Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@staff.aruba.it.
The latest stored availability evidence still shows the domain reachable; 20 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
b-buc[.]it
فحص التصيد والأمان للنطاق b-buc.it
“Maintenance”
b-buc.it — آخر نشاط معروف (HTTP 200). ملخص الأدلة: VirusTotal 14/91 (alphaMountain.ai, BitDefender, CRDF, ESET, Forcepoint ThreatSeeker); Google Safe Browsing flagged; PhishDestroy score 100/100. مسجّل النطاق: Aruba s.p.a.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of the domain b-buc.it shows that it has been active since its registration on 9 May 2019 through Aruba s.p.a. The authoritative name servers dns.technorail.com, dns2.technorail.com and dns3.arubadns.net resolve the name to the IPv4 address 31.11.36.13. The domain appears on the PhishDestroy blocklist, indicating that at least one security‑focused feed has classified it as malicious. Google Safe Browsing also marks the site for social engineering, a label consistent with phishing‑related activity. VirusTotal scans have returned three positive detections out of ninety‑five submitted security engines, providing additional independent confirmation of suspicious behavior. No public SSL certificate details, HTTP response codes, or page title information are currently available, so the exact nature of the hosted content cannot be verified from the present data set. The lack of such telemetry leaves the specific phishing vector—whether credential harvesting, account takeover, or other social‑engineering technique—undetermined. Nevertheless, the convergence of blocklist inclusion, Safe Browsing warning, and multiple vendor detections establishes a high confidence that b-buc.it is being used for phishing. Defenders should add the IP address 31.11.36.13 and the domain name to network‑level denylists, enforce DNS filtering that incorporates the PhishDestroy feed, and monitor outbound traffic for connections to the host. Continuous re‑scanning with VirusTotal or similar multi‑engine platforms is recommended to capture any evolution of the payload. Analysts should also retrieve the site’s HTTP response and TLS certificate when possible to enrich the profile and confirm the exact phishing campaign employed.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
المراجع المتقاطعة لاستخبارات التهديدات · source references
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of b-buc.it · checked Jul 20, 2026
الأدلة والتقارير الخارجية
PD-20260720-994EF0 Recipient: abuse@staff.aruba.it هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب