I BLOCK boosters of Auschwitz spam (reason: my grandfather was a Jew and Auschwitz was hijacked by Zionists incl. WestBank settler Dani Dayan; see https://todon.nl/@ErikvanStraten/115536032444852356). Independent 65+ Dutch security researcher. I hate injustice, propaganda and discrimination. I try to be as objective as possible. Mission: make the internet a safer place! Primary focus: #impersonation (i.e. when #authentication fails). Other: #Gaza #Ukraine #vaccination (last anti-Covid jab 20250916). Notes: • Don't auto-trust me. It may be a spoof, even if "I" say it's not (my account may be hacked). • Muting users of URL-shorteners (like buff.ly) • Now BLOCKING "Gazans" begging for money
Erik van Straten
@ErikvanStraten@todon.nl
todon.nl
Replying to
@ErikvanStraten@todon.nl
PHISHING - update 1/2
De volgende sites waren gisteravond nog live maar nu niet meer:
https:⧸⧸bunq.stakebet.live (IPv4: 216.203.20.170)
https:⧸⧸bunq.diaojj.com (achter Cloudflare)
Die laatste link laat Cloudflare testen of U wel betrouwbaar bent en meldt daarna een time-out met de feitelijke server.
Dezelfde groep cybercriminelen zit kennelijk nog niet achter de tralies, de volgende phishingsites waren zojuist nog live, op de volgende na - die nog niet of niet meer live is:
https:⧸⧸knab.stakebet.live (dit subdomein achter Cloudflare)
In de volgende toot screenshots met domeinnamen van "doorstuursites".
P.S. druk op een plaatje om te vergroten.
#Phishing #Odido #OdidoDataLek #knab #bunq #KvK #BitVavo #knabPhishing #bunqPhishing #KvKPhishing #BitVavoPhishing #Cloudflare #CloudflareIsEvil #CloudflareIsCrimineel
Erik van Straten
@ErikvanStraten@todon.nl
I BLOCK boosters of Auschwitz spam (reason: my grandfather was a Jew and Auschwitz was hijacked by Zionists incl. WestBank settler Dani Dayan; see https://todon.nl/@ErikvanStraten/115536032444852356). Independent 65+ Dutch security researcher. I hate injustice, propaganda and discrimination. I try to be as objective as possible. Mission: make the internet a safer place! Primary focus: #impersonation (i.e. when #authentication fails). Other: #Gaza #Ukraine #vaccination (last anti-Covid jab 20250916). Notes: • Don't auto-trust me. It may be a spoof, even if "I" say it's not (my account may be hacked). • Muting users of URL-shorteners (like buff.ly) • Now BLOCKING "Gazans" begging for money
todon.nl
Replying to
@ErikvanStraten@todon.nl
CLOUDFLARE IS EVIL
De volgende websites sturen uw browser op dit moment door naar de volgende Bitvavo phishingsite (zoals zovele nepsites, verstopt ook deze zich achter Cloudflare):
https:⧸⧸digitaalformulier.im/two.html (zie screenshot)
Al die doorstuursites zijn te zien in het RELATIONS tabblad van https://www.virustotal.com/gui/ip-address/185.68.93.129
https:⧸⧸[www.]ramey-photography.com
https:⧸⧸[www.]therapeutix.com
https:⧸⧸[www.]bidonalbany.com
https:⧸⧸[www.]kkbrocks.com
https:⧸⧸[www.]bidonmacon.com
https:⧸⧸[www.]cheqpaq.com
https:⧸⧸[www.]isimgt.com
https:⧸⧸[www.]247.co.il
https:⧸⧸[www.]cbc-restaurant-corp.com
https:⧸⧸[www.]islandnight.org
Nb. ik heb "https:⧸⧸" i.p.v. "https://" gebruikt om onbedoeld openen door u te voorkómen. Met "[www.] voorafgaand aan de domeinnaam bedoel ik dat ook die variant doorstuurt naar de Bitvavo phishingsite.
Scammers gebruiken meerdere en steeds nieuwe doorstuursites om te voorkómen dat spamfilters hun phishinge-mails blokkeren.
#CloudflareIsEvil #Phishing #CyberCrime #Bitvavo #BitvavoPhising #Odido #OdidoDataLek
You've seen all posts