This cluster centers on 1486 connected domains tagged as AgentTesla, None, js. The domains include i.postimg.cc, cdn.discordapp.com, s3.us-east-2.amazonaws.com, pastes.io, dl.dropboxusercontent.com, ltcexchange.bitparking.com, bitcoin.sipa.be, litecoinpool.org, cryptocoincharts.com, sigaintevyh2rzvw.onion, toremail.net, lelantos.org, www.sigaint.org, epjhlyfgxenf2q4o.onion~~, inocncymyac2mufx.onion, torbox3uiot6wchz.onion, 344c6kbnjnljjzlz.onion, mailtor.net, bscscan.com, securitized.io and 1466...
412-827-1413
Last reported Mar 26, 2026
- 1 community report from users
Campaign Intelligence
This cluster centers on 2559 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include 83.224.148.34, 14.236.247.68, 120.157.72.59, 95.127.248.192, 116.110.179.199, 116.101.73.68, 95.127.250.241, 152.173.199.182, 91.80.129.100, 59.88.45.188, 117.216.5.20, 182.60.11.164, 41.146.14.165, 120.157.46.38, 59.182.90.199, 113.168.249.76, 78.132.114.25, 171.241.208.124, 120.157.229.220, 14.236.84.25 and 2539 more. 640 of these domains have been flagged by threat intelligence feeds inc...
Details
Linked Company Activity
Connected Entities
Linked Companies
Flagstar Bank, N.A.
campaign co-membercompanyFirst Credit Services Inc.
campaign co-membercompanyPENTAGON FEDERAL CREDIT UNION
campaign co-membercompanyFIFTH THIRD FINANCIAL CORPORATION
campaign co-membercompanyCredit Services Corporation, LLC
campaign co-membercompanyIntegrity Group Inc
campaign co-membercompanyDirect, Inc
campaign co-membercompanyThe Bureaus, Inc.
campaign co-membercompanyEVERBANK, NATIONAL ASSOCIATION
campaign co-membercompanyTime Investment Corporation
campaign co-membercompanyCheckr, Inc
campaign co-membercompanyMOUNTAIN AMERICA FEDERAL CREDIT UNION
campaign co-memberRelated Phone Numbers
8553572202
campaign co-memberphone8667715844
campaign co-memberphone8339086865
campaign co-memberphone8009220204
campaign co-memberphone4097617631
campaign co-memberphone6789998212
campaign co-memberphone6512042449
campaign co-memberphone5187704680
campaign co-memberphone8887291403
campaign co-memberphone8889194623
campaign co-memberphone9805107108
campaign co-memberphone7712473445
campaign co-memberphone5858247925
campaign co-memberphone8009993355
campaign co-memberphone8007715361
campaign co-memberphone8009033637
campaign co-memberphone2025582508
campaign co-memberphone9297499563
campaign co-memberphone8887910954
campaign co-memberphone8334471291
campaign co-memberphone7656119812
campaign co-memberphone8669591188
campaign co-memberphone8442446363
campaign co-memberphone3473635189
campaign co-memberRelated Domains
130.12.180.43
campaign co-memberdomainimplementing-theft-metal-justin.trycloudflare.com
campaign co-memberdomainstaying-heavily-meaning-blowing.trycloudflare.com
campaign co-memberdomaincreations-venture-traditional-stainless.trycloudflare.com
campaign co-memberdomain103.125.219.204
campaign co-memberdomain206.123.145.26
campaign co-memberdomainarilprivate.storexyz.web.id
campaign co-memberdomain14.236.182.73
campaign co-memberdomain83.224.162.132
campaign co-memberdomain123.31.81.229
campaign co-memberdomain120.157.56.105
campaign co-memberdomain113.176.132.141
campaign co-memberRelated Emails
cfjtfl@verxl.com
campaign co-memberemaildiana@ierek.com
campaign co-memberemailhr@teknfix.com
campaign co-memberemailcbx-df@ceszx.com
campaign co-memberemailj.thompson8822@ymail.com
campaign co-memberemailbb.adige@libero.it
campaign co-memberemailpangmyiuhk@yahoo.co.jp
campaign co-memberemailmarydavis09@zoho.com
campaign co-memberemailxxxxxxxxxxxxxxxxxxxxxxxx@vmh5.grupoaldama.com.mx
campaign co-memberemaila4084163@trbvm.com
campaign co-memberemaillegalnotice@facebookmail.com
campaign co-memberemailleads@myhome.ie
campaign co-memberCommunity Reports
On 02/19/26 at approximately 1814 hours, NVPD dispatched received a call from a male who identified himself as M*** *******. ******* resides in Denver, Colorado, however he recently came upon an ad on Facebook Marketplace for a 1957 Chevrolet Bel Aire, red in color with a white roof. ******* stated that the images showed a recently restored vehicle that was being sold for a quarter of the price it was worth. ******* began a dialogue with a female named Hannah regarding the vehicle and with the intent to make arrangements to fly here to look at the vehicle. Once ******* mentioned that he wanted to look at the vehicle before wiring any money, Hannah became evasive and stated that the vehicle was not able to be viewed for several days due to scheduling conflicts. During the course of the conversation, ******* was able to obtain a phone number, website and location of the supposed car dealership. The website he found was https://fishersalescars.com/ which listed a phone number of 412-827-1413 and the dealership headquarters as 1101 Lincoln Highway. That address used to be Fisher Car Sales, which closed in 2024. The property has remained vacant since the dealership closed. A Google search of the phone number shows a recent Yelp review for the fictitious business. I was able to review the mentioned website and noted the same information that was given to me by *******, however we were not able to locate the original Marketplace ad. As I browsed the website while on the phone with *******, he pointed out several issues, namely that all the vehicles were being sold at less than half the price of the market value. ******* also explained that he requested additional information on the vehicle, to include title, VIN plates, etc and it was sent via text message to which the attachment would not open. ******* stated that he quickly realized that the business was fictitious and that somebody was most li [BBB Scam Type: Online Purchase] [Business: Fisher Sales Cars/ Fisher Classic
Share Your Experience
What's Your Exposure?
Know your risk exposure to this message with a Thorough Analysis. It returns a detailed report covering the complaint history, your data breach exposure, related scam entities, and risk signals tied to this email message. Check the box and enter your email address now.