Taking out ConnectWise sites

clones for www.cp9help.top

Website: Registrar: Registered on:
https://www.pp9help.top/ Gname.com 2025-05-29
https://www.t4khelp.top/ Gname.com 2025-05-01
https://www.s3phelp.top/ Gname.com 2025-04-30

Does reporting these sites to Abuse complaints-Domain name reporting do anything? I gave it a go. Reporting to Report an unsafe site - Microsoft Security Intelligence
and https://safebrowsing.google.com/safebrowsing/report-url seems to help get sites flagged. At least I notice that scammers have to keep buying more domain names as they get quickly flagged.

hey if you can send it to me at [email protected]

Yes, reporting does help quite a bit, not all the time but it’s effective.

So I reported through GName and they shut down those three sites ( pp9, t4k, s3p ) pretty quick.

Edit: So you need include a screen shot. Ideally they have PayPal or other logos in the screenshot. I don’t know if they care unless they see a fake/copied logo. (Most connect wise sites simply have a place to enter a code.)

Edit: NameSilo reporting: https://www.namesilo.com/phishing-report

I think most reporting sites want to see PayPal logos etc. I’m not sure how convincing it is to post a site with no trademarked images.

Other sites found:

https://upohelp.top
https://sup2.bkd210.ru:8118 (down?)
https://pxgcare.help (backed by ConnectWise)
https://www.kb3help.top

6/18

https://hctcare.help

https://nyvcare.help/
https://mxnlive.help/

clones for mxnlive.help

site registered on registrar
https://zznet.help/ 2025-06-14 NameSilo
https://ktmlive.help/ 2025-05-28 NameSilo

unfortunately the script relies on urlscan.io to find the clones, so if it wasn’t submitted, it won’t find them + (luckily) they don’t last long anymore

another example why I struggle to find clones: when pisol.help was posted no clones where found, now I find a couple, submitted in the meantime

site registered on registrar
https://jrzlive.help/ 2025-05-28 NameSilo,
https://rztlive.help/ 2025-05-28 NameSilo,
https://qmsol.help/ 2025-06-12 NameSilo,
https://zmsol.help/ 2025-06-05 NameSilo,

All of you working on this project are doing excellent work! Every effort made on taking them out is making progress, the sites are significantly decreasing.

Site Registered on Registrar
https://knbphelp.us/ 2025-05-30 Namecheap
https://rybphelp.top/ 2025-06-12 Gname.com

BHOCARE.HELP domain

hp3help.top
hs9help.top

https://gkma.us:9113/

https://bdycare.help/
https://ctmcare.help/

https://pyacare.help/

https://hqxcare.help/

https://jtccare.help/

ran the new script "Script to find new ConnectWise sites " on some of the hashes predefined, this is the list of the current results for these hashes:
39ad554ecb56c04433cd9a618e019e0c4670c5f255c089266c779d1cbd141e4e
3270f59b64211cf247d6f01056e6a97ffd39acd40a815d3b3ff3431d894774ca
1f9bf98e43b7dd4317006be99ecbcf871b0ec475dd6dcb656bb8439239d0e4e5
9b9339876c1a3666f1c61d7a29fdcee0a55c819f6b57c5cd09872a811c4aa861
f3a74cc8eaf2dbdb157e4631b084cee9b0b4a7da241a31aefe380b17dca98c6e

(some are probably suspended already but mb worth knowing the status quo):

https://bdycare.help/
https://bhocare.help/
https://cmnet.help/
https://fbxcare.help/
https://hqxcare.help/
https://i9vkhy-7y.top/
https://itdcare.help/
https://ivrcare.help/
https://jrzlive.help/
https://jtccare.help/
https://mxnlive.help/
https://nyvcare.help/
https://orbcare.help/
https://orvcare.help/
https://pisol.help/
https://pyacare.help/
https://qmsol.help/
https://rztlive.help/
https://tbfrt-ew3.top/
https://www.bg9help.top/
https://www.bw5help.top/
https://www.d4khelp.top/
https://www.f6qhelp.top/
https://www.g6dhelp.top/
https://www.g6vhelp.top/
https://www.g7nhelp.top/
https://www.g7whelp.top/
https://www.g8khelp.top/
https://www.gt4help.top/
https://www.gt9help.top/
https://www.gthelp9.top/
https://www.h8thelp.top/
https://www.help2b.top/
https://www.help56.top/
https://www.help6t.top/
https://www.help7s.top/
https://www.help98.top/
https://www.helpa8.top/
https://www.helpe6.top/
https://www.helpo3.top/
https://www.helpt5.top/
https://www.helpw6.top/
https://www.helpw8.top/
https://www.helpz9.top/
https://www.hp3help.top/
https://www.hs9help.top/
https://www.jd6help.top/
https://www.m6whelp.top/
https://www.md7help.top/
https://www.n3fhelp.top/
https://www.p4bhelp.top/
https://www.ppshelp.top/
https://www.t3uhelp.top/
https://www.v4shelp.top/
https://www.y7shelp.top/
https://zmsol.help/
https://zznet.help/

new clone sites:
https://ipxz32-rd.top/
https://mjpcare.help/
looks like the script works

new clone sites:
https://absol.help/