Is this PHISH-IP flagged?

At least Google Safebrowsing has it: https://aw-snap.info/file-viewer/?protocol=not-secure&tgt=www.upath.club%2F&ref_sel=GSP2&ua_sel=ff&fs=1
Re: http://urlquery.net/report.php?id=1493234746874
Malicious history of IP: http://cyberwarzone.com/malicious-history-of-184-168-221-60/

pol

GoDaddy abuse and link to ransomeware detected to IP 50.63.202.58: https://www.herdprotect.com/ip-address-50.63.202.58.aspx
and https://ransomwaretracker.abuse.ch/ip/50.63.202.58/

GET /img.aspx?q=L3MkWGAkAGH3ZmN0AmZ0AGxjAGplAQHjZPHlAzpyZ3R1ZQNkWGV2MFHmpFHlAz4yZ3RjWGV2LlHmpGNyZwMyMvHmpGNyZwMzWGAkWGV2MJpyZ3RlZQR3ZQDlAwRmZQRjAvHlAzA5WGAkZFHlAaEaWGAkZvHlAatyZ3RyZwMhrvHmpGNyZwMzpPHmpGNyZwMbozpyZ3RkWGV2qTLyZ3R2WGV2pUNyZ3SuLvHlAaSyWGAkozLgpJI2pF1vLv0kBQt1AmR0ZGt2AGDjBQx0WGV2MzqjWGAkZN==-1 HTTP/1.1 Host: upath dot club

User-Agent: Mozilla/5.0 etc.
Accept: image/png,image/;q=0.8,/;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,
;q=0.7
Keep-Alive: 115
Connection: keep-alive
Referer: htxp://upath.club/?reqp=1&reqr=
United States
AS26496 GoDaddy.com, LLC 50.63.202.58
HTTP/1.1 200 OK
Content-Type: image/gif
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Wed, 26 Apr 2017 19:56:49 GMT
Age: 259
Transfer-Encoding: chunked
Connection: keep-alive

Re: https://asafaweb.com/Scan?Url=upath.club 1 errors:Fail and 2 Warning.

polonus (volunteer website security analyst and website error-hunter)

Getting a 404 unreachable atm for 50.63.202.52. Just as well given what you’ve discovered.

Howdy mchain,

Again a GoDaddy secureserver dot net address “coming loose at the seams sort of”, you know what I mean :wink: :frowning:
Host appears down now, as that is what you reports also. Wonder whether they won’t bone it out now as a sedo parking site, or take it down and have it out to the next domain to be hosted there until that one also “tumbles under because of issues, GoDaddy fails to address”.

Hopeless bulk serving, actually. A party just in there to get you hooked and then you will not run away, just like the Comcast end-users.
Sad state of affairs, as you come to think of it, and bad for the security status of the overall infrastructure.

Damian