proposals-onyx[.]xyz
“Pieni hetki...”
proposals-onyx.xyz — Contenido no disponible (HTTP 502). Resumen de las pruebas: VirusTotal 3/95 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft); PhishDestroy score 65/100. Registrador: OwnRegistrar.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain is flagged for hosting credential theft infrastructure, a specific threat type designed to harvest login credentials through deceptive login portals. Analysis indicates the site employs social engineering tactics, likely impersonating legitimate services to trick users into submitting sensitive information such as usernames, passwords, or multi-factor authentication codes. The risk level is classified as elevated due to the domain's recent creation, association with known malicious infrastructure, and detection by multiple security vendors. Infrastructure analysis reveals the following technical indicators: the domain proposals-onyx.xyz was registered on September 20, 2025, through OwnRegistrar, Inc., a registrar frequently observed in phishing campaigns. It resolves to the IP address 172.67.160.42, which has been linked to other malicious domains in prior investigations. The domain currently appears on one security blocklist and is flagged by 3 out of 95 security vendors on VirusTotal. Additionally, the domain received a trust score of 0/100 from Gridinsoft, further corroborating its malicious intent. The page title, 'Pieni hetki...,' suggests an attempt to mimic a legitimate service, possibly targeting Finnish-speaking users or services. To mitigate the risks associated with credential theft, organizations and individuals should implement the following measures: Immediately block the domain and its associated IP address (172.67.160.42) at the network perimeter using firewalls or DNS filtering solutions. Conduct a retrospective analysis of logs to identify any prior interactions with the domain, particularly focusing on authentication attempts or data submissions. Educate users on recognizing credential theft tactics, such as unexpected login prompts, mismatched URLs, or requests for sensitive information via untrusted channels. Enforce multi-factor authentication (MFA) across all accounts to reduce the impact of credential compromise. Finally, monitor for indicators of compromise, such as unusual login attempts or unauthorized access, and reset credentials for any accounts that may have been exposed.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.