ddosforhire[.]st
Evidence Summary
The domain ddosforhire.st was registered on 30 April 2026 and is currently resolving to the Cloudflare‑owned address 172.67.156.132 located in Canada. The site presents a TLS certificate issued by Google Trust Services under the WE1 hierarchy, indicating a valid‑looking HTTPS endpoint. HTTP requests return a 403 status code and the only visible page title is “Just a moment…”, which suggests the site may be employing a Cloudflare challenge page or similar obstruction. Intelligence sources classify the activity as a brand‑impersonation generic phishing campaign; however, the specific victim brand has not been disclosed in the available data. The domain is listed on the PhishDestroy blocklist and appears in a single AlienVault OTX pulse, confirming that it has been observed by at least one external threat‑intel feed. VirusTotal analysis shows that three of ninety‑one scanned scanners flagged the domain, and Gridinsoft assigns it a trust score of zero out of one hundred, reinforcing the malicious assessment. The risk rating is high and the operational status is active. Defenders should add ddosforhire.st to outbound and inbound filtering rules, monitor traffic to the associated Cloudflare IP, and ensure that any email or web gateway solutions reference the latest blocklists that include this domain. Continuous re‑evaluation is advised, as the content behind the “Just a moment…” page has not been publicly examined, leaving the exact phishing payload uncertain.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive