celestorasol[.]xyz
celestorasol.xyz — Masqué · accessible. Résumé des preuves: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); cloaking observed; PhishDestroy score 98/100. Bureau d’enregistrement: PDR.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, celestorasol.xyz, is under investigation for generic phishing activity. Registered on April 18, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, it currently resolves to a Cloudflare IP (172.67.216.148) located in Canada. Infrastructure analysis reveals Cloudflare nameservers (leo.ns.cloudflare.com, phoenix.ns.cloudflare.com) and an SSL certificate issued by Google Trust Services (WE1), which are common among both legitimate and malicious sites. The domain appears on one security blocklist and was flagged in a single AlienVault OTX threat intelligence pulse, though no specific brand impersonation or phishing kit has been confirmed in available data. The page title 'Just a moment...' and HTTP 403 status suggest either a holding page, a blocked access attempt, or a misconfigured phishing landing page. Defenders should note that while 94 vendors scanned the domain on VirusTotal with no detections, this does not confirm safety—only that no known signatures matched at the time of scanning. The domain remains active and was recently blocked by PhishDestroy, indicating ongoing monitoring by at least one security provider. Given the lack of confirmed brand targeting or scam type, further analysis is required to determine the exact threat model. Recommended actions include monitoring DNS resolutions, inspecting SSL certificate transparency logs for related domains, and checking for connections to known phishing campaigns or shared infrastructure. If internal systems interact with this domain, log analysis should prioritize unusual outbound connections or credential submissions.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif