xn--rbb-6cd1h[.]xn--ismlsaft-k4dd464auubea1m3b1t[.]useful[.]gr[.]com
“useful.gr.com | 521: Web server is down”
xn--rbb-6cd1h.xn--ismlsaft-k4dd464auubea1m3b1t.useful.gr.com — Nicht bestätigt. Zusammenfassung der Beweislage: VirusTotal 2/91 (alphaMountain.ai, Gridinsoft); PhishDestroy score 71/100. Registrar: Key-Systems.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain xn--rbb-6cd1h.xn--ismlsaft-k4dd464auubea1m3b1t.useful.gr.com has been classified as a generic_phishing site and is currently listed as under_investigation. The page title returned by the server is "useful.gr.com | 521: Web server is down", indicating that the web service is presently inaccessible but the domain remains active.
Infrastructure analysis shows the domain was registered on February 21, 2026 through Key-Systems GmbH. It is hosted behind Cloudflare and resolves to IP address 172.67.134.215, which belongs to AS13335 Cloudflare, Inc. in the United States. The site is served over TLS with a Let's Encrypt certificate identified as E8, and HTTP/3 support is observed. The authoritative nameservers are ns1.centralnic.net, ns2.centralnic.net, ns3.centralnic.net, and ns4.centralnic.net.
Threat intelligence indicates the domain is blocked by PhishDestroy and appears on one external security blocklist. The Gridinsoft trust score is 0 out of 100, reflecting a highly suspicious rating. An HTTP 521 status code is returned, a Cloudflare‑specific error that typically signifies the origin server is refusing connections, a pattern often associated with malicious landing pages that are intermittently taken offline to evade detection. The lack of detections on VirusTotal (0/95) does not imply safety, as the domain’s recent creation and blocklist presence suggest active malicious use.
Defenders should prioritize monitoring for DNS resolutions to 172.67.134.215 and consider adding the domain to blocklists at the network perimeter. Continuous surveillance of the associated IP and any related subdomains is advised, as well as the implementation of sinkholing for traffic destined for this domain. Because the site is still alive despite the 521 error, threat hunters should also inspect any captured payloads or redirects that may be triggered when the server becomes reachable again.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt