Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@ifastnet.com.
The latest stored availability evidence still shows the domain reachable; 28 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
tagesschau24-290125[.]totalh[.]net
“SONDERBERICHT: Dietmar Hopp stellt FRS, Regierung und Weltbank bloß, weil sie versuchen, seine neue…”
tagesschau24-290125.totalh.net — No verificado. Tipo de estafa: Credential Phishing. Resumen de las pruebas: VirusTotal 1/91 (LevelBlue); URLQuery 1 alert; PhishDestroy score 71/100. Registrador: Namecheap.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain tagesschau24-290125.totalh.net shows a long‑standing registration dating to 11 May 2012 and a current association with the IP address 185.27.134.221. The domain is serviced by five Byet.org nameservers (ns1.byet.org through ns5.byet.org), a configuration commonly seen on free‑hosting platforms. Registration was performed through Namecheap Inc, a registrar that does not enforce strict verification of registrant identity, which can facilitate abuse.
The domain has been flagged by the PhishDestroy intelligence feed and appears on a single external blocklist, indicating that at least one security‑vendor community has observed malicious activity linked to the host. VirusTotal records show that the URL was scanned by 95 antivirus and URL‑reputation engines, none of which raised a detection; however, the lack of a positive flag does not corroborate safety and may reflect limited visibility of the payload or evasion techniques. No public SSL/TLS certificate details, HTTP response codes, or page titles have been disclosed, leaving the exact content and the targeted brand or service undefined.
Consequently, the precise phishing scenario—whether a credential‑harvesting login page or another social‑engineering vector—remains uncertain. Defenders should therefore treat the domain as hostile: add the hostname and its resolving IP to deny or sink‑hole lists, enforce URL filtering for all outbound traffic, and monitor DNS queries for the associated Byet.org nameservers. Continuous re‑scanning with sandbox and reputation services is advised to capture any future changes in payload or hosting that could elevate the threat.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | tagesschau24-290125.totalh.net |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: totalh.net
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain totalh.net behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 5 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100 % de confianzaOpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.
openresty.org 100 % de confianzajQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100 % de confianzaGoogle Hosted Libraries is a stable, reliable, high-speed, globally available content distribution network for the most popular, open-source JavaScript libraries.
developers.google.com 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of tagesschau24-290125.totalh.net · checked Jul 23, 2026
Datos y informes externos
PD-20260723-D27692 Recipient: abuse@ifastnet.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.