veriga[.]site[.]tb-hosting[.]com
“The account hosting this domain has been temporarily disabled.”
veriga.site.tb-hosting.com — Nicht bestätigt. Betrugstyp: Account Takeover. Zusammenfassung der Beweislage: VirusTotal 20/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, Certego, CRDF); CF Radar malicious; PhishDestroy score 95/100. Registrar: Combell NV.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, veriga.site.tb-hosting.com, is identified as a generic phishing infrastructure designed to impersonate account suspension or hosting service notifications. Analysis indicates no direct association with a specific brand, though the page title 'The account hosting this domain has been temporarily disabled' suggests an attempt to mimic legitimate service disruption alerts. No drainer kit signatures or wallet addresses were observed in the available data, but the domain's structure and hosting behavior align with typical phishing campaigns targeting users through fear-based social engineering tactics. Infrastructure analysis reveals the following technical indicators: the domain was created on October 28, 2021, and is registered through Combell NV. It resolves to the IP address 198.18.1.209, a non-routable range often used in testing or malicious environments. The SSL certificate is issued by Let's Encrypt (R12), a common choice for phishing domains due to its free and automated issuance process. VirusTotal reports 20 out of 95 security vendors flagging this domain as malicious. The domain appears on two security blocklists, including PhishDestroy and PhishingDB, and is currently not listed in Google Safe Browsing (GSB) at the time of analysis. The domain is currently offline, with the hosting account disabled, likely due to abuse complaints or automated takedown mechanisms. While the immediate threat is mitigated, the infrastructure remains a residual risk. Historical DNS records and SSL certificates may still be leveraged in future campaigns, and the domain could be reactivated or repurposed. Organizations should monitor for re-emergence of this domain or similar patterns under the same registrar or IP range. Users are advised to treat any communication referencing this domain or its IP with suspicion, particularly unsolicited account suspension notices. Network-level blocking of the IP 198.18.1.209 and domain-based filtering for veriga.site.tb-hosting.com are recommended as proactive measures.
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
Technologien · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
VirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt