88.191.36.45 [Proxad, France] is hosting a series of fake banking domains, one of which is detailed by F-Secure.The domains target Finnish and Spanish banks.
The following sites appear to be hosted on that IP:
bbva-es.com
nordea-vf.com
nordeasfi.com
nordea-if.com
nordea-fis.com
osuuspankki-fi.com
Some sites might use the following subdomains: kultaraha, solo1, solo2, www and xxx.
The (fake) registrant details are:
Admin Name……….. Arthur Williams
Admin Address…….. lake tarson 41
Admin Address……..
Admin Address…….. new york city
Admin Address…….. 90121
Admin Address…….. NY
Admin Address…….. UNITED STATES
Admin Email………. sir.arthur999@hotmail.com
Admin Phone………. +1.802716100
Blocking access to 88.191.36.45 would probably be a good idea if you have Spanish or Finnish users.
Leave a reply