discord[.]quasarsoftware[.]net
“Discord”
Résumé des preuves
Analysis of discord.quasarsoftware.net indicates a brand impersonation campaign targeting Discord users. The domain was registered on February 21, 2026 and is currently marked offline. DNS resolution points to IP address 85.209.70.13, which resides in Russia and is announced by AS21030 Cluster LLC. The hosting infrastructure therefore originates from a Russian network, a factor that may affect response time for takedown actions. An SSL certificate labeled R12 is present, suggesting the use of a standard TLS certificate without further validation of its issuance authority.
VirusTotal scans show that seven of ninety‑three security vendors flagged the domain, demonstrating modest detection across the scanning ecosystem. The domain appears on a single public blocklist and has been explicitly blocked by the PhishDestroy filtering service, reinforcing the view that it is recognized as malicious by at least one security community. The page title returned by the server is "Discord," matching the declared brand target and confirming the intent to masquerade as the official Discord service. The campaign is classified as Social Media Phishing, consistent with the brand impersonation label.
No additional evidence about the page content, phishing kit, or credential capture mechanisms is available, leaving the exact user‑experience details uncertain. Defenders should continue to block the domain and its associated IP address at network perimeter devices, update URL filtering rules, and monitor for any re‑registration attempts. Given the modest vendor detection count, additional sandboxing or heuristic analysis of any future payloads linked to this infrastructure is advisable. Organizations that rely on Discord for internal communications should educate users about unsolicited login requests and enforce multi‑factor authentication to mitigate credential theft risks.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 13/08/2026
10 sources externes surveillées Aucune correspondance
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif