site-3fejh9hgr[.]godaddysites[.]com
“Anmeldung UPC Mail”
site-3fejh9hgr.godaddysites.com — المحتوى غير متوفر. انتحال العلامة التجارية: Godaddy. ملخص الأدلة: VirusTotal 13/93 (alphaMountain.ai, BitDefender, CRDF, Forcepoint ThreatSeeker, G-Data); PhishDestroy score 89/100. مسجّل النطاق: GoDaddy.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis as of July 24 2026 indicates that the sub‑domain site-3fejh9hgr.godaddysites.com was used to host a phishing page titled “Anmeldung UPC Mail”. The domain is registered through GoDaddy.com, LLC and has been active since 18 Nov 2013. DNS resolution points to IP 13.248.243.5, which belongs to Amazon.com, Inc. (AS16509) and is located in the United States. The host is served behind GoDaddy’s default nameservers cns1.secureserver.net and cns2.secureserver.net, and the TLS certificate presented is a Go Daddy Secure Certificate Authority – G2 issued to GoDaddy.com, Inc., confirming the legitimate certificate chain but offering no protection against malicious content. The page was flagged by PhishDestroy and is listed on one security blocklist.
VirusTotal scans show that 13 of 93 antivirus or URL‑reputation engines flagged the domain, indicating a moderate detection rate. HTTP probing returned a 404 status code, and the current operational status is recorded as offline, suggesting the phishing page has been taken down. Nonetheless, the historical evidence of phishing activity remains relevant for threat‑intel correlation. Defenders should continue to monitor the IP address 13.248.243.5 for any re‑use in future campaigns, especially since the Amazon hosting environment is frequently leveraged for transient malicious infrastructure.
Existing blocklist entries should be maintained, and any outbound traffic to this host should be denied or logged. Because the domain’s registration details are publicly available and the SSL certificate is valid, reputation‑based filtering alone may not be sufficient; supplemental URL‑reputation checks and cross‑reference with the 13 VirusTotal detections are advisable. In environments where users may receive emails purporting to be from UPC, security awareness training should highlight the “Anmeldung UPC Mail” title as a known indicator of compromise. Continuous review of GoDaddy‑hosted sub‑domains for similar patterns is recommended.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
Registration: godaddysites.com
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain godaddysites.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب