Hey folks, here’s some more crap i came across after my post a few hours ago, it’s pretty much all apple-targeted phishing pages. Some 16Shop, a few iPanel Pro panels, iPanel (regular), iTech Ultimate, some weird one called “ZIKOOO” which looks like a rip of Phoenix Panel, Phoenix Panels (both english and russian (as evidenced by the HTTP banner “Пример входа в PHP”)), as well as an AppleKit panel. It’s kinda late on the east coast, so here ya go.
URL | IP |
---|---|
appieid[.]appeid[.]co[.]jp-encodingutf8openidassochandle[.]i2cgsiv2[.]info | 162[.]144[.]67[.]32 |
appieid[.]appeid[.]com-encodingutf8openidassochandle[.]i2cgsiv1[.]info | 162[.]144[.]67[.]32 |
apple-appleidcom[.]servehttp[.]com/admin | 13[.]66[.]5[.]101 |
apple[.]com-protect-now[.]com | 185[.]87[.]187[.]160 |
apple[.]com-serv[.]live/admin/login[.]php | 162[.]223[.]31[.]2 |
apple[.]com[.]br-login[.]id/admin/login | 162[.]0[.]232[.]164 |
apple[.]support[.]support-recovery[.]eu/access | 91[.]234[.]99[.]159 |
appleid-emails[.]com | 91[.]234[.]99[.]209 |
appleid-myaccount-apple[.]kolakang[.]com | 172[.]217[.]8[.]19 |
appleid-supportrequired[.]duckdns[.]org/admin/login[.]php | 167[.]172[.]117[.]194 |
appleid[.]apple[.]appsfind[.]site/admin/?attempt=1 | 31[.]31[.]198[.]107 |
appleid[.]appstore-helpersecurity-manage-subscription[.]com/admin/login[.]php | 20[.]185[.]68[.]254 |
appleid[.]com[.]find[.]me-locator[.]info/admin | 95[.]46[.]114[.]15 |
appleid[.]com[.]imaps[.]en-link[.]me/admin | 95[.]46[.]114[.]15 |
appleid[.]support-recovery[.]eu/access | 91[.]234[.]99[.]159 |
com-valid[.]in | 162[.]241[.]85[.]228 |
com-valid[.]in[.]ibench-server[.]com | 162[.]241[.]85[.]228 |
icloud[.]com-apple[.]center/admin | 37[.]46[.]132[.]208 |
icloud[.]com-appleid-fmi[.]com/admin/login[.]php | 190[.]14[.]38[.]22 |
icloud[.]com-ifind[.]icu/admin | 37[.]230[.]113[.]14 |
icloud[.]com-locate[.]imap-fmi[.]info/admin/auth[.]php | 80[.]87[.]203[.]19 |
icloud[.]com-myspace[.]live/admin/login[.]php | 162[.]223[.]31[.]2 |
icloud[.]com-support[.]id/admin | 198[.]252[.]104[.]170 |
icloud[.]com-uk-dev[.]be/admin/?attempt=1 | 31[.]31[.]198[.]147 |
icloud[.]com-uk-devices[.]be/admin/?attempt=1 | 31[.]31[.]198[.]147 |
icloud[.]com[.]acc-en[.]us/admin/?attempt=1 | 37[.]140[.]192[.]33 |
icloud[.]com[.]cn-fmi[.]live/admin/login[.]php | 190[.]14[.]38[.]22 |
icloud[.]com[.]cn-log[.]live/admin/login[.]php | 190[.]14[.]38[.]22 |
icloud[.]com[.]cn-web[.]live/admin/login[.]php | 190[.]14[.]38[.]22 |
icloud[.]com[.]de/admin | 204[.]11[.]58[.]144 |
icloud[.]com[.]en-login[.]live/admin/login[.]php | 190[.]14[.]38[.]22 |
icloud[.]com[.]fmi1[.]us/admin | 91[.]234[.]99[.]209 |
icloud[.]com[.]id-log-in[.]us/admin/?attempt=1 | 31[.]31[.]198[.]206 |
icloud[.]com[.]imap-fmi[.]info/admin/auth[.]php | 80[.]87[.]203[.]19 |
icloud[.]com[.]login-en[.]live/admin/login[.]php | 190[.]14[.]38[.]22 |
icloud[.]com[.]map-fmi[.]info/admin/auth[.]php | 80[.]87[.]203[.]19 |
icloud[.]com[.]onlinedevice[.]info/admin | 162[.]0[.]235[.]147 |
icloud[.]support-recovery[.]eu/access | 91[.]234[.]99[.]159 |
idmsa-appleid-update-appservice-informationids-s1[.]kozow[.]com/admin/login[.]php | 162[.]144[.]100[.]8 |
idmsa-appleid-update-appservice-informationids-s2[.]ooguy[.]com/admin/login[.]php | 162[.]144[.]100[.]8 |
iforgot[.]appleid[.]verify[.]me-locator[.]info/admin | 95[.]46[.]114[.]15 |
mapsconnect[.]apple[.]support-recovery[.]eu/access | 91[.]234[.]99[.]159 |
srvcsappleldweb[.]duckdns[.]org/admin/login[.]php | 101[.]32[.]166[.]248 |
support-recovery[.]eu/access | 91[.]234[.]99[.]159 |
www[.]appieid[.]appeid[.]co[.]jp-encodingutf8openidassochandle[.]i2cgsiv2[.]info | 162[.]144[.]67[.]32 |
www[.]appieid[.]appeid[.]com-encodingutf8openidassochandle[.]i2cgsiv1[.]info | 162[.]144[.]67[.]32 |
www[.]apple[.]com-protect-now[.]com | 185[.]87[.]187[.]160 |
www[.]apple[.]com-serv[.]live/admin/login[.]php | 162[.]223[.]31[.]2 |
www[.]apple[.]support[.]support-recovery[.]eu/access | 91[.]234[.]99[.]159 |
www[.]appleid-supportrequired[.]duckdns[.]org/admin/login[.]php | 167[.]172[.]117[.]194 |
www[.]appleid[.]appstore-helpersecurity-manage-subscription[.]com/admin/login[.]php | 20[.]185[.]68[.]254 |
www[.]appleid[.]support-recovery[.]eu/access | 91[.]234[.]99[.]159 |
www[.]appleidstoresupport[.]site/admin | 81[.]177[.]135[.]41 |
www[.]com-valid[.]in | 162[.]241[.]85[.]228 |
www[.]com-valid[.]in[.]ibench-server[.]com | 162[.]241[.]85[.]228 |
www[.]icloud[.]com-apple[.]center/admin | 37[.]46[.]132[.]208 |
www[.]icloud[.]com-appleid-fmi[.]com/admin/login[.]php | 190[.]14[.]38[.]22 |
www[.]icloud[.]com-appleid[.]live/admin | 188[.]120[.]228[.]235 |
www[.]icloud[.]com-locate[.]imap-fmi[.]info/admin/auth[.]php | 80[.]87[.]203[.]19 |
www[.]icloud[.]com-mapconnect-loading[.]live/admin | 198[.]252[.]104[.]159 |
www[.]icloud[.]com-myspace[.]live/admin/login[.]php | 162[.]223[.]31[.]2 |
www[.]icloud[.]com-support[.]id/admin | 198[.]252[.]104[.]170 |
www[.]icloud[.]com[.]cn-fmi[.]live/admin/login[.]php | 190[.]14[.]38[.]22 |
www[.]icloud[.]com[.]cn-log[.]live/admin/login[.]php | 190[.]14[.]38[.]22 |
www[.]icloud[.]com[.]cn-web[.]live/admin/login[.]php | 190[.]14[.]38[.]22 |
www[.]icloud[.]com[.]de/admin | 204[.]11[.]58[.]144 |
www[.]icloud[.]com[.]en-login[.]live/admin/login[.]php | 190[.]14[.]38[.]22 |
www[.]icloud[.]com[.]fmi1[.]us/admin | 91[.]234[.]99[.]209 |
www[.]icloud[.]com[.]get-support[.]me/admin | 31[.]148[.]99[.]152 |
www[.]icloud[.]com[.]imap-fmi[.]info/admin/auth[.]php | 80[.]87[.]203[.]19 |
www[.]icloud[.]com[.]login-en[.]live/admin/login[.]php | 190[.]14[.]38[.]22 |
www[.]icloud[.]com[.]map-fmi[.]info/admin/auth[.]php | 80[.]87[.]203[.]19 |
www[.]icloud[.]support-recovery[.]eu/access | 91[.]234[.]99[.]159 |
www[.]idmsa-appleid-update-appservice-informationids-s1[.]kozow[.]com/admin/login[.]php | 162[.]144[.]100[.]8 |
www[.]idmsa-appleid-update-appservice-informationids-s2[.]ooguy[.]com/admin/login[.]php | 162[.]144[.]100[.]8 |
www[.]itunes[.]support-recovery[.]eu/access | 91[.]234[.]99[.]159 |
www[.]mapsconnect[.]apple[.]support-recovery[.]eu/access | 91[.]234[.]99[.]159 |
www[.]srvcsappleldweb[.]duckdns[.]org/admin/login[.]php | 101[.]32[.]166[.]248 |