estatex-sale[.]net
“1 new message”
estatex-sale.net — Inhalt nicht verfügbar. Markenidentität: Microsoft; Betrugstyp: Fake Airdrop. Zusammenfassung der Beweislage: VirusTotal 6/95 (alphaMountain.ai, CRDF, CyRadar, Ermes, Forcepoint ThreatSeeker); 1 external blocklist match (ScamSniffer); PhishDestroy score 68/100. Registrar: Ultahost.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain estatex-sale.net was registered on June 12, 2025 through Ultahost, Inc. and resolves to the IPv4 address 198.54.132.28, which is announced by AS11878 (tzulo, inc.) in Canada. The site presents a TLS certificate issued by Let’s Encrypt for the identifier YE2, confirming that encrypted HTTPS is available but offering no indication of legitimate ownership. Reputation services record a Scamadviser trust score of 31 out of 100 and a Gridinsoft trust score of zero, suggesting a low level of perceived legitimacy.
The domain is currently listed on two public blocklists, specifically PhishDestroy and ScamSniffer, and appears on two additional security blocklists, reinforcing the view that it is being used for malicious purposes. VirusTotal analysis shows that six of ninety-five scanned security vendors flagged the domain, providing independent confirmation of suspicious activity. The page title returned by the site is "1 new message," and the campaign is classified as a "Fake Airdrop" that impersonates Microsoft, indicating that victims may be lured with promises of a token or reward tied to the Microsoft brand.
Defenders should treat estatex-sale.net as an active, elevated‑risk indicator. Immediate actions include adding the domain and its resolving IP address to outbound and inbound deny lists, updating web proxy and DNS filtering policies to block resolution, and monitoring for any internal connections to the IP or TLS handshake with the Let’s Encrypt certificate. Continuous threat‑intel feeds should be consulted for any new detections, and incident response teams should be prepared to investigate any user reports of unexpected Microsoft‑related communications that reference the "1 new message" phrasing.
Sicherheitssignale
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Forensische Erkenntnisse
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt