yafin[.]top
Resumen de las pruebas
Analysis indicates that yafin.top was registered on February 21 2026 and currently resolves to 172.67.141.123, an address owned by Cloudflare (AS13335) located in the United States. The domain is presently taken offline, which limits immediate interaction but does not remove the underlying infrastructure from threat assessments. VirusTotal scans have returned 12 positive detections out of 93 submitted engines, demonstrating that multiple security products have identified malicious behavior associated with the host. Gridinsoft assigns a trust score of 0 out of 100, confirming a lack of confidence in the domain's legitimacy.
The SSL certificate is labeled WE1, indicating a weak or self‑signed certificate that fails standard trust validation. Reputation data shows the domain appears on a single security blocklist and is listed in one AlienVault OTX pulse, reflecting limited but existing community awareness. PhishDestroy has also blocked the domain, reinforcing its classification as a phishing vector. The combination of a recent creation date, Cloudflare front‑end, low trust score, multiple vendor detections, and inclusion on blocklists suggests the site was used for credential‑harvesting or similar phishing campaigns.
Because the site is offline, direct observation of content is unavailable; therefore, the exact phishing lure, targeted brand, or page structure remains unknown. Defenders should continue to block DNS resolution to 172.67.141.123, update intrusion detection signatures with the observed indicators, and monitor for any re‑use of the domain or associated IP range. Ongoing threat‑intel feeds should be queried for new pulses referencing yafin.top, and any outbound traffic to the IP should be investigated for potential data exfiltration attempts.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
10 fuentes externas supervisadas Sin coincidencias
Inteligencia forense
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.