radyum[.]se[.]net
“radyum.se.net | 522: Connection timed out”
radyum.se.net — No verificado. Resumen de las pruebas: VirusTotal 10/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, ESET); URLQuery 100 det.; 1 external blocklist match (ScamSniffer); PhishDestroy score 95/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain radyum.se.net, observed on July 24 2026, indicates that it was being used for a generic phishing operation before being taken offline. The domain resolves to the IP address 104.21.48.1, which is hosted by Cloudflare (ASN 13335) and geolocated to the United States. Both authoritative nameservers—alaric.ns.cloudflare.com and kira.ns.cloudflare.com—are Cloudflare‑managed, confirming the use of a reputable CDN for rapid deployment and potential concealment of the underlying infrastructure. The site presented the HTTP status “522: Connection timed out” in its page title, and no TLS certificate was observed, suggesting that the service was either mis‑configured or deliberately left without encryption to simplify traffic interception.
Reputation data is extremely poor: Gridinsoft assigned a trust score of 0 / 100, and the domain appears on two independent blocklists, specifically PhishDestroy and ScamSniffer. VirusTotal scanned the host and recorded nine positive detections out of ninety‑five antivirus engines, reinforcing the malicious classification. The combination of low trust scoring, blocklist presence, and multi‑vendor detections aligns with the elevated risk rating assigned by the analyst. Because the domain is currently offline, active probing is not possible, and no further content analysis (e.g., login pages, credential‑stealing forms) is available.
Consequently, the exact phishing template, targeted brand, or victim demographic remain unknown. Defenders should continue to block any DNS resolution to 104.21.48.1 that originates from radyum.se.net, enforce outbound filtering for HTTP traffic to the domain, and monitor for similar Cloudflare‑hosted sub‑domains that exhibit the same 522 status pattern. Adding the domain to internal blocklists and sharing the indicator set with upstream threat‑sharing platforms will help prevent re‑use of the same infrastructure in future campaigns.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.