aquiverif-outoksmail2025[.]gamer[.]gd
“Bienvenido”
aquiverif-outoksmail2025.gamer.gd — Nicht bestätigt. Markenidentität: Outlook; Betrugstyp: Tech Support Scam. Zusammenfassung der Beweislage: VirusTotal 14/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 97/100. Registrar: Key Systems.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, aquiverif-outoksmail2025.gamer.gd, is assessed as an elevated-risk brand impersonation threat specifically designed for credential theft targeting Outlook users. Analysis indicates the infrastructure was deployed to mimic legitimate Microsoft authentication portals, with the page title 'Bienvenido' suggesting a localized attack vector aimed at Spanish-speaking users. The domain exhibits multiple high-risk indicators that align with known credential harvesting campaigns. Infrastructure analysis reveals the domain was registered on July 25, 2025, through Key Systems GmbH, a registrar frequently observed in transient phishing operations. It resolves to the IP address 185.27.134.231, hosted on AS34119 (Wildcard UK Limited) in Great Britain, an autonomous system previously associated with bulletproof hosting services. The domain appears on two security blocklists, PhishDestroy and PhishingDB, while VirusTotal detection metrics show 17 out of 95 security vendors flagging the domain as malicious. Notably, the absence of an SSL certificate further reduces legitimacy, as modern credential theft campaigns typically employ encryption to evade detection. To mitigate the risk posed by this credential theft operation, organizations should implement immediate countermeasures. Network-level protections should block both the domain and its resolving IP address (185.27.134.231) at firewalls and DNS resolvers. Security teams are advised to search authentication logs for connections originating from this domain or IP, particularly those occurring after July 25, 2025. End-user education should emphasize the risks of localized phishing pages, especially those using welcome messages in non-English languages. Given the domain's current offline status, continuous monitoring for re-emergence under similar naming conventions is recommended, as threat actors frequently reuse infrastructure patterns in subsequent campaigns.
Sicherheitssignale
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt