connectauth[.]hstn[.]me
“Clock error”
connectauth.hstn.me — No verificado. Resumen de las pruebas: VirusTotal 14/91 (BitDefender, Chong Lua Dao, CyRadar, ESET, Forcepoint ThreatSeeker); Google Safe Browsing flagged; 4 external blocklist matches; PhishDestroy score 100/100. Registrador: Porkbun.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain connectauth.hstn.me is currently active and classified as a high‑risk generic phishing site. Infrastructure analysis shows it resolves to the IPv4 address 185.27.134.219, which is hosted in the United Kingdom and belongs to AS34119 Wildcard UK Limited. The authoritative nameservers are ns1.byet.org through ns4.byet.org, indicating use of a shared hosting provider. Registration information lists Porkbun LLC as the registrar, with the domain creation date of June 03, 2019. The site presents an HTTPS certificate issued by ZeroSSL ECC Domain Secure Site CA, but the certificate does not mitigate the malicious intent. Google Safe Browsing flags the domain for social engineering, and VirusTotal records 12 detections out of 95 scanned vendors, reflecting consensus among security tools. Additional reputation data includes a Gridinsoft trust score of 0/100, placement on five blocklists, and active blocking by services such as PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura. The HTTP response returns status code 200, and an MX record is configured pointing to mx.hstn.me, which may be used for credential harvesting. While the page title "Clock error" provides no insight into the payload, the combination of hostile indicators suggests the domain is being leveraged for credential‑stealing or similar phishing campaigns. Defenders should immediately block network traffic to both the domain and its resolved IP, enforce URL filtering for the domain, and monitor email systems for the associated MX host. Continuous threat‑intel feeds should be consulted for any emerging indicators, and incident response teams should be prepared to investigate potential compromises originating from this infrastructure.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.