Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 2. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

notebookoff[.]uz

“Ноутбуки в Ташкенте - Купить с доставкой по Ташкенту”

Threat verdict Critical 86/100 evidence score
Availability Cloaked · reachable Reachability observed through cloaking checks
VirusTotal detections: 2/91 Scam type: Generic Phishing Last known active
Jun 24, 2026

Stored detection

Cloaking alert

Cloaking type
content_divergence
Cloaking score
1/6
Scanner-facing title301 Moved Permanently
Visitor-facing titleНоутбуки в Ташкенте - Купить с доставкой по Ташкенту
Evidence Summary
CRITICAL
Score
86/100

This domain, www.notebookoff.uz, is currently flagged as an active phishing site targeting users in the Uzbek market under the guise of selling laptops in Tashkent. Analysis indicates the site presents itself as a legitimate electronics retailer, with the page title 'Ноутбуки в Ташкенте - Купить с доставкой по Ташкенту' suggesting localized delivery services. The domain was registered on May 21, 2020, and remains operational as of July 12, 2026, resolving to IP address 167.235.222.200, which is hosted on AS24940 (Hetzner Online GmbH) in Germany. A 301 HTTP redirect is present, which may be used to obscure the final destination or chain multiple compromised domains together in the attack flow. Infrastructure review reveals the domain uses Let's Encrypt SSL certificates (R12) and is served via nameservers dns1.webspace.uz and dns2.webspace.uz, both pointing to 95.46.96.77. While the domain appears on one security blocklist and is flagged by a single vendor on VirusTotal, these detections are not conclusive on their own. However, the Gridinsoft trust score of 0/100 further supports the assessment of malicious intent, particularly in the context of credential harvesting or payment fraud. The longevity of the domain—active for over six years—may contribute to its perceived legitimacy among unsuspecting users. Defenders should treat this domain as high-risk due to its persistent operation, localized social engineering tactics, and hosting on infrastructure commonly associated with phishing campaigns. Network-level blocking is recommended for the domain and its associated IP address. Organizations should monitor for any redirects or subdomains linked to this infrastructure, as attackers may leverage the established reputation to bypass initial filters. No evidence currently links this domain to a specific phishing kit or threat actor, but the consistent use of Hetzner hosting suggests a preference for bulletproof or low-cost hosting providers.

VirusTotal
VirusTotal
2 det.
TLS Certificate
Expired or unverified -6d
Age
6.2 yr
Observed status
Cloaked · reachable 301
PhishDestroy
DestroyList
Listed
Data coverage VirusTotal 2 / 91 URLQuery checked — no detections recorded PhishStats not checked OTX no community references CF Radar no data URLScan capture stored report URLScan verdict Analysis completed DNS blocks not checked TLS Expired or unverified WHOIS 76 mo old Screenshot 3 captures · 3 sources Redirect chain not probed

Threat Response Pipeline

Discovery
Checks
Reports
Availability
8/10

Blocklist coverage

10 monitored external feeds · stored snapshot Aug 10, 2026

Stored Capture

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Server / ASN nginx · AS24940 HETZNER-AS Hetzner Online GmbH, DE
IP Reputation abuse score 0/100 0 reports checked Jul 24, 2026
Registrar Arsenal-D
IP Address 167.235.222.200 DE
GeoDE Nuremberg, DE
NetworkAS24940 · Hetzner Online GmbH
RegistrationCreated May 21, 2020 Expires May 21, 2027
HTTP Status301 Moved Permanently
Elapsed Since First Report 1h
What we count Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Cloaked · reachable.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, TLS names and timestamps
First DetectedJun 24, 2026
DOM Analysisanalyzed Jul 9, 2026score 86/100
Submitted URLhttp://www.notebookoff.uz/
Nameserversdns1.webspace.uzdns1.webspace.uz.95.46.96.77dns2.webspace.uzdns2.webspace.uz.185.74.4.43dns3.webspace.uzdns3.webspace.uz.
TLS fingerprint
TLS observationvalid from May 6, 2026scanned Jun 24, 2026
TLS subject alternative namesmail.notebookoff.uznotebookoff.uznotebookoff.uz.167-235-222-200.cpanel.sitewww.notebookoff.uz.167-235-222-200.cpanel.site
Favicon Hash
Page Title
Ноутбуки в Ташкенте - Купить с доставкой по Ташкенту
TLS Certificate
Expired or unverified · Issued by Let's Encrypt / R12
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

2 / 91 security vendors flagged this domain
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
Forcepoint ThreatSeeker
SOCRadar

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing

External tools

HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/notebookoff.uz"
  title="PhishDestroy threat report for notebookoff.uz"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>