MALICIOUS — CRITICAL
Phishing- und Sicherheitsprüfung für a25365.cc
a25365[.]
This domain, a25365.cc, is flagged as a high-risk phishing endpoint with active redirection behavior.
- VirusTotal
- 16/93
- Blocklists
- No stored match
- Verfügbarkeit
- Letzter bekanntermaßen aktiv · HTTP 302
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
a25365.cc — Letzter bekanntermaßen aktiv (HTTP 302). Markenidentität: Bet365; Betrugstyp: Credential Phishing. Zusammenfassung der Beweislage: VirusTotal 16/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLQuery 5 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 100/100. Registrar: GoDaddy.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
This domain, a25365.cc, is flagged as a high-risk phishing endpoint with active redirection behavior. Analysis indicates the domain was registered on February 21, 2026, through a registrar and currently resolves to IP 27.124.41.84, hosted on AS152194 in Hong Kong. The HTTP response code is 302, suggesting an immediate redirect to another destination, which is consistent with phishing infrastructure designed to evade detection or dynamically serve malicious content based on visitor profiles. Infrastructure review reveals the domain uses nameservers v1s1.xundns.com and v1s2.xundns.com, a pattern observed in other recently reported phishing campaigns. The SSL certificate is issued to 'Default Company Ltd,' a generic placeholder commonly associated with low-effort or automated malicious setups. Security vendors on VirusTotal have flagged this domain 16 times out of 95, indicating moderate consensus on its malicious nature, though the specific impersonated brand or service remains unconfirmed. The domain appears on one security blocklist and was referenced in a single threat intelligence pulse, suggesting limited but targeted distribution. Defenders should treat this domain as an active threat. The 302 redirect behavior may obscure the final payload, so network-level blocking of 27.124.41.84 and the associated nameservers is recommended. Logs should be reviewed for any outbound connections to this IP or domain, particularly from endpoints that handle credentials or financial data. Given the domain's recent registration and lack of legitimate historical activity, it is unlikely to serve any valid business purpose. If internal access is detected, immediate isolation of affected systems and credential rotation should be prioritized.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | a25365.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | a25365.cc |
malicious | Sinkholed |
| Cloudflare DNS | hd365756.com |
malicious | Sinkholed |
| DigiCert UltraDNS | hd365756.com |
malicious | Sinkholed |
| DNS4EU | hd365756.com |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.