online-rew[.]to
Zusammenfassung der Beweislage
Analysis of online-rew.to shows an active generic phishing infrastructure. The domain resolves to Cloudflare IP 104.21.45.245, hosted in Canada, and is served through the Cloudflare nameservers martha.ns.cloudflare.com and sid.ns.cloudflare.com. A Let’s Encrypt certificate (YE1) is present, indicating the site is reachable over HTTPS. HTTP requests return a 403 status code and the page title "Just a moment...," suggesting that content is being blocked or concealed. The domain appears on three security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL. It is also referenced in a single AlienVault OTX pulse, confirming its inclusion in broader threat intelligence feeds. VirusTotal scans report four of ninety‑one security vendors flagging the domain, reinforcing the malicious assessment. Registration details list the Government of the Kingdom of Tonga as the registrar, a pattern sometimes seen in abuse‑related registrations. While the exact phishing payload cannot be confirmed due to the HTTP 403 response, the convergence of blocklist listings, TLS certificate, and threat‑intel references provides sufficient evidence to classify the domain as a confirmed phishing site. Defenders should immediately block or sinkhole online-rew.to, monitor DNS queries for the associated Cloudflare IP range, and incorporate the domain into intrusion detection signatures. Ongoing observation of related Cloudflare‑hosted domains is advised to detect potential campaign expansions.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
8 überwachte externe Feeds Kein Treffer
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
Technologien
2 Technologien mit hoher Konfidenz erkannt
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of online-rew.to · checked Jul 19, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt