ya-browser[.]ru
Análisis de phishing y seguridad de ya-browser.ru
“Скачать удобный браузер и полезные сервисы от Яндекса в едином пакете”
ya-browser.ru — Último activo conocido (HTTP 200). Resumen de las pruebas: VirusTotal 8/91 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, Fortinet, Gridinsoft); PhishDestroy score 84/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain ya-browser.ru indicates it is an active phishing site targeting users seeking Yandex browser software. The page title, 'Скачать удобный браузер и полезные сервисы от Яндекса в едином пакете,' explicitly references Yandex services, suggesting an attempt to deceive visitors into downloading malicious software under the guise of a legitimate browser package. The domain currently resolves to the IP address 35.228.96.114, hosted on infrastructure belonging to Google LLC (AS396982) in Finland, which is atypical for official Yandex distribution channels. Infrastructure analysis reveals the domain lacks an SSL certificate, a critical security gap that exposes users to interception or tampering during downloads. The domain is served by Cloudflare nameservers (george.ns.cloudflare.com and nina.ns.cloudflare.com), a common configuration that may obscure the true origin of the malicious content. Security vendors have flagged the domain, with 7 out of 95 engines on VirusTotal identifying it as malicious, while it appears on one security blocklist and is referenced in a single AlienVault OTX threat intelligence pulse. The Gridinsoft trust score of 0/100 further corroborates its high-risk classification. While the domain is actively serving content (HTTP 200 status), the exact nature of the payload remains unverified due to the absence of direct forensic analysis. Defenders should treat this domain as a confirmed phishing threat targeting Russian-speaking users, particularly those seeking Yandex-related software. Network-level blocking is recommended, along with monitoring for connections to the associated IP address 35.228.96.114. Organizations should also verify any recent downloads from this domain within their environments, as the delivered software is likely to contain malware or unwanted applications. The use of Cloudflare infrastructure suggests the operators may rapidly change hosting details, necessitating real-time threat intelligence updates.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Análisis de la configuración del sitio
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.