Click to jump to signature section
Source: http://jaz.wxk.mybluehost.me/ch/104c5 | Avira URL Cloud: detection malicious, Label: phishing |
Source: http://jaz.wxk.mybluehost.me/ch/104c5 | SlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering |
Source: http://jaz.wxk.mybluehost.me/ch/104c5/css/sso.min-20200819.css | Avira URL Cloud: Label: phishing |
Source: http://jaz.wxk.mybluehost.me/ch/104c5 | Virustotal: Detection: 14% | Perma Link |
Source: http://jaz.wxk.mybluehost.me/ch/104c5/ | LLM: Score: 9 brands: SwissPass Reasons: The URL 'http://jaz.wxk.mybluehost.me/ch/104c5/' does not match the legitimate domain for SwissPass, which should be something like 'swisspass.ch'. The use of a subdomain on 'mybluehost.me' is highly suspicious and often used in phishing attacks. The page contains a login form, which is a common target for phishing. The overall design mimics the legitimate SwissPass branding, which is a social engineering technique to deceive users. DOM: 0.0.pages.csv |
Source: http://mybluehost.me | Matcher: Template: swisspass matched with high similarity |
Source: http://jaz.wxk.mybluehost.me/ch/104c5/ | Matcher: Template: swisspass matched with high similarity |
Source: http://jaz.wxk.mybluehost.me/ch/104c5/ | Matcher: Found strong image similarity, brand: SWISSPASS |
Source: http://jaz.wxk.mybluehost.me/ch/104c5/ | Matcher: Template: swisspass matched |
Source: http://jaz.wxk.mybluehost.me/ch/104c5/ | HTTP Parser: Number of links: 0 |
Source: https://custommapposter.com/ | HTTP Parser: Total embedded image size: 10944 |
Source: http://jaz.wxk.mybluehost.me/ch/104c5/ | HTTP Parser: Title: Login | SwissPass does not match URL |
Source: http://jaz.wxk.mybluehost.me/ch/104c5/ | HTTP Parser: Has password / email / username input fields |
Source: http://jaz.wxk.mybluehost.me/ch/104c5/ | HTTP Parser: Form action: ./send1.php |
Source: http://jaz.wxk.mybluehost.me/ch/104c5/ | HTTP Parser: <input type="password" .../> found |
Source: https://custommapposter.com/article/top/926 | HTTP Parser: No favicon |
Source: https://custommapposter.com/article/top/926 | HTTP Parser: No favicon |
Source: https://custommapposter.com/article/top/926 | HTTP Parser: No favicon |
Source: https://custommapposter.com/article/top/926 | HTTP Parser: No favicon |
Source: https://custommapposter.com/article/top/926 | HTTP Parser: No favicon |
Source: about:blank | HTTP Parser: No favicon |
Source: https://app.grow.me/iframe-login?siteId=U2l0ZTo3NTI4MzhlYS05MGI4LTRiMGMtYTQyNC0wNzI3YWJiMGIyMGI%3D&callback=https%3A%2F%2Fcustommapposter.com%2Farticle%2Ftop%2F926 | HTTP Parser: No favicon |
Source: https://ads.pubmatic.com/AdServer/js/user_sync.html?kdntuid=1&p=156972 | HTTP Parser: No favicon |
Source: https://cs.seedtag.com/cs.html?pt=5261-2296-01&pc=US | HTTP Parser: No favicon |
Source: https://www.swisspass.ch//pw-reset?lang=de&provider=sbbkn&callback=oevloginhttps://www.swisspass.ch//register?lang=de&provider=sbbkn&callback=oevlogin | HTTP Parser: No favicon |
Source: https://www.swisspass.ch//pw-reset?lang=de&provider=sbbkn&callback=oevloginhttps://www.swisspass.ch//register?lang=de&provider=sbbkn&callback=oevlogin | HTTP Parser: No favicon |
Source: https://ssbsync.smartadserver.com/api/sync?callerId=22&gdpr=0&gdpr_consent= | HTTP Parser: No favicon |
Source: https://simage2.pubmatic.com/AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTc4JnRsPTE1NzY4MDA=&piggybackCookie=6403784576581203868&gdpr=0&gdpr_consent= | HTTP Parser: No favicon |
Source: https://image2.pubmatic.com/AdServer/Pug?gdpr=0&vcode=bz0yJnR5cGU9MSZjb2RlPTExMTMmdGw9NDMyMDA=&piggybackCookie=n_N2CJ_yIwmE8yBcyKNvWZr2cFKE_HENkKNZrxvU | HTTP Parser: No favicon |
Source: https://eus.rubiconproject.com/usync.html | HTTP Parser: No favicon |
Source: https://visitor.omnitagjs.com/visitor/isync?uid=513c4e190506981c315d38ccadf488f2&name=SEEDTAG&visitor=&gdpr=0&gdpr_consent_string=&us_privacy= | HTTP Parser: No favicon |
Source: https://ads.pubmatic.com/AdServer/js/user_sync.html?p=157743&gdpr=0&gdpr_consent=&us_privacy=&predirect=https%3A%2F%2Fs.seedtag.com%2Fcs%2Fcookiesync%2Fpubmatic%3Fchanneluid%3D | HTTP Parser: No favicon |
Source: https://ads.pubmatic.com/AdServer/js/user_sync.html?p=157743&gdpr=0&gdpr_consent=&us_privacy=&predirect=https%3A%2F%2Fs.seedtag.com%2Fcs%2Fcookiesync%2Fpubmatic%3Fchanneluid%3D | HTTP Parser: No favicon |
Source: https://ads.pubmatic.com/AdServer/js/user_sync.html?p=157743&gdpr=0&gdpr_consent=&us_privacy=&predirect=https%3A%2F%2Fs.seedtag.com%2Fcs%2Fcookiesync%2Fpubmatic%3Fchanneluid%3D | HTTP Parser: No favicon |
Source: https://d5p.de17a.com/getuid/pubmatic?https://image2.pubmatic.com/AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTI3NDUmdGw9MTI5NjAw&gdpr=0&gdpr_consent=&piggybackCookie=$UID | HTTP Parser: No favicon |
Source: https://ipac.ctnsnet.com/int/cm?exc=14&redir=https://simage2.pubmatic.com/AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTM0MTEmdGw9MjAxNjA=&piggybackCookie=[user_id] | HTTP Parser: No favicon |
Source: https://image2.pubmatic.com/AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTM0ODkmdGw9NDMyMDA=&piggybackCookie=OPU0580edc5dbac4778bfc19398f495dfb8 | HTTP Parser: No favicon |
Source: https://image2.pubmatic.com/AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTI3MzkmdGw9MTI5NjAw&piggybackCookie=5140084931246551630 | HTTP Parser: No favicon |
Source: https://hde.tynt.com/deb/?m=xch&rt=html&id=0015a00003HljHyAAJ&ru=https%3A%2F%2Fvisitor.omnitagjs.com%2Fvisitor%2Fsync%3Fname%3D33ACROSS%26ttl%3D720%26uid%3D2f9442d7df2189f76c8b593d5f54ce95%26visitor%3D33XUSERID33X%26gdpr%3D0%26gdpr_consent%3D&gdpr=0&gdpr_consent=&b=1 | HTTP Parser: No favicon |
Source: https://core.iprom.net/cookiesync?gdpr=0&gdpr_consent= | HTTP Parser: No favicon |
Source: https://s.tribalfusion.com/z/i.match?p=b11&redirect=https%3A//simage2.pubmatic.com/AdServer/Pug%3Fvcode%3Dbz0yJnR5cGU9MSZjb2RlPTMzMjYmdGw9MTI5NjAw%26piggybackCookie%3D%24TF_USER_ID_ENC%24&u=${PUBMATIC_UID} | HTTP Parser: No favicon |
Source: https://c1.adform.net/serving/cookie/match?CC=1&party=14&cid=9C64CA21-50AD-44D1-9AA7-4F2BA46D171B&gdpr=0&gdpr_consent= | HTTP Parser: No favicon |
Source: https://resources.infolinks.com/static/container-4.0.html | HTTP Parser: No favicon |
Source: https://image2.pubmatic.com/AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTI4ODQmdGw9MTI5NjAw&piggybackCookie=tk2EoAPtRYYTTaXUhTWRTahX&gdpr=0&gdpr_consent= | HTTP Parser: No favicon |
Source: https://router.infolinks.com/usync/manage?pid=3245929&wsid=0&pdom=custommapposter.com&purl=https%3A%2F%2Fcustommapposter.com%2Farticle%2Ftop%2F926 | HTTP Parser: No favicon |
Source: https://simage2.pubmatic.com/AdServer/Pug?vcode=bz0yJnR5cGU9MSZjb2RlPTMyMDMmdGw9NDMyMDA=&piggybackCookie=RX-8049d3ed-2f50-405b-8cd5-dc9be6476848-003 | HTTP Parser: No favicon |
Source: https://de.tynt.com/deb/?m=xch&rt=html&sid=0010b00002CpYhEAAV | HTTP Parser: No favicon |
Source: https://onetag-sys.com/usync/?pubId=598ce3ddaee8c90 | HTTP Parser: No favicon |
Source: https://ssum-sec.casalemedia.com/usermatch?cb=https%3A%2F%2Frouter.infolinks.com%2Fdyn%2Fix-usync%3Fuid%3D&s=191306&C=1 | HTTP Parser: No favicon |
Source: unknown | HTTPS traffic detected: 23.206.229.209:443 -> 192.168.2.9:49740 version: TLS 1.0 |
Source: unknown | HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.9:49725 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.9:49728 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 64.74.236.223:443 -> 192.168.2.9:50316 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 46.228.174.117:443 -> 192.168.2.9:50301 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 91.228.74.244:443 -> 192.168.2.9:50412 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 52.31.50.141:443 -> 192.168.2.9:50547 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.66.42.247:443 -> 192.168.2.9:50801 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 34.251.30.134:443 -> 192.168.2.9:50995 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 185.89.210.46:443 -> 192.168.2.9:51119 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 185.89.210.82:443 -> 192.168.2.9:51239 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 54.171.119.95:443 -> 192.168.2.9:51316 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 99.80.73.249:443 -> 192.168.2.9:51448 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 68.67.179.153:443 -> 192.168.2.9:51512 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 35.214.149.91:443 -> 192.168.2.9:52104 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 46.228.174.117:443 -> 192.168.2.9:52263 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 185.89.210.122:443 -> 192.168.2.9:52531 version: TLS 1.2 |
Source: unknown | Network traffic detected: IP country count 10 |
Source: global traffic | TCP traffic: 192.168.2.9:52685 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.9:50673 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.9:50278 -> 1.1.1.1:53 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | HTTP traffic: Redirect from: corporatedefenseetl.com to https://custommapposter.com/article/top/926 |
Source: global traffic | DNS traffic detected: number of DNS queries: 255 |
Source: unknown | HTTPS traffic detected: 23.206.229.209:443 -> 192.168.2.9:49740 version: TLS 1.0 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.11 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.11 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.229.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.229.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.11 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.229.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.11 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.11 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.11 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.229.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.229.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.229.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.229.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.11 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.229.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.229.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.229.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.229.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.229.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.229.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.206.229.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 21 May 2024 09:21:11 GMTServer: nginx/1.21.6Content-Type: text/htmlContent-Length: 14645Last-Modified: Mon, 20 May 2024 19:35:18 GMTCache-Control: max-age=7200Expires: Tue, 21 May 2024 09:40:05 GMTVary: Accept-EncodingContent-Encoding: gziphost-header: c2hhcmVkLmJsdWVob3N0LmNvbQ==X-Newfold-Cache-Level: 2X-Server-Cache: trueX-Proxy-Cache: HITAccept-Ranges: bytesData Raw: 1f 8b 08 00 00 00 00 00 00 03 e5 72 d9 76 dc 46 b2 ed f3 f5 5a fe 87 74 c9 36 c9 36 b3 26 0e 92 4a a4 ba 35 da 74 8b 92 6c 49 76 db 3e be 5c 09 64 00 48 56 22 13 ce 4c d4 40 5b 7f 73 be e1 3c f9 cd 3f 76 03 a8 81 35 24 8a ac 22 a5 ee b3 2e ca 16 81 88 1d 11 3b 76 ec a3 cf 9e be 7a f2 f6 a7 d7 cf 48 e2 52 f9 f0 d3 4f 8e 8a bf 24 94 cc da e3 da b9 25 4a 53 a7 f3 30 21 09 b3 49 98 30 15 03 49 84 75 da 0c 49 68 ad 33 4c d9 48 9b d4 ce 7f ed f1 e9 b7 70 42 2b 4b 6c 2f 26 42 49 a1 a0 78 c3 ff 43 29 b2 8c b9 c4 92 4c b2 10 12 2d 39 18 92 6a fc 57 d5 08 17 e6 b8 26 9d a9 11 89 33 8f 6b 1c 68 98 d4 88 75 43 09 c7 b5 1a 32 25 f8 1c 25 c0 f8 f8 bd fc 4e c1 31 5c c5 65 14 7e cb 45 ef b8 f6 44 2b 07 ca d1 b7 c3 0c 6a 24 1c 7d 1d d7 1c 0c 5c a3 58 f5 01 c1 a5 8c 05 77 fc ee ed 73 7a af 36 db cc 09 27 e1 e1 0b 1d 0b 45 fe 20 6f fa c2 da d7 a8 cb 51 63 94 58 1c 3b 6d 7e f2 ec 18 78 0c bb d8 da e8 14 8e 5b b5 39 4a ff a2 ef 1e d1 27 3a c5 e5 45 20 a1 56 dd 08 c5 0f 59 98 60 27 7c 2b 34 c7 b7 34 b7 8e 1a e8 31 29 38 73 30 df fa 49 81 a6 c5 ce 46 cb 6b 34 9e af 7e 6d 58 9c b2 15 65 cd 79 fc b3 41 26 0c d8 15 05 7d c1 5d 72 cc a1 27 42 a0 e5 c7 2e 9a 00 1d c1 24 b5 21 c3 53 b6 ea 4d dc 89 0d 44 9a a7 97 a1 1a 51 0c 85 ab f5 04 f4 33 6d dc 8a 11 1c 26 e0 71 88 16 86 c9 59 bc 4a d8 a7 e8 b4 e9 3d 09 da 99 14 de 7b 13 26 f2 af 3f ad 05 49 a2 bf fe 34 e4 24 31 40 4e 75 20 a4 70 7f fd b7 eb 90 e7 12 06 22 00 b9 4b 72 c5 82 e4 af ff 56 b1 88 f1 9d 93 9e 96 12 3b fc 80 5c 41 48 a8 4f 38 71 b0 a1 11 99 13 5a ad a0 23 0b 8b ed 5e 32 da 25 2c d0 e5 3f 4a 41 8a 90 5d 12 b3 5d 92 30 19 38 36 d8 25 01 4b 10 7e 91 c7 bb e4 af ff 89 22 50 52 e0 31 0d e9 81 e9 42 62 76 2f 5f fe fa 9f de 84 4a 17 86 7d 6d f8 aa 73 bd 79 fc 98 3c 79 fe 9c 3c 7f fe 66 52 c5 72 97 68 b3 5e 4d 96 07 52 58 24 b4 5e 59 a8 b3 a1 11 71 b2 ea da de b2 34 63 6a b8 a2 e8 45 21 2f f9 e3 52 df 29 51 74 09 75 3a 13 e1 8a ea 36 e1 6c 38 2d 31 e8 65 2b 1c 65 91 5b b9 9f 50 1c 06 d3 22 1d 68 b7 4a 78 0f c3 cc e8 0c 8c 1b 1e d7 74 dc 71 c2 c9 7f b3 9f e7 f8 5c cf d6 89 73 99 ed 34 1a fd 7e bf 6e 0b 76 19 b |