gwem76x[.]life
“GET-X”
gwem76x.life — Nicht bestätigt. Zusammenfassung der Beweislage: VirusTotal 10/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); Spamhaus DBL_SPAM; PhishDestroy score 88/100. Registrar: URL Solutions.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Analysis indicates that the domain gwem76x.life is actively flagged as a high-risk phishing site targeting credentials under the page title 'GET-X'. Registered on February 21, 2026, through URL Solutions, Inc., the domain resolves to the IP address 186.2.165.69, hosted by Iqweb LLC in the United Arab Emirates. Infrastructure analysis reveals the use of nameservers ns1.pananames.com through ns4.pananames.com, a pattern commonly observed in phishing campaigns leveraging bulk domain registration services. The domain is currently detected by 2 of 93 security vendors on a widely used scanning platform, with additional blocking by at least one dedicated anti-phishing system. The SSL certificate is classified as R11, a designation often associated with low-trust or automated certificate issuance, further reducing confidence in the domain's legitimacy. Technologies detected on the site include Node.js, Google Cloud, Vue.js, Nuxt.js, Nginx, Amazon Web Services, and reCAPTCHA, suggesting a moderately sophisticated infrastructure that may be used to evade basic detection mechanisms or simulate legitimacy. The HTTP status code 301 indicates a permanent redirect, though the destination remains unconfirmed. The domain appears on one security blocklist as of the report date. While the exact brand or service being impersonated is not explicitly identified in available data, the page title 'GET-X' may imply a focus on credential harvesting or account takeover attempts. Defenders are advised to treat this domain as malicious and implement blocking at the DNS or network level. Further investigation into associated IP ranges, certificate histories, and redirect chains is recommended to identify related infrastructure. Given the active status and high-risk classification, monitoring for new domains registered under the same nameservers or IP space may aid in preemptive mitigation.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologien · 14 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Suite of cloud computing services running on Google infrastructure.
Progressive JavaScript framework for building user interfaces.
Hybrid Vue framework for server-side rendering and static sites.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Cloud computing platform offering compute, storage, and networking services.
Google's bot-challenge service. On phishing sites, used to appear legitimate and filter out automated scanners.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comContent delivery network built on Google global edge infrastructure.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comAmazon Web Services CDN for low-latency content delivery.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt