hxxps[://]commisionbeforeclosing[.]com
Lol look at this shit
Found this after going through SO MANY REDIRECTS
An open redirect was abused from medium and calendly, among a bunch of other compromised hosts inbetween those.
ufarm[.]biz
rrautotech[.]co[.]in
I don't feel particularly too hot today so I'm not going to write up a huge thing that a few people read lol
But it was interesting to see the kits at the end trying to phish users for:
Ionos
xfinity
aol
microsoft
and others