#scam β Public Fediverse posts
Live and recent posts from across the Fediverse tagged #scam, aggregated by home.social.
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: rustgrade[.]com[.]ru
π Analysis at: https://phishdestroy.io/domain/rustgrade.com.ru/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: rustgrade[.]com[.]ru
π Analysis at: https://phishdestroy.io/domain/rustgrade.com.ru/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: dpln-tutoriel[.]com
π Analysis at: https://phishdestroy.io/domain/dpln-tutoriel.com/#NFT #SecureYourWallet #malware #scam #BlockchainFraud #scamalert
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: dpln-tutoriel[.]com
π Analysis at: https://phishdestroy.io/domain/dpln-tutoriel.com/#NFT #SecureYourWallet #malware #scam #BlockchainFraud #scamalert
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: claim-st[.]netlify[.]app
π Analysis at: https://phishdestroy.io/domain/claim-st.netlify.app/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: claim-st[.]netlify[.]app
π Analysis at: https://phishdestroy.io/domain/claim-st.netlify.app/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: samratitinstitute[.]com
π Analysis at: https://phishdestroy.io/domain/samratitinstitute.com/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: samratitinstitute[.]com
π Analysis at: https://phishdestroy.io/domain/samratitinstitute.com/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: aneesurrehmandm[.]github[.]io
π Analysis at: https://phishdestroy.io/domain/aneesurrehmandm.github.io/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: aneesurrehmandm[.]github[.]io
π Analysis at: https://phishdestroy.io/domain/aneesurrehmandm.github.io/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: xmailinctrrses[.]weebly[.]com
π Analysis at: https://phishdestroy.io/domain/xmailinctrrses.weebly.com/#BlockchainFraud #scam #CryptoDrainers #malware #PhishingWarning #CryptoThreats
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: xmailinctrrses[.]weebly[.]com
π Analysis at: https://phishdestroy.io/domain/xmailinctrrses.weebly.com/#BlockchainFraud #scam #CryptoDrainers #malware #PhishingWarning #CryptoThreats
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: ledger-help-io[.]square[.]site
π Analysis at: https://phishdestroy.io/domain/ledger-help-io.square.site/#scam #ProtectCrypto #SecureYourWallet #WalletHackers #Web3Security #WalletDrainers
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: ledger-help-io[.]square[.]site
π Analysis at: https://phishdestroy.io/domain/ledger-help-io.square.site/#scam #ProtectCrypto #SecureYourWallet #WalletHackers #Web3Security #WalletDrainers
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: tkshp[.]dyincihna[.]com
π Analysis at: https://phishdestroy.io/domain/tkshp.dyincihna.com/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: tkshp[.]dyincihna[.]com
π Analysis at: https://phishdestroy.io/domain/tkshp.dyincihna.com/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: registrer-user[.]com
π Analysis at: https://phishdestroy.io/domain/registrer-user.com/#AntiPhishing #ProtectCrypto #Web3Awareness #cybersec #scam #ScamPrevention
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: registrer-user[.]com
π Analysis at: https://phishdestroy.io/domain/registrer-user.com/#AntiPhishing #ProtectCrypto #Web3Awareness #cybersec #scam #ScamPrevention
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: verlineasiguiente2026[.]iceiy[.]com
π Analysis at: https://phishdestroy.io/domain/verlineasiguiente2026.iceiy.com/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: verlineasiguiente2026[.]iceiy[.]com
π Analysis at: https://phishdestroy.io/domain/verlineasiguiente2026.iceiy.com/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: dstat[.]vc
π Analysis at: https://phishdestroy.io/domain/dstat.vc/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: dstat[.]vc
π Analysis at: https://phishdestroy.io/domain/dstat.vc/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: rroblox[.]wf
π Analysis at: https://phishdestroy.io/domain/rroblox.wf/#scam #ScamPrevention #SecureYourWallet #PhishingWarning #ProtectCrypto #malware
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: rroblox[.]wf
π Analysis at: https://phishdestroy.io/domain/rroblox.wf/#scam #ScamPrevention #SecureYourWallet #PhishingWarning #ProtectCrypto #malware
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: web3eoxdus[.]zapier[.]app
π Analysis at: https://phishdestroy.io/domain/web3eoxdus.zapier.app/#scam #ScamDetection #CyberFraud #PhishingScam #Web3Awareness #cybersec #FraudDetection
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: web3eoxdus[.]zapier[.]app
π Analysis at: https://phishdestroy.io/domain/web3eoxdus.zapier.app/#scam #ScamDetection #CyberFraud #PhishingScam #Web3Awareness #cybersec #FraudDetection
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: inemssgecert10c06[.]wasmer[.]app
π Analysis at: https://phishdestroy.io/domain/inemssgecert10c06.wasmer.app/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: inemssgecert10c06[.]wasmer[.]app
π Analysis at: https://phishdestroy.io/domain/inemssgecert10c06.wasmer.app/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: s[.]teams-tc[.]com
π Analysis at: https://phishdestroy.io/domain/s.teams-tc.com/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: s[.]teams-tc[.]com
π Analysis at: https://phishdestroy.io/domain/s.teams-tc.com/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: ertomaincertewhj89[.]wasmer[.]app
π Analysis at: https://phishdestroy.io/domain/ertomaincertewhj89.wasmer.app/#CryptoAwareness #ProtectCrypto #scam #CryptoThreats #PhishingWarning
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: ertomaincertewhj89[.]wasmer[.]app
π Analysis at: https://phishdestroy.io/domain/ertomaincertewhj89.wasmer.app/#CryptoAwareness #ProtectCrypto #scam #CryptoThreats #PhishingWarning
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: cryptostresser[.]org
π Analysis at: https://phishdestroy.io/domain/cryptostresser.org/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: cryptostresser[.]org
π Analysis at: https://phishdestroy.io/domain/cryptostresser.org/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: stresserr[.]online
π Analysis at: https://phishdestroy.io/domain/stresserr.online/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: stresserr[.]online
π Analysis at: https://phishdestroy.io/domain/stresserr.online/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: authorizecvv[.]pro
π Analysis at: https://phishdestroy.io/domain/authorizecvv.pro/#scam #WalletDrainers #CryptoAwareness #ProtectCrypto #SecureYourWallet
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: authorizecvv[.]pro
π Analysis at: https://phishdestroy.io/domain/authorizecvv.pro/#scam #WalletDrainers #CryptoAwareness #ProtectCrypto #SecureYourWallet
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: www[.]stresser[.]es
π Analysis at: https://phishdestroy.io/domain/www.stresser.es/#CyberFraud #malware #CryptoAwareness #scam #WalletSecurity #ScamPrevention
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: www[.]stresser[.]es
π Analysis at: https://phishdestroy.io/domain/www.stresser.es/#CyberFraud #malware #CryptoAwareness #scam #WalletSecurity #ScamPrevention
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: dstat[.]xyz
π Analysis at: https://phishdestroy.io/domain/dstat.xyz/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: dstat[.]xyz
π Analysis at: https://phishdestroy.io/domain/dstat.xyz/ -
π¨ PHISHING DETECTED π¨
π Suspicious URL: www[.]cregis[.]com
π Analysis at: https://phishdestroy.io/domain/www.cregis.com/#CryptoAwareness #CyberFraud #SecureYourWallet #CryptoDrainers #Web3Awareness #scam
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: www[.]cregis[.]com
π Analysis at: https://phishdestroy.io/domain/www.cregis.com/#CryptoAwareness #CyberFraud #SecureYourWallet #CryptoDrainers #Web3Awareness #scam
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: livepump[.]solstream[.]cc
π Analysis at: https://phishdestroy.io/domain/livepump.solstream.cc/#cybersec #ProtectCrypto #CryptoHacking #Web3Hacking #ScamDetection #scam #AntiPhishing
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: livepump[.]solstream[.]cc
π Analysis at: https://phishdestroy.io/domain/livepump.solstream.cc/#cybersec #ProtectCrypto #CryptoHacking #Web3Hacking #ScamDetection #scam #AntiPhishing
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: www[.]evmentry[.]com
π Analysis at: https://phishdestroy.io/domain/www.evmentry.com/#ScamDetection #ProtectCrypto #scam #CryptoProtection #WalletSecurity
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: www[.]evmentry[.]com
π Analysis at: https://phishdestroy.io/domain/www.evmentry.com/#ScamDetection #ProtectCrypto #scam #CryptoProtection #WalletSecurity
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: 518869-binance[.]com
π Analysis at: https://phishdestroy.io/domain/518869-binance.com/#scam #cybersec #CryptoDrainers #PhishingScam #CryptoProtection
-
π¨ PHISHING DETECTED π¨
π Suspicious URL: 518869-binance[.]com
π Analysis at: https://phishdestroy.io/domain/518869-binance.com/#scam #cybersec #CryptoDrainers #PhishingScam #CryptoProtection
-
Three actors. Zero sites compromised. Thousands of victims inherited.
In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.
Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.
βοΈ Sample IOCs:
Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]comFull indicators on GitHub. https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #phishing
-
Three actors. Zero sites compromised. Thousands of victims inherited.
In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.
Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.
βοΈ Sample IOCs:
Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]comFull indicators on GitHub. https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #phishing
-
Three actors. Zero sites compromised. Thousands of victims inherited.
In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.
Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.
βοΈ Sample IOCs:
Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]comFull indicators on GitHub. https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #phishing
-
"Pig-butchering scams involve engaging unsuspecting people online, cultivating trust, and persuading victims to invest, often in fraudulent cryptocurrency schemes that may use fake websites designed to resemble legitimate trading platforms and sometimes provide apparent initial returns to create a false sense of legitimacy."
tl;dr that new person you met online might be something terrible.
I've had 3 friends fall victim to this scam.
-
"Pig-butchering scams involve engaging unsuspecting people online, cultivating trust, and persuading victims to invest, often in fraudulent cryptocurrency schemes that may use fake websites designed to resemble legitimate trading platforms and sometimes provide apparent initial returns to create a false sense of legitimacy."
tl;dr that new person you met online might be something terrible.
I've had 3 friends fall victim to this scam.
-
"Pig-butchering scams involve engaging unsuspecting people online, cultivating trust, and persuading victims to invest, often in fraudulent cryptocurrency schemes that may use fake websites designed to resemble legitimate trading platforms and sometimes provide apparent initial returns to create a false sense of legitimacy."
tl;dr that new person you met online might be something terrible.
I've had 3 friends fall victim to this scam.
-
π§ π«΄ Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over πΈ $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.
Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an β£οΈ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.
We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.
Read the full teardown here: https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/
Some Sable Squirrel dropcatch domains:
thebreastcancercharities[.]org
andromda[.]org
d-rev[.]org
churchofreality[.]org
swradioafrica[.]com
americansecuritytoday[.]com
2026worldcupnorthamerica[.]com
poweredbyclear[.]com
fora[.]tv#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink
-
π§ π«΄ Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over πΈ $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.
Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an β£οΈ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.
We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.
Read the full teardown here: https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/
Some Sable Squirrel dropcatch domains:
thebreastcancercharities[.]org
andromda[.]org
d-rev[.]org
churchofreality[.]org
swradioafrica[.]com
americansecuritytoday[.]com
2026worldcupnorthamerica[.]com
poweredbyclear[.]com
fora[.]tv#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink
-
π§ π«΄ Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over πΈ $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.
Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an β£οΈ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.
We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.
Read the full teardown here: https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/
Some Sable Squirrel dropcatch domains:
thebreastcancercharities[.]org
andromda[.]org
d-rev[.]org
churchofreality[.]org
swradioafrica[.]com
americansecuritytoday[.]com
2026worldcupnorthamerica[.]com
poweredbyclear[.]com
fora[.]tv#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink
-
How Scammers Built an Investment Scam Network Using Maliciously Registered Domain Names
Andy Malis shares an investigation by Whalebone into a scam that used fake news stories to draw victims to a fake investment platform. He explains how the scammers used maliciously registered and deceptively composed domain names and both brand and personality impersonation to make the scam convincing and safe.
This is that one occasion where you should pay attention to a "fake news" claim.
https://interisle.substack.com/p/how-scammers-built-an-investment