Skip to content

Conversation

@g0d33p3rsec
Copy link
Contributor

add draschool[.]org to wildcard list

Phishing Domain/URL/IP(s):

https://draschool.org/M0YzWDRTNjM3VTMwN3M=
https://draschool.org/M2g1TjF0Mm0wbDNaMW8=

Impersonated domain

Describe the issue

This domain is now hosting the phishing kit that previously at craigbrimm[.]com(#480), albapietra[.]com[.]br(#479), yanisac[.]com(#478), sbic[.]com[.]br (#477), squad[.]cl(#473), benyex[.]cl (#468), lebomashilo[.]co[.]za (#462), havenhills[.]za[.]com (#459), intrinsicisle[.]za[.]com (#452), reluzformaturas[.]com[.]br (#435), abcmueblesbogota[.]com (#432), ergoterapiacaribu[.]ch (#426), ijconnects[.]com (#421), cbcaps[.]shop (#417), bersowir[.]org (#416), brunotasso[.]com[.]br (#413), wisbechguide[.]uk (#408), pescacancun[.]com (#406), bkengineersindia[.]com (#405), englishplusmore[.]com (#404), carnesboinobre[.]com[.]br (#398), technowide[.]com[.]tr (#396), jestertunes[.]com (#393), safecartusa[.]com (#391), foreverfarley[.]com (#387), azezieldraconous[.]com (#381), westernautomobileassembly[.]com (#376) , littleswanaircon[.]com[.]sg (#372), iwan2travel[.]com (#370), applesforfred[.]com (#369), theaerie[.]ca (#367), nico[.]sa (#366), ajstelecom[.]com[.]mx (#362), and many others.

I don't have screenshots for this one, but it has the same common indicator, uses Nuxt.js just like the others listed, and has the same pattern of HTTP requests.

Related external source

Screenshot

Click to expand

image
image
image

add draschool[.]org to wildcard list
@spirillen spirillen merged commit 7f7317a into Phishing-Database:main Sep 26, 2024
1 check passed
spirillen added a commit to mypdns/matrix that referenced this pull request Sep 26, 2024
@g0d33p3rsec g0d33p3rsec deleted the add-draschool.org-to-lsits branch October 1, 2024 15:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants