radyum[.]se[.]net
“radyum.se.net | 522: Connection timed out”
Zusammenfassung der Beweislage
Analysis of the domain radyum.se.net, observed on July 24 2026, indicates that it was being used for a generic phishing operation before being taken offline. The domain resolves to the IP address 104.21.48.1, which is hosted by Cloudflare (ASN 13335) and geolocated to the United States. Both authoritative nameservers—alaric.ns.cloudflare.com and kira.ns.cloudflare.com—are Cloudflare‑managed, confirming the use of a reputable CDN for rapid deployment and potential concealment of the underlying infrastructure. The site presented the HTTP status “522: Connection timed out” in its page title, and no TLS certificate was observed, suggesting that the service was either mis‑configured or deliberately left without encryption to simplify traffic interception.
Reputation data is extremely poor: Gridinsoft assigned a trust score of 0 / 100, and the domain appears on two independent blocklists, specifically PhishDestroy and ScamSniffer. VirusTotal scanned the host and recorded nine positive detections out of ninety‑five antivirus engines, reinforcing the malicious classification. The combination of low trust scoring, blocklist presence, and multi‑vendor detections aligns with the elevated risk rating assigned by the analyst. Because the domain is currently offline, active probing is not possible, and no further content analysis (e.g., login pages, credential‑stealing forms) is available.
Consequently, the exact phishing template, targeted brand, or victim demographic remain unknown. Defenders should continue to block any DNS resolution to 104.21.48.1 that originates from radyum.se.net, enforce outbound filtering for HTTP traffic to the domain, and monitor for similar Cloudflare‑hosted sub‑domains that exhibit the same 522 status pattern. Adding the domain to internal blocklists and sharing the indicator set with upstream threat‑sharing platforms will help prevent re‑use of the same infrastructure in future campaigns.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt