pik303[.]cyou
“Attention Required! | Cloudflare”
ملخص الأدلة
Analysis indicates that pik303.cyou was registered on December 17 2025 through Dynadot LLC and is currently hosted behind Cloudflare’s network (AS13335). The domain resolves to 172.67.129.198, an IP range owned by Cloudflare, Inc., and the TLS certificate presented is issued by Google Trust Services under the WE1 label, confirming a legitimate‑looking HTTPS endpoint. HTTP requests receive a 403 response and the page title returned is “Attention Required! | Cloudflare”, suggesting that access is being denied, consistent with the reported offline status.
The domain appears on one security blocklist and has been explicitly blocked by PhishDestroy. VirusTotal scans show that two of ninety‑three security vendors flagged the domain, indicating limited but present detection of malicious activity. Detected technologies include Cloudflare and HTTP/3, and the authoritative nameservers are anirban.ns.cloudflare.com and mina.ns.cloudflare.com. While the limited vendor detections and single blocklist entry prevent a definitive classification, the combination of recent creation, Cloudflare‑protected hosting, a 403 status, and the presence on a phishing‑focused blocklist aligns with patterns observed in generic phishing infrastructure.
The lack of publicly available content beyond the Cloudflare interstitial means that the exact payload or credential‑harvesting intent cannot be confirmed at this time. Defenders should treat the domain as hostile: incorporate the FQDN into URL filtering, block the associated IP address range where feasible, and monitor DNS logs for queries to pik303.cyou. Continuous re‑evaluation is advised, as additional detections or intelligence could emerge.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
نطاق SHORTDOT · أدلة عامة
.cyou
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات
حُدّدَت تقنيتان عاليتا الثقة
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب