sun-sun[.]us
Análisis de phishing y seguridad de sun-sun.us
“Website 190.115.24.11 is ready. The content is to be added”
sun-sun.us — Contenido no disponible (HTTP 502). Resumen de las pruebas: VirusTotal 2/95 (Gridinsoft); PhishDestroy score 56/100. Registrador: CNOBIN INFORMATION TEC….
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis as of July 24, 2026 indicates that the domain sun-sun.us was registered on September 04, 2025 through CNOBIN INFORMATION TECHNOLOGY LIMITED. The authoritative nameservers are asa.ns.cloudflare.com and rohin.ns.cloudflare.com, pointing the domain to the Cloudflare edge IP 172.67.203.8, which belongs to ASN13335 Cloudflare, Inc., located in the United States. No TLS certificate is presented, meaning HTTPS connections would be established without encryption, a typical characteristic of temporary phishing infrastructure. The HTTP response returned a page titled “Website 190.115.24.11 is ready.
The content is to be added”, suggesting the site was a placeholder rather than a fully deployed credential‑stealing page. The domain is currently taken offline, and its presence on a single external blocklist (PhishDestroy) confirms prior detection. VirusTotal scans recorded two detections out of ninety‑five vendors, reinforcing the suspicion of malicious use. Gridinsoft assigned a trust score of 0 out of 100, indicating a complete lack of trust.
The combination of recent registration, Cloudflare hosting, absence of SSL, low trust score, and detection by multiple security vendors aligns with patterns observed in generic phishing campaigns that rely on short‑lived domains. However, the limited visible content prevents confirmation of a specific brand impersonation or the exact phishing kit employed. Defenders should add sun‑sun.us to URL filtering and blocklist rules, enforce blocking of its IP address 172.67.203.8, and monitor for any future re‑registration or activity from the same registrar or nameserver set. Continuous re‑scanning with multi‑engine services is recommended to capture any changes in the threat profile.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.