24T15:36:20.0Z&#xA;Registrar Registration Expiration Date: 2025-09-24T15:36:20.0Z&#xA;Registrar: Global Domain Group LLC&#xA;Registrar IANA ID: 3956&#xA;Registrar Abuse Contact Email: abuse@globaldomaingroup.com&#xA;Registrar Abuse Contact Phone: +1.8053943992&#xA;Reseller: Andro Givan&#xA;Registry Registrant ID: C-1408273&#xA;Registrant Name: Anya Cruk&#xA;Registrant Street: Сумы&#xA;Registrant City: Суми&#xA;Registrant State/Province: Сумська область&#xA;Registrant Postal Code: 01001&#xA;Registrant Country: UA&#xA;Registrant Phone: +380.508445774&#xA;Registrant Email: hasladus@gmail.com&#xA;Registry Admin ID: C-1408275&#xA;&#xA;(admin/tech info same as Registrant info)&#xA;&#xA;Name Server: daniella.ns.cloudflare.com&#xA;Name Server: milan.ns.cloudflare.com&#xA;DNSSEC: unsigned&#xA;      Last update of WHOIS database: 2024-09-25 02:24:07 -0700 &lt;&lt;&lt;&#xA;&#xA;And one may also wonder a bit about Cloudflare:&#xA;~ % dig advokatiks.info&#xA;;; ANSWER SECTION:&#xA;advokatiks.info.&#x9;300&#x9;IN&#x9;A&#x9;172.67.170.22&#xA;advokatiks.info.&#x9;300&#x9;IN&#x9;A&#x9;104.21.39.85&#xA;;; WHEN: Fri Nov 08  2024&#xA;&#xA;]]&gt;</description>
      <content:encoded><![CDATA[<p>More and more sites popping up.
Some results from urlscan.io as of today (8. nov. 2024):
advokatiks.info
advokats.blog
advokats.info
canada-pol.best
canada-pol.biz
canada-pol.site
cyber-payback.pro
cyber-police.site
cyberfundreturn.pics
cyberfundreturn.pro
cyberreturnfund.digital
cyberpl.info
digital-recover.cyou
digital-recovery.autos
digital-recover.best
digital-recovery.best
digital-recovery.blog
digital-recovery.bond
digital-recovery.site
digital-recovery.xyz
digitalrecovery.autos
digitalrecovery.cam
digitalrecovery.site
digitalrefund.apicil.group
euro-pol.art
euro-polc.blog
euro-polc.site
europol-eu.com
europol-police.pro
europol-refund.info
europolonline.net
germam-pol.xyz
german-police.blog
germanic-pol.auction
gretcomp-invest.com
gretcomp-invest.com
interfundreturned.digital
internet-cyberpolice.network
queenscreekcapital.com
refunds-money.site
secureinvestments.cfd
uk-advokats.site
uk-pol.site
Some of those are probably gone  when you read this.</p>

<p>If you are registered at urlscan.io, here is a list with “dynamic” results based on one common file :
<a href="https://urlscan.io/search/#filename:%22bg-important2.png%22" rel="nofollow">https://urlscan.io/search/#filename:%22bg-important2.png%22</a>
There are some duplicates and maybe a few not related.
And there is probably better ways to find more related domains.</p>

<p>One example of whois info. Somehow we mistrust the registrant info, one may wonder about globaldomaingroup.com and its resellers. They seem to be involved in several of these domains.
This domain was registered on Sept. 24 this year and is still alive as of Nov. 8 (2024):
whois advokatiks.info (some info skipped for readability)
organisation: Identity Digital Limited
(included in administrative contact info)
contact:      administrative
name:         Vice President, Engineering
organisation: Identity Digital Limited
address:      10500 NE 8th Street, Suite 750
address:      Bellevue WA 98004
address:      United States of America (the)
phone:        +1.425.298.2200
fax-no:       +1.425.671.0020
e-mail:       tldadmin@identity.digital
contact:      technical
(included in administrative contact  info)
nserver:      A0.INFO.AFILIAS-NST.INFO 199.254.31.1 2001:500:19:0:0:0:0:1
nserver:      A2.INFO.AFILIAS-NST.INFO 199.249.113.1 2001:500:41:0:0:0:0:1
nserver:      B0.INFO.AFILIAS-NST.ORG 199.254.48.1 2001:500:1a:0:0:0:0:1
nserver:      B2.INFO.AFILIAS-NST.ORG 199.249.121.1 2001:500:49:0:0:0:0:1
nserver:      C0.INFO.AFILIAS-NST.INFO 199.254.49.1 2001:500:1b:0:0:0:0:1
nserver:      D0.INFO.AFILIAS-NST.ORG 199.254.50.1 2001:500:1c:0:0:0:0:1
ds-rdata:     5104 8 2 1af7548a8d3e2950c20303757df9390c26cfa39e26c8b6a8f6c8b1e72dd8f744
whois:        whois.nic.info
whois.globaldomaingroup.com
Domain Name: ADVOKATIKS.INFO
Registry Domain ID: 977211288a584007a5ea216ae869c497-DONUTS
Registrar WHOIS Server: whois.globaldomaingroup.com
Registrar URL: <a href="http://www.globaldomaingroup.com" rel="nofollow">http://www.globaldomaingroup.com</a>
Updated Date: 2024-09-25T09:24:07.0Z
Creation Date: 2024-09-24T15:36:20.0Z
Registrar Registration Expiration Date: 2025-09-24T15:36:20.0Z
Registrar: Global Domain Group LLC
Registrar IANA ID: 3956
Registrar Abuse Contact Email: abuse@globaldomaingroup.com
Registrar Abuse Contact Phone: +1.8053943992
Reseller: Andro Givan
Registry Registrant ID: C-1408273
Registrant Name: Anya Cruk
Registrant Street: Сумы
Registrant City: Суми
Registrant State/Province: Сумська область
Registrant Postal Code: 01001
Registrant Country: UA
Registrant Phone: +380.508445774
Registrant Email: hasladus@gmail.com
Registry Admin ID: C-1408275</p>

<p>(admin/tech info same as Registrant info)</p>

<p>Name Server: daniella.ns.cloudflare.com
Name Server: milan.ns.cloudflare.com
DNSSEC: unsigned
&gt;&gt;&gt; Last update of WHOIS database: 2024-09-25 02:24:07 -0700 &lt;&lt;&lt;</p>

<p>And one may also wonder a bit about Cloudflare:
~ % dig advokatiks.info
;; ANSWER SECTION:
advokatiks.info.    300 IN  A   172.67.170.22
advokatiks.info.    300 IN  A   104.21.39.85
;; WHEN: Fri Nov 08  2024</p>
]]></content:encoded>
      <guid>https://infosec.press/ducks/crypto-refund-scams-fnyh</guid>
      <pubDate>Fri, 08 Nov 2024 20:38:21 +0000</pubDate>
    </item>
    <item>
      <title>Fraud sites on the move</title>
      <link>https://infosec.press/ducks/many-fraud-sites-moved-from-94-23-253-103-to-84-247-184-65</link>
      <description>&lt;![CDATA[Fraud sites on the move &#xA;&#xA;Many fraud sites has been moved from 94.23.253.103 to 84.247.184.65.&#xA;Still many left at 94.23.253.103. &#xA;Related:&#xA;prime.seodns.one&#xA;server.multivpshost.com (Creation Date: 2024-09-24)&#xA;okonjohn133.gmail.com&#xA;ciscopet2021.gmail.com&#xA;https://whoisdatacenter.com/email/ciscopet2021@gmail.com/&#xA;https://bgp.he.net/ip/94.23.253.103#dnsrecords&#xA;https://bgp.he.net/ip/84.247.184.65#dnsrecords&#xA;OVH&#xA;Centrihost.com&#xA;Anitahost.com]]&gt;</description>
      <content:encoded><![CDATA[<p>Fraud sites on the move</p>

<p>Many fraud sites has been moved from 94.23.253.103 to 84.247.184.65.
Still many left at 94.23.253.103.
Related:
prime.seodns.one
server.multivpshost.com (Creation Date: 2024-09-24)
okonjohn133.gmail.com
ciscopet2021.gmail.com
<a href="https://whoisdatacenter.com/email/ciscopet2021@gmail.com/" rel="nofollow">https://whoisdatacenter.com/email/ciscopet2021@gmail.com/</a>
<a href="https://bgp.he.net/ip/94.23.253.103#_dnsrecords" rel="nofollow">https://bgp.he.net/ip/94.23.253.103#_dnsrecords</a>
<a href="https://bgp.he.net/ip/84.247.184.65#_dnsrecords" rel="nofollow">https://bgp.he.net/ip/84.247.184.65#_dnsrecords</a>
OVH
Centrihost.com
Anitahost.com</p>
]]></content:encoded>
      <guid>https://infosec.press/ducks/many-fraud-sites-moved-from-94-23-253-103-to-84-247-184-65</guid>
      <pubDate>Fri, 08 Nov 2024 00:29:47 +0000</pubDate>
    </item>
    <item>
      <title>The &#34;olux&#34; and/or &#34;oxo&#34; or whatever guys</title>
      <link>https://infosec.press/ducks/the-olux-and-or-oxo-or-whatever-guys</link>
      <description>&lt;![CDATA[Their telegram account: hxxps://t.me/oluxshopsite/&#xA;2 336 subscribers&#xA;Olux Buy Tools, Shells, web shell, RDP, SSH, cPanel, Mailer, SMTP, Leads, Webmail, Cards, Account, Pages, olux, Olux SHOP, olux store&#xA;&#xA;hxxps://t.me/oluxshopsite/729:&#xA;quoteTutorial Video&#xA;Cpanel &amp; shell &amp; Smtps &amp; Mailler 1$-10$&#xA;Rdps &amp; Office logs &amp; Leads &amp; Numbers 1$-20$&#xA;Accounts &amp; webmails &amp; Pages &amp; Methods 1$-500$&#xA;&#xA;you can top up your account instantly few seconds with bitcoin&#xA;Send the exactly number of Bitcoin or more&#xA;don&#39;t close the payment page. u can refresh page&#xA;&#xA;Any Problem with the order:Submit report to seller&#xA;Seller didn&#39;t fix problem within 5 hours.We will refund Buyer.&#xA;Buyer didn&#39;t reply within 24 hours after seller.We will Close report.&#xA;Note:avoid multi reply.&#xA;hxxps://olux.li&#xA;hxxps://oluxshop.li&#xA;t.me/oluxshopsite/729&#xA;edited  Sep 28 at 07:43&#xA;/quote&#xA;&#xA;cdn4.cdn-telegram.org/file/cff2fa7546.mp4 --  not able to catch that one.&#xA;&#xA;IP-address 162.55.238.94&#xA;I first stumbled across a cryptofraud site on that IP.&#xA;But I also found sites on the same IP with hidden content.&#xA;One or more lines with the following content on one or more pages on the same domain, first example:&#xA;view-source:hxxps://www.bitwealthasset.com/ :&#xA;hxxps://www.oxo.si/&#39;  Buy Spamming Tools, Shells, web shell, RDP, SSH, cPanel.&#xA;I don&#39;t know the value of this, some kind of &#34;seo&#34; maybe?&#xA;Other domains with the same or variations of the code:&#xA;&#xA;bluerichfoods.com&#xA;bxplorer.online&#xA;tocpharmaceuticals.com&#xA;euphoriaeventplace.com (24 rows with the code)&#xA;abbasheartinternationalministries.com&#xA;abdanielstradomedhospital.com&#xA;caishencharteredtrust.com&#xA;capitalgrowinvest.com&#xA;capitecfin.com&#xA;cattyinvest.com&#xA;cheeckstox.com&#xA;educurrency.top&#xA;&#xA;citricosartaca.com is apparently a blank page, but contains almost 40 lines, but with additional domains and keywords in the code.&#xA;Contains links to the following domains:&#xA; oxo.vc (gone), oxo.si (127.0.0.1) and oxo.is (which celebrates christmas).&#xA;&#34;Buy Leads&#34;and &#34;SMTP&#34; has sneaked in some places in what &#34;services&#34; they seem to provide.&#xA;&#xA;clarity-options-trade.com&#xA;climaxpaytrading.com&#xA;coinswalletsapp.com&#xA;commercial-trading.com&#xA;conexriseltd.com&#xA;crescent-funds.com&#xA;crownenergy-investment.com&#xA;cryptohive.online&#xA;cryptohubmine.com&#xA;cryptoinxhange.com&#xA;cryptotradinggai.com&#xA;bettercryptoinvestment.net&#xA;climatefitsolutions.com&#xA;educurrency.top (redirectet from chuksblog.top)&#xA;clarity-options-trade.com&#xA;climaxpaytrading.com&#xA;cloudminingcity.com&#xA;coinstitude.com&#xA;combdb.com&#xA;commercial-trading.com&#xA;corporateuniontrustbank.com&#xA;couttss.com&#xA;cryptnetverse.com&#xA;cryptoevolution.info&#xA;cryptohubmine.com&#xA;cryptoinxhange.com&#xA;cryptoref.info&#xA;cryptospotpro.online&#xA;daily-gt.com&#xA;dashtradefx.com&#xA;debulad.com&#xA;decentralisedincome.com&#xA;deroyaleservices.com&#xA;doubleyielders.com&#xA;empablockmarket.live&#xA;eqtycdf.com&#xA;euphoriaeventplace.com&#xA;expertminer.online&#xA;firstcornerstoneb.com&#xA;firstmidwsb.com&#xA;firstspringcu.online&#xA;flaretrustline.app&#xA;ftxdailyincome.com&#xA;fx-primetradhub.com&#xA;fxnetworktrading.com&#xA;getmypins.com/manage/&#xA;ggemfx.com&#xA;glimcoinfx.com&#xA;globalbestcutbutchers.com (in total 190 lines of code)&#xA;globalbinarycpro.com&#xA;globalprimefinance.com&#xA;globalsignalexpertmarkets.com&#xA;globewritershub.com&#xA;glockamory.com&#xA;gnbancorp.com&#xA;godfelhrconsultancy.com&#xA;goldenmovicltd.com&#xA;grandoption.org&#xA;grantbakingonline.com&#xA;greencoastonline.org&#xA;greenpathtb.com&#xA;greenpathtrust.com&#xA;gricunashr.com&#xA;hakkbully.com&#xA;hakkdomain.com&#xA;hakknocrat.com&#xA;haloinvestpro.com&#xA;hashmarketfx.com&#xA;heritagecapitalfx.com&#xA;heritagecf.net&#xA;heritagepvltd.com&#xA;hfplatform.live&#xA;hoardblockexplorer.info&#xA;hoardfx.com&#xA;hoperbookings.online&#xA;horizonjury.com&#xA;icbcsbnk.com&#xA;iconiccanna.com&#xA;trades.idealtradesignal.com&#xA;instaplug01.com&#xA;intconib.com&#xA;intertrustbk.com&#xA;itechglobehack.com&#xA;jkcostant.online&#xA;kathleencahillmariconda.com&#xA;kryptofxcore.com&#xA;legacycrf.com&#xA;legcreditf.com&#xA;liamfinancing.com&#xA;liteinterext.online&#xA;luminerybank.com&#xA;lumineryfb.com&#xA;luxorrtech.com&#xA;masterfxtrade.live&#xA;mauricugointernational.com&#xA;mectomfx.com&#xA;megafxoptions.com&#xA;midascryptotrade.com&#xA;milesassetltd.com&#xA;digitechcompany.cloud/en/public/ (redirects from minecoins.online)&#xA;moleystonescapitals.com&#xA;mycrypai.com&#xA;mypnconline.com&#xA;myviasupport.com&#xA;nationalcreditunion.online&#xA;niketradeprime.com&#xA;northcelly.com&#xA;northernsb.com&#xA;omegafinanceleasing.com&#xA;optimoser.com&#xA;optimuminternationalmarkets.com&#xA;ordezenterprise.com&#xA;peakhash.com&#xA;pinb.online&#xA;premier-option.com&#xA;primeglobalinvestments.live/home/&#xA;profxcrypto.com&#xA;prohakks.com&#xA;propertiesloans.com&#xA;prudcrb.comstockstradersfx.com&#xA;standardcorpb.com&#xA;stuartfellstaffordshirebullterriers.com&#xA;successfulfx.online&#xA;suisepay.com&#xA;surfhakks.com&#xA;swisslitebank.online&#xA;syngenresources.com&#xA;tcloudusdt.com&#xA;tescoinv.com&#xA;titantrustb.com (site copied from cnl.com, which was registered in 1995 and seems &#34;legit&#34;)&#xA;tnbancorp.com&#xA;tocpharmaceuticals.com (on a buttload of links on this domain)&#xA;tokssphere.com&#xA;tonensiadiamonds.com&#xA;top-m.online&#xA;topromedics.com&#xA;torchcart.com&#xA;trippydelics.store&#xA;tsbcadvisor.com&#xA;ualliancecrdu.com&#xA;ultimafxoption.com&#xA;ultimaterealistic.com&#xA;ultimatexplorer.info&#xA;&#xA;ultrafxoption.com  &#xA;A bit interesting is that the code did not exist on ultrafxoption.com on November 30th 2022 according to urlscan.io.&#xA;But shows up in a scan in December 2023. Did all sites got this code injected in this timeframe? Can only speculate. Or use a lot of time trying to find out.&#xA;&#xA;uniqueglobaloptions.com&#xA;vacationdepts.info&#xA;vertextradings.com&#xA;vitalityplc.online&#xA;waxiprofit.com&#xA;wcouservice.biz&#xA;web-gmd.com&#xA;westagefinance.com  According to urlscan this domain contained the code also on December 4th 2023&#xA;winnersviewoptioninvestment.org&#xA;wisgodynamic.com&#xA;wmovelogistics.com&#xA;wolf-trademarket.cfd&#xA;world-miners.com&#xA;wourld-cour.com&#xA;xiloans.com&#xA;xpressct.com&#xA;xtrafcb.com&#xA;xtrainterextcorp.com&#xA;xtrainterextfb.com&#xA;xtrainterextfcb.com&#xA;xtratreasury.com&#xA;ysmbundle.com&#xA;ziraatinternationalcorporation.com * According to urlscan this domain contained the code also on September 11th 2023&#xA; &#xA;&#xA;citricosartaca.com is apparently a blank page, but contains almost 40 lines, but with different additional domains and keywords in the code.&#xA;Contains links to the following domains:&#xA; oxo.vc (gone), oxo.si (127.0.0.1) and oxo.is which celebrates christmas.&#xA;&#34;Buy Leads&#34;and &#34;SMTP&#34; has sneaked in some places in what &#34;services&#34; they provide.&#xA;&#xA;Various search engines gives hits to other sites on the same IP, but the hidden stuff is now gone:&#xA;fujowillbusiness.com/sample-page/&#xA;wmtips.com/tools/info/sh3elltools.to&#xA;hxxps://www.hotelfontana.de/magazin/tag/ayurvedische-reinigungskur/&#xA;hxxps://albertfinni.com/gva_template/crowdfunding-single-template/&#xA;&#xA;Some sites appear in searches, but are now gone:&#xA;lufix.pro, lufix.to, oluxshop.to&#xA;&#xA;Domains, variatons of oluxshop.[tld]&#xA;oluxshop.to (127.0.0.1)&#xA;&#xA;Domains, variatons of olux.[tld]&#xA;olux.to&#xA;&#xA;ICQ:&#xA;hxxps://icq.im/oluxshop&#xA;&#xA;A now apparent dead facebook account: hxxps://www.facebook.com/groups/buywebshell/&#xA;sh3elltools.to seems somwehat related.&#xA;]]&gt;</description>
      <content:encoded><![CDATA[<p>Their telegram account: hxxps://t.me/oluxshopsite/
2 336 subscribers
Olux Buy Tools, Shells, web shell, RDP, SSH, cPanel, Mailer, SMTP, Leads, Webmail, Cards, Account, Pages, olux, Olux SHOP, olux store</p>

<p>hxxps://t.me/oluxshopsite/729:
Tutorial Video
Cpanel &amp; shell &amp; Smtps &amp; Mailler 1$-10$
Rdps &amp; Office logs &amp; Leads &amp; Numbers 1$-20$
Accounts &amp; webmails &amp; Pages &amp; Methods 1$-500$</p>

<p>you can top up your account instantly few seconds with bitcoin
Send the exactly number of Bitcoin or more
don&#39;t close the payment page. u can refresh page</p>

<p>Any Problem with the order:Submit report to seller
Seller didn&#39;t fix problem within 5 hours.We will refund Buyer.
Buyer didn&#39;t reply within 24 hours after seller.We will Close report.
Note:avoid multi reply.
hxxps://olux.li
hxxps://oluxshop.li
t.me/oluxshopsite/729
edited  Sep 28 at 07:43
</p>

<p>cdn4.cdn-telegram.org/file/cff2fa7546.mp4 —&gt; not able to catch that one.</p>

<h2 id="ip-address-162-55-238-94">IP-address 162.55.238.94</h2>

<p>I first stumbled across a cryptofraud site on that IP.
But I also found sites on the same IP with hidden content.
One or more lines with the following content on one or more pages on the same domain, first example:
view-source:hxxps://www.bitwealthasset.com/ :
hxxps://www.oxo.si/&#39;&gt;Buy Spamming Tools, Shells, web shell, RDP, SSH, cPanel.
I don&#39;t know the value of this, some kind of “seo” maybe?
Other domains with the same or variations of the code:</p>

<p>bluerichfoods.com
bxplorer.online
tocpharmaceuticals.com
euphoriaeventplace.com (24 rows with the code)
abbasheartinternationalministries.com
abdanielstradomedhospital.com
caishencharteredtrust.com
capitalgrowinvest.com
capitecfin.com
cattyinvest.com
cheeckstox.com
educurrency.top</p>

<p>citricosartaca.com is apparently a blank page, but contains almost 40 lines, but with additional domains and keywords in the code.
Contains links to the following domains:
 oxo.vc (gone), oxo.si (127.0.0.1) and oxo.is (which celebrates christmas).
“Buy Leads”and “SMTP” has sneaked in some places in what “services” they seem to provide.</p>

<p>clarity-options-trade.com
climaxpaytrading.com
coinswalletsapp.com
commercial-trading.com
conexriseltd.com
crescent-funds.com
crownenergy-investment.com
cryptohive.online
cryptohubmine.com
cryptoinxhange.com
cryptotradinggai.com
bettercryptoinvestment.net
climatefitsolutions.com
educurrency.top (redirectet from chuksblog.top)
clarity-options-trade.com
climaxpaytrading.com
cloudminingcity.com
coinstitude.com
combdb.com
commercial-trading.com
corporateuniontrustbank.com
couttss.com
cryptnetverse.com
cryptoevolution.info
cryptohubmine.com
cryptoinxhange.com
cryptoref.info
cryptospotpro.online
daily-gt.com
dashtradefx.com
debulad.com
decentralisedincome.com
deroyaleservices.com
doubleyielders.com
empablockmarket.live
eqtycdf.com
euphoriaeventplace.com
expertminer.online
firstcornerstoneb.com
firstmidwsb.com
firstspringcu.online
flaretrustline.app
ftxdailyincome.com
fx-primetradhub.com
fxnetworktrading.com
getmypins.com/manage/
ggemfx.com
glimcoinfx.com
globalbestcutbutchers.com (in total 190 lines of code)
globalbinarycpro.com
globalprimefinance.com
globalsignalexpertmarkets.com
globewritershub.com
glockamory.com
gnbancorp.com
godfelhrconsultancy.com
goldenmovicltd.com
grandoption.org
grantbakingonline.com
greencoastonline.org
greenpathtb.com
greenpathtrust.com
gricunashr.com
hakkbully.com
hakkdomain.com
hakknocrat.com
haloinvestpro.com
hashmarketfx.com
heritagecapitalfx.com
heritagecf.net
heritagepvltd.com
hfplatform.live
hoardblockexplorer.info
hoardfx.com
hoperbookings.online
horizonjury.com
icbcsbnk.com
iconiccanna.com
trades.idealtradesignal.com
instaplug01.com
intconib.com
intertrustbk.com
itechglobehack.com
jkcostant.online
kathleencahillmariconda.com
kryptofxcore.com
legacycrf.com
legcreditf.com
liamfinancing.com
liteinterext.online
luminerybank.com
lumineryfb.com
luxorrtech.com
masterfxtrade.live
mauricugointernational.com
mectomfx.com
megafxoptions.com
midascryptotrade.com
milesassetltd.com
digitechcompany.cloud/en/public/ (redirects from minecoins.online)
moleystonescapitals.com
mycrypai.com
mypnconline.com
myviasupport.com
nationalcreditunion.online
niketradeprime.com
northcelly.com
northernsb.com
omegafinanceleasing.com
optimoser.com
optimuminternationalmarkets.com
ordezenterprise.com
peakhash.com
pinb.online
premier-option.com
primeglobalinvestments.live/home/
profxcrypto.com
prohakks.com
propertiesloans.com
prudcrb.comstockstradersfx.com
standardcorpb.com
stuartfellstaffordshirebullterriers.com
successfulfx.online
suisepay.com
surfhakks.com
swisslitebank.online
syngenresources.com
tcloudusdt.com
tescoinv.com
titantrustb.com (site copied from cnl.com, which was registered in 1995 and seems “legit”)
tnbancorp.com
tocpharmaceuticals.com (on a buttload of links on this domain)
tokssphere.com
tonensiadiamonds.com
top-m.online
topromedics.com
torchcart.com
trippydelics.store
tsbcadvisor.com
ualliancecrdu.com
ultimafxoption.com
ultimaterealistic.com
ultimatexplorer.info</p>

<p>ultrafxoption.com *
A bit interesting is that the code did not exist on ultrafxoption.com on November 30th 2022 according to urlscan.io.
But shows up in a scan in December 2023. Did all sites got this code injected in this timeframe? Can only speculate. Or use a lot of time trying to find out.</p>

<p>uniqueglobaloptions.com
vacationdepts.info
vertextradings.com
vitalityplc.online
waxiprofit.com
wcouservice.biz
web-gmd.com
westagefinance.com * According to urlscan this domain contained the code also on December 4th 2023
winnersviewoptioninvestment.org
wisgodynamic.com
wmovelogistics.com
wolf-trademarket.cfd
world-miners.com
wourld-cour.com
xiloans.com
xpressct.com
xtrafcb.com
xtrainterextcorp.com
xtrainterextfb.com
xtrainterextfcb.com
xtratreasury.com
ysmbundle.com
ziraatinternationalcorporation.com * According to urlscan this domain contained the code also on September 11th 2023</p>

<p>citricosartaca.com is apparently a blank page, but contains almost 40 lines, but with different additional domains and keywords in the code.
Contains links to the following domains:
 oxo.vc (gone), oxo.si (127.0.0.1) and oxo.is which celebrates christmas.
“Buy Leads”and “SMTP” has sneaked in some places in what “services” they provide.</p>

<p>Various search engines gives hits to other sites on the same IP, but the hidden stuff is now gone:
fujowillbusiness.com/sample-page/
wmtips.com/tools/info/sh3elltools.to
hxxps://www.hotelfontana.de/magazin/tag/ayurvedische-reinigungskur/
hxxps://albertfinni.com/gva_template/crowdfunding-single-template/</p>

<p>Some sites appear in searches, but are now gone:
lufix.pro, lufix.to, oluxshop.to</p>

<p>Domains, variatons of oluxshop.[tld]
oluxshop.to (127.0.0.1)</p>

<p>Domains, variatons of olux.[tld]
olux.to</p>

<p>ICQ:
hxxps://icq.im/oluxshop</p>

<p>A now apparent dead facebook account: hxxps://www.facebook.com/groups/buywebshell/
sh3elltools.to seems somwehat related.</p>
]]></content:encoded>
      <guid>https://infosec.press/ducks/the-olux-and-or-oxo-or-whatever-guys</guid>
      <pubDate>Fri, 22 Dec 2023 19:35:07 +0000</pubDate>
    </item>
    <item>
      <title>Some day</title>
      <link>https://infosec.press/ducks/some-day</link>
      <description>&lt;![CDATA[We&#39;ve thought about using WriteFreely for a blog some day.&#xA;Hosting/installing it myself is way out of our league.&#xA;So it was a pleasant surprise when we discovered that infosec had this possibility.&#xA;&#xA;But have always been slow and in addition age is now showing.&#xA;Working on a couple of drafts, perhaps they will be finished.&#xA;Some day.&#xA;&#xA;Introduction (kind of)&#xA;We prefer not to write too much here, maybe some day.&#xA;]]&gt;</description>
      <content:encoded><![CDATA[<p>We&#39;ve thought about using WriteFreely for a blog some day.
Hosting/installing it myself is way out of our league.
So it was a pleasant surprise when we discovered that infosec had this possibility.</p>

<p>But have always been slow and in addition age is now showing.
Working on a couple of drafts, perhaps they will be finished.
Some day.</p>

<h1 id="introduction-kind-of">Introduction (kind of)</h1>

<p>We prefer not to write too much here, maybe some day.</p>
]]></content:encoded>
      <guid>https://infosec.press/ducks/some-day</guid>
      <pubDate>Sun, 12 Mar 2023 18:32:03 +0000</pubDate>
    </item>
  </channel>
</rss>