Threat Level: green Handler on Duty: Rick Wanner

SANS ISC: Internet Storm Center - SANS Internet Storm Center Internet Storm Center


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Latest Diaries

Paypal Phishing landing pages hosted at HostGator

Published: 2016-03-06
Last Updated: 2016-03-06 19:34:10 UTC
by Rick Wanner (Version: 1)
0 comment(s)

It appears that a large number of websites, approximately 500, hosted on IP 192.185.225.116 are being used as PayPal Phishing landing pages.  That IP is registered to websitewelcome.com, but we have been told by customers that the IP is in use by popular U.S. based web hosting company HostGator.

When the FQDN of a legitimate web page on that IP is appended with:

~pbhanney/goobooker/avatars/user_uploaded/manage/ffe02d0542523d2fca9d479a2b50a948/

for example 

hxxp://24efitness.com/~pbhanney/goobooker/avatars/user_uploaded/manage/ffe02d0542523d2fca9d479a2b50a948/

will take you to a PayPal login landing page.

Google seems to be aware of the issue and is warning on attempts to access the pages.

The issue has been reported to both HostGator and Paypal, so hopefully they can get it clean up soon.

-- Rick Wanner MSISE - rwanner at isc dot sans dot edu - http://namedeplume.blogspot.com/ - Twitter:namedeplume (Protected)

Keywords:
0 comment(s)

If you have more information or corrections regarding our diary, please share.

Recent Diaries

Angler EK campaign targeting several .co domains deploying teslacrypt 3.0 malware
1 day ago by Manuel Humberto Santander Pelaacuteez (1 comment)

Cisco Security Advisory: Default Credentials
4 days ago by tony (2 comments)

Exploit o' the day: DROWN
4 days ago by tony (4 comments)

OpenSSL Update Released
5 days ago by Dr. J. (0 comments)

Quick Analysis of a Recent MySQL Exploit
6 days ago by Dr. J. (1 comment)

RFC 6598 - Carrier Grade NAT
1 week ago by Guy (0 comments)

View All Diaries →

Latest Discussions

iOS 9.2.1 Siri Lock screen bug returns?
created 5 days ago by Jubs (0 replies)

File Integrity Monitoring (FIM) -
created 5 days ago by ItsMe (0 replies)

Win10 knowledge anyone?
created 1 week ago by Teemu (2 replies)

Asset Management (Inventory of Assets)
created 1 week ago by Anonymous (0 replies)

STUN traffic
created 1 week ago by Teemu (0 replies)

View All Forums →

Latest News

View All News →

Top Diaries

Critical Cisco ASA IKEv1/v2 Vulnerability. Active Scanning Detected
3 weeks ago by Dr. J. (24 comments)

CVE-2015-7547: Critical Vulnerability in glibc getaddrinfo
2 weeks ago by Dr. J. (9 comments)

Angler exploit kit generated by "admedia" gates
2 weeks ago by Brad (5 comments)

Critical Vulnerabilities in Palo Alto Networks PAN-OS
1 week ago by Dr. J. (1 comment)

December 2015 Microsoft Patch Tuesday
2 months ago by Dr. J. (19 comments)