neurovagrant,
@neurovagrant@masto.deoan.org avatar

Seeing a handful of newly registered domains with VMware-impersonating landing pages.

Registrar: Gname
IP: CloudFlare
NS: share-dns[.]com
First observed: 2024-04-24

Landing page impersonating vmware:
gl-vmwareopts[.]com
vmwarewebs[.]com
gl-vmwarewebs[.]com

Same domain profile, currently 404's:
vmwareopts[.]com

neurovagrant,
@neurovagrant@masto.deoan.org avatar

Looking at my favorite pet peeves, IDN homoglyph domains, it appears actors are targeting procurement SaaS procurify[.]com from Russian IPs, example:

xn--procurfy-h2a[.]com

which in most contexts displays as:

procurífy[.]com

(note the diacritical mark over the i)

Interestingly, the IP hosts several other sites targeting Brunei and Dubai.

neurovagrant,
@neurovagrant@masto.deoan.org avatar

oop, broke the thread. continues here:

https://masto.deoan.org/@neurovagrant/112355182220822719

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • kavyap
  • tacticalgear
  • Durango
  • DreamBathrooms
  • mdbf
  • magazineikmin
  • thenastyranch
  • Youngstown
  • khanakhh
  • slotface
  • vwfavf
  • everett
  • rosin
  • osvaldo12
  • provamag3
  • modclub
  • GTA5RPClips
  • ethstaker
  • InstantRegret
  • cisconetworking
  • cubers
  • ngwrru68w68
  • tester
  • normalnudes
  • Leos
  • anitta
  • megavids
  • JUstTest
  • All magazines