goaltrail[.]ru[.]com
“Bulletproof Hosting”
Zusammenfassung der Beweislage
goaltrail.ru.com is a newly registered domain (creation date 21 February 2026) that currently resolves to the IPv4 address 103.50.161.106. The site returns HTTP 200 and presents a title of “Bulletproof Hosting”, suggesting the page is being used to masquerade as a hosting‑service login or control panel. The domain is listed as active and is hosted under the Sav.com, LLC registrar, with four centralnic.net nameservers (ns1–ns4.centralnic.net). The hosting IP belongs to ASN 394695, advertised by PDR and geolocated to India. The TLS certificate presented is identified as “R13”, indicating a recent, possibly self‑signed or low‑validation certificate. Threat intelligence feeds have flagged the domain: PhishDestroy has already added it to its blocklist, VirusTotal reports eight out of ninety‑five scanners rating the domain as malicious, and one external blocklist also lists it. Gridinsoft assigns a trust score of zero out of one hundred, reinforcing the malicious assessment. Analysis indicates that the infrastructure is characteristic of generic phishing campaigns that lease bulletproof hosting to evade takedown. The exact brand or service being spoofed is not disclosed in the visible content, and no phishing kit fingerprints have been observed, leaving the specific target ambiguous. Defenders should proactively block both the domain and its resolving IP, monitor DNS queries for similar sub‑domains under the same registrar, and enforce URL filtering for any pages presenting the “Bulletproof Hosting” title. Continuous re‑evaluation is advised, as the active status and low trust score suggest the site may evolve its payload or expand its phishing scope.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | quantumxy.ru.com |
malicious | Sinkholed |
| DNS0 Zero | fonts.cfd |
malicious | Sinkholed |
| DNS4EU | fonts.cfd |
malicious | Sinkholed |
| OpenDNS | goaltrail.ru.com |
phishing | Phishing Block |
| Hagezi Threat Feed | goaltrail.ru.com |
malicious | Sinkholed |
| DNS0 Zero | goaltrail.ru.com |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of goaltrail.ru.com · checked Mar 25, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt