MALICIOUS — CRITICAL
فحص التصيد والأمان للنطاق 1red.sk
1red[.]
Analysis of the domain 1red.sk, observed on July 22, 2026, indicates that the site is currently active and associated with a generic phishing campaign.
- VirusTotal
- 6/91
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- آخر نشاط معروف · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
1red.sk — آخر نشاط معروف (HTTP 200). نوع الاحتيال: Gambling. ملخص الأدلة: VirusTotal 6/91 (alphaMountain.ai, Bfore.Ai PreCrime, CRDF, Forcepoint ThreatSeeker, Gridinsoft); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. مسجّل النطاق: WEDOS Internet, a.s.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
Analysis of the domain 1red.sk, observed on July 22, 2026, indicates that the site is currently active and associated with a generic phishing campaign. The domain was registered on March 06, 2026 through the registrar WEDOS Internet, a.s., and is hosted on the IP address 172.67.213.157, which belongs to Cloudflare’s network as reflected by the authoritative nameservers penny.ns.cloudflare.com and scott.ns.cloudflare.com. VirusTotal scans show that one out of ninety‑five security vendors flagged the domain, providing a minimal but non‑zero detection signal.
The domain is listed on a single security blocklist and has been explicitly blocked by the PhishDestroy feed, confirming that at least one threat‑intelligence source categorises it as malicious. No additional public intelligence such as Safe Browsing status, Open Threat Exchange entries, SSL certificate details, HTTP response codes, or page‑title metadata is presently available, leaving those aspects unverified. The limited detection footprint suggests that the phishing infrastructure may be newly deployed or employing techniques to evade broader detection.
Defenders should continue to monitor the domain for changes in detection counts, add the IP address 172.67.213.157 to network‑level block lists, and enforce DNS‑level filtering that includes the known blocklist entry. Organizations using web‑proxy or secure web‑gateway solutions should ensure that traffic to 1red.sk is denied, and incident‑response teams should be prepared to investigate any credential submissions that reference this domain. Ongoing observation of the registrar’s activity and the Cloudflare nameserver configuration is recommended to detect potential re‑hosting or domain‑generation patterns.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
Casino / Gambling License Verification
التقنيات · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of 1red.sk · checked Jul 22, 2026
تحليل إعدادات الموقع
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.