ai1115[.]com
“USDT”
Résumé des preuves
Analysis of ai1115.com shows a newly registered domain created on 21 February 2026 through NameCheap, Inc. The domain resolves to the Cloudflare address 172.67.146.123, which belongs to AS13335 Cloudflare, Inc. and is located in the United States. Traffic is protected by an SSL certificate issued by Google Trust Services under the WE1 authority, indicating the presence of HTTPS. The site’s front‑end stack includes Vue.js, the Marked markdown library, Cloudflare Browser Insights, and Baidu Analytics, and it serves content over HTTP/3, all of which were identified by passive fingerprinting tools. The only publicly visible page title is "USDT," but the site is currently taken offline, so its active content cannot be inspected.
Two of ninety‑three security vendors on VirusTotal have flagged the domain, suggesting malicious characteristics, and it is listed on one external security blocklist. Additional reputation services rate the domain poorly: Gridinsoft assigns a trust score of 6 out of 100, while Scamadviser gives a score of 1 out of 100. PhishDestroy has explicitly blocked the domain, reinforcing the classification as a phishing resource. The combination of a recent registration, low reputation scores, detection by multiple vendors, and confirmation from an anti‑phishing feed indicates a high likelihood that the domain was used for phishing, possibly targeting cryptocurrency users given the "USDT" title.
Uncertainty remains regarding the exact payload or victim interaction because the site is offline and no page content has been captured. Defenders should continue to block ai1115.com at perimeter and DNS filters, monitor for any resurgence of activity, and consider adding the domain to internal threat‑intelligence feeds. Continuous re‑evaluation is advised if the site reappears or if additional detection data become available.
Instantané des preuves transmises
- Envoyé
- Entrées du registre
- 1
- ID du dossier
PD-20260124-16A979- Artefact PDF
- Preuve PDF
Fondement juridique
Texte intégral des preuves
Policy Violations: Domain Registration Agreement prohibits hacking, misuse of domain to conduct attacks, scam and fraudulent activities; AUP allows immediate suspension
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Signaux de sécurité
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | ai1115.com |
malicious | Sinkholed |
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of ai1115.com · checked Mar 2, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif