98734afs5[.]cfd
“Coming Soon”
Zusammenfassung der Beweislage
Analysis indicates that the domain 98734afs5.cfd was registered through Dynadot LLC on 27 October 2025 and is currently offline. The authoritative nameservers are harvey.ns.cloudflare.com and rosa.ns.cloudflare.com, placing the domain behind Cloudflare’s network (ASN 13335). DNS resolution points to IP address 188.114.97.3, which is located in the United States and belongs to Cloudflare, Inc. No TLS certificate was observed, meaning the site served only HTTP content. The sole visible page title returned “Coming Soon,” providing no indication of a legitimate service. Reputation services assign a trust score of 1 out of 100 on Scamadviser, reflecting extreme suspicion.
Threat intelligence sources have recorded the domain in a single AlienVault OTX pulse and on one public security blocklist. PhishDestroy has already blocked the domain, and VirusTotal reports that 12 of 95 scanned security vendors flagged the domain as malicious. The limited detection footprint suggests the site was short‑lived or rapidly taken down, but the presence of multiple vendor detections confirms malicious intent consistent with a generic phishing campaign. Uncertainty remains regarding the exact phishing payload, target brand, or compromised credentials, as no further content analysis is available beyond the generic page title. Defenders should continue to monitor DNS queries for 188.114.97.3 and enforce blocklisting of the domain across perimeter and endpoint security solutions.
Given the Cloudflare hosting, any future re‑use of the same IP or nameserver pair should be treated with heightened scrutiny. Updating URL filtering policies to include the domain and its associated IP, as well as leveraging threat intel feeds that reference the observed OTX pulse and blocklist entry, will reduce the risk of inadvertent exposure. Organizations that rely on the Scamadviser trust score or similar reputation metrics should consider the score of 1/100 as a strong indicator of malicious activity.
Data Coverage
Sicherheitssignale
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
SHORTDOT-ZONE · ÖFFENTLICHE BELEGE
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt