MALICIOUS — CRITICAL
diffuculttan[.]xyz
diffuculttan.xyz is an active brand impersonation domain targeting Microsoft, classified under elevated risk by PhishDestroy.
- VirusTotal
- 22/91
- Blocklists
- 1 · CryptoFirewall
- التوفر
- آخر نشاط معروف · HTTP 302
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
diffuculttan.xyz — آخر نشاط معروف (HTTP 302). انتحال العلامة التجارية: Microsoft; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 22/91 (ADMINUSLabs, alphaMountain.ai, Antiy-AVL, BitDefender, Certego); URLQuery 6 alerts; 1 external blocklist match (CryptoFirewall); CF Radar malicious; PhishDestroy score 100/100. مسجّل النطاق: MarkMonitor.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
diffuculttan.xyz is an active brand impersonation domain targeting Microsoft, classified under elevated risk by PhishDestroy. This site deceives users with a false Microsoft seizure notice to harvest credentials or install malicious payloads under the guise of legitimate enforcement actions.
This domain was flagged by 21 of 95 VirusTotal security vendors and blocked by Maltrail. It resolves to IP 40.91.108.115, was registered through MarkMonitor, Inc. on December 06, 2024, and appears on one known security blocklist. The SSL certificate is fraudulently issued to 'Microsoft Corporation', reinforcing its false legitimacy.
Treat this domain as hostile. Do not visit, click links, or input any data. Block the domain at DNS, firewall, and email levels. If accessed accidentally, close the browser, clear the cache, and scan for malware. Report the domain to Microsoft Security Intelligence and your IT security team. Block the IP (40.91.108.115) and related domains to prevent further exposure.
نطاق تغطية البيانات13 recorded checks
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | www.noticeofpleadings.net |
malicious | Sinkholed |
| Cloudflare DNS | diffuculttan.xyz |
malicious | Sinkholed |
| Hagezi Threat Feed | diffuculttan.xyz |
malicious | Sinkholed |
| DigiCert UltraDNS | diffuculttan.xyz |
malicious | Sinkholed |
| DNS4EU | diffuculttan.xyz |
malicious | Sinkholed |
| Quad9 DNS | diffuculttan.xyz |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.