mitchellkrogza/phishing

Phishing Server IPS

Opened this issue · 5 comments

Domain/URL/IP(s) where you have found the Phishing

188.34.139.235
23.99.65.85
20.94.249.183
52.170.83.27
188.34.139.235
51.116.134.73
104.46.14.154
20.52.2.74
20.109.185.93
20.115.152.112

Related external source

No response

Describe the issue

There are several server IP addresses opened for phishing purposes. Can you blacklist them?

Screenshot

Click to expand

download

Sure, if you provide evidence for each ip and information to reproduce (Confirmation) as adding a IP to a phishing is a devastating thing to do against a IP address and the common trust to that IP-range.

Sure, if you provide evidence for each ip and information to reproduce (Confirmation) as adding a IP to a phishing is a devastating thing to do against a IP address and the common trust to that IP-range.

Sure. Look here: https://www.shodan.io/search?query=http.title%3A%22telif%22&page=2

"telif" or "telif hakki" in english "copyright" I searched with this keyword and scanned the results with spiderfoot. You can also verify

Also, as I added visually, all IP addresses contain the same image when visited

Maybe it is netter you post a screenshot...

image

Only half of the IPs seems active

Subject Status Source Expiration Date Registrar HTTP Code Checker


188.34.139.235 ACTIVE DNSLOOKUP Unknown Unknown Unknown AVAILABILITY
52.170.83.27 ACTIVE HTTP CODE Unknown Unknown 200 AVAILABILITY
188.34.139.235 ACTIVE DNSLOOKUP Unknown Unknown Unknown AVAILABILITY
23.99.65.85 INACTIVE STDLOOKUP Unknown Unknown Unknown AVAILABILITY
104.46.14.154 INACTIVE STDLOOKUP Unknown Unknown Unknown AVAILABILITY
51.116.134.73 INACTIVE STDLOOKUP Unknown Unknown Unknown AVAILABILITY