Taking out ConnectWise sites

12/20/24 afhelp.top 104.21.112.1 Cloudflare/Gname - 58PD77A
12/20/24 atmolatori.icu 188.114.96.3 Cloudflare/Gname

That sounds like Alexhost - they brag on their website they are DMCA free and REFUSE to take down sites

12/20/24 fihelp.top 104.21.48.1 Cloudflare/Gname - 32UT59N/798786
12/20/24 gajrokerware.icu 188.114.97.3 Cloudflare/Gname

Second code they thought they were getting on a cell phone

Download last seen used with wmhelp.top
11/22/24 wmhelp.top 172.67.156.157 Cloudflare/Gname.com
11/22/24 gajrokerware.icu 188.114.97.3 Cloudflare/Gname.com

https://www.gxhelp.top/

mrhelp.top is still in play. one scammer gave me this today.

ppl.help9.top

https://gxhelp.top/?__cf_chl_tk=cuXmrIb7EoTl0D0PNWKF3zgo72rYhpzUIhIvaU90an0-1734728437-1.0.1.1-2hqQ08gqS0Rwq1x6GoasB0ioaxr31DFz5smrpc2FyA8

thats an offshore of https://gajrokerring.icu

off shore of https://cogajroker.icu

Yup and I’ve noticed if you looked at all of their ASNs, you will find a handful of connectwise sites which has a SUPER high probability of it being used for scamming because of their DMCA policy

Can you send the phone number?

molatorier.icu - main site
gzhelp.top - alternative site which is using molatorier.icu

both are using cloudflare so just report to cloudflare

https://xlhelp.top/?__cf_chl_rt_tk=Bnf66ArRRx2j84A6t1sKthDI93qnZv0NhpFAauKU4v0-1734808074-1.0.1.1-PI8j52ntkLURPah3nTA0OVbAIoPlwOzGRuJvsTjrmQQ

https://xkhelp.top/,
and,
https://qbhelp.top/,
and,
https://nohelp.top/

https://fihelp.top/,
and,
https://orhelp.top/,
and,
https://gthelp.top/,
and,
https://djhelp.top/,
and,
https://pdhelp.top/,
and,

https://pzhelp.top/ note: at this time it’s an invitation only session…,
https://pahelp.top/

https://xshelp.top/ note: invitation only session…,
and,
https://axhelp.top/,
and,
https://aehelp.top/,
https://afhelp.top/
https://tdhelp.top/
https://tchelp.top/
https://trhelp.top/
https://ywhelp.top/
https://gahelp.top/

https://gxhelp.top/

https://gzhelp.top/

https://afhelp.top/

https://sgsupport.help/

https://ibsde-4r.top/
these aren’t connectwise servers but they are malicious and were found during my research:
apple-log.top, appleasistentes.com, asistencia-icloud.icu, assistance-isop.top, bo-icloud.com, co-apple-maps.click, co-support-maps.com, detectsuspiciouslogin.pro, encontrar-lphone.com, encontrar-lphonecom.info, find-lcioud.online, flnd-loginmaps.info, folio-ishop.shop, folio-support.help, folio-support.top, gmailgoogle.xyz, help-appie.info, help-apple-bo.support, help-encontrar.com, help-encontrar.info, help-lcioud.info, help-lost.app, help-lphone.info, helpmx-support-apple.com, i-cloudmx-gpsg.info, icloud-bo.info, icloudlocalwz.pro, iforgot-com.info, infomx-idsupport-apple.com, ishop-retenciones-enlinea.com, ishop-soporteenlinea.com, ishop-support.top, ishopservices.com, l-cloudlost.info, lcloud-com.info, lcloud-gsm.info, ldappleinc.com, ldapplelnc.com, lfindcloud.com, loc-findmiip.com, localizar-ubicacion-tiempo-real.info, locatefmi.pro, location-maps.info, login-servercloud.click, lost-icloud.app, lost-lcioud.info, lphone-com.info, mapps.world, maps-gps.help, mapsapplee.pro, mx-support-maps.click, mxhelp-idsupport-apple.com, myfind-detectubicacion.click, myldappleld.com pe-account.com, phonelost-per.info, phonelost.info, rastrear-lphone.com, reclamacionesapple.com, reporteappleonline.com, serviciomacstore.com, settlngs-apple.app, solicitudesappleonline.com, soporte-apple.top, soporte-mixupi.shop, soportetecnicomacstore.com, storeapplee.pro, su-port-devlce-flnd.life, suporticloudyz.pro, support-ishop.shop, support-store.top, suptt-locate.help

https://acxcare.help/
https://krhelp.top/?__cf_chl_rt_tk=4hao7McgNrJAmLlo6BGstwWx3utJCx0S09Vhb58Xt08-1735051301-1.0.1.1-gqipm7wF.W1QyZzGyBUTbyTg_WTXm1oTnWgTtubhR1I
and,
https://snhelp.top/,
and,
https://wihelp.top/,
and,
https://wjhelp.top/ invitation only session,
and,
https://wnhelp.top/,
and,
https://xkhelp.top/ invitation only session
https://xlhelp.top/
https://xohelp.top/ invitation only session