Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Phishing ams-shared-7.hostwindsdns.com #1006

Closed
hwtechsupport opened this issue Jan 9, 2025 · 2 comments
Closed

Phishing ams-shared-7.hostwindsdns.com #1006

hwtechsupport opened this issue Jan 9, 2025 · 2 comments
Assignees

Comments

@hwtechsupport
Copy link

What are the subjects of the phishing (domains, URLs or IPs)?

  • ams-shared-7.hostwindsdns.com
  • ams-shared-7.hostwindsdns.com
  • https://ams-shared-7.hostwindsdns.com
  • https://ams-shared-7.hostwindsdns.com

What are the impersonated domains?

  • ams-shared-7.hostwindsdns.com
  • ams-shared-7.hostwindsdns.com
  • https://ams-shared-7.hostwindsdns.com
  • https://ams-shared-7.hostwindsdns.com

Where or how did you discover this phishing?

I discovered this phishing by...
I was targeted by this phishing by...

Do you have a screenshot?

[Screenshot](https://hw-screenshots.sea-proxy.windystorage.com/screenshots/2025-01-09_14-41-10_5156fd3b-43f2-44a9-a709-294882ac73b5.png)

Related external source

Additional Information or Context

Hello,

      The domain "[ams-shared-7.hostwindsdns.com](http://ams-shared-7.hostwindsdns.com/)" is free from infected or malware content. Please remove the domain from the malware list.

Hostwinds

@phishing-database-bot
Copy link
Member

Verification Required

@hwtechsupport, thank you for submitting a false positive report! To help us verify your ownership of the affected domain(s), please complete the following steps:

  1. Set a DNS TXT record for the domain(s) listed in this issue with the following details:

    • Record Name: _phishingdb
    • Record Value: antiphish-d35f8174a21a86ec2b45baa12634672f9d80b7f4

    Your Verification ID: antiphish-d35f8174a21a86ec2b45baa12634672f9d80b7f4

  2. Wait for DNS propagation (this may take a few minutes to a few hours).

  3. Reply to this issue once the TXT record has been set.

Important Notes

  • Verification does not guarantee whitelisting. The Phishing.Database team will review your report after verifying ownership, but the decision to whitelist depends on further investigation and analysis.
  • If the record cannot be set or you need alternative methods of verification, please contact us at [email protected] - preferably from the domain's official email address.

How to Check the TXT Record ?

You can verify that the TXT record is properly set using:

Thank you for your cooperation! We will address your issue as soon as possible after verification.

The Phishing.Database Project Team.

@spirillen
Copy link
Contributor

Now that I can see this is the second issue regarding hostwindsdns.com

I would like to share a couple of other dubious subdomains, marked on the blacklist systems.

Search results

Lookup provided by My Privacy DNS

Hosts-Sources

External Hosts-Sources can be found here

Ultimate.Hosts.Blacklist1.csv:dal-business-25.hostwindsdns.com
Ultimate.Hosts.Blacklist1.csv:dal-business-26.hostwindsdns.com
Ultimate.Hosts.Blacklist1.csv:dal-business-28.hostwindsdns.com
Ultimate.Hosts.Blacklist1.csv:dal-shared-11.hostwindsdns.com
hosts-file.psh.csv:bs51.hostwindsdns.com
hosts-file.psh.csv:dal-business-26.hostwindsdns.com
phishing_database/ALL-phishing-links.csv:ams-business-7.hostwindsdns.com
phishing_database/ALL-phishing-links.csv:ams-business-8.hostwindsdns.com
phishing_database/ALL-phishing-links.csv:ams-shared-11.hostwindsdns.com
phishing_database/ALL-phishing-links.csv:ams-shared-12.hostwindsdns.com
phishing_database/ALL-phishing-links.csv:dal-business-25.hostwindsdns.com
phishing_database/ALL-phishing-links.csv:dal-shared-11.hostwindsdns.com
phishing_database/ALL-phishing-links.csv:hwsrv-1252301.hostwindsdns.com
phishing_database/ALL-phishing-links.csv:hwsrv-728665.hostwindsdns.com
phishing_database/ALL-phishing-links.csv:hwsrv-926859.hostwindsdns.com
phishing_database/ALL-phishing-links.csv:hwsrv-943988.hostwindsdns.com
phishing_database/ALL-phishing-links.csv:sea-shared-16.hostwindsdns.com
phishing_database/phishing.database/domain.csv:ams-business-7.hostwindsdns.com
phishing_database/phishing.database/domain.csv:ams-business-8.hostwindsdns.com
phishing_database/phishing.database/domain.csv:ams-shared-11.hostwindsdns.com
phishing_database/phishing.database/domain.csv:ams-shared-12.hostwindsdns.com
phishing_database/phishing.database/domain.csv:dal-business-25.hostwindsdns.com
phishing_database/phishing.database/domain.csv:dal-shared-11.hostwindsdns.com
phishing_database/phishing.database/domain.csv:hwsrv-1252301.hostwindsdns.com
phishing_database/phishing.database/domain.csv:hwsrv-728665.hostwindsdns.com
phishing_database/phishing.database/domain.csv:hwsrv-926859.hostwindsdns.com
phishing_database/phishing.database/domain.csv:hwsrv-943988.hostwindsdns.com
phishing_database/phishing.database/domain.csv:sea-shared-16.hostwindsdns.com

Sorted result

ams-business-7.hostwindsdns.com
ams-business-8.hostwindsdns.com
ams-shared-11.hostwindsdns.com
ams-shared-12.hostwindsdns.com
bs51.hostwindsdns.com
dal-business-25.hostwindsdns.com
dal-business-26.hostwindsdns.com
dal-business-28.hostwindsdns.com
dal-shared-11.hostwindsdns.com
hwsrv-1252301.hostwindsdns.com
hwsrv-728665.hostwindsdns.com
hwsrv-926859.hostwindsdns.com
hwsrv-943988.hostwindsdns.com
sea-shared-16.hostwindsdns.com

Might be worth having a giving your network a general overhaul, just your friendly goblin 👺

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: ✅ Done
Development

No branches or pull requests

6 participants