esanraxo-530btc[.]it
“esanraxo-530btc.it | 523: Origin is unreachable”
esanraxo-530btc.it — Non vérifié. Résumé des preuves: VirusTotal 6/91 (alphaMountain.ai, Bfore.Ai PreCrime, CRDF, Fortinet, Gridinsoft); PhishDestroy score 83/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of the domain esanraxo-530btc.it shows that it is currently active and serving HTTP status code 301, indicating a permanent redirect. The domain has been observed by six of ninety‑one security vendors on VirusTotal, which signals malicious intent consistent with a phishing‑related operation. It is listed on a single external blocklist and is actively blocked by PhishDestroy, reinforcing the assessment that the site is being used for illicit credential harvesting.
No additional infrastructure details such as registrar, IP address, ASN, hosting provider, or SSL certificate information have been disclosed in the available intelligence, leaving the broader hosting profile uncharacterized. The page title and any brand‑specific references have not been published, so the exact lure employed by the site cannot be confirmed at this time. The combination of a redirect response, multi‑vendor detection, and inclusion on a phishing‑focused blocklist is sufficient to classify the domain as a high‑risk phishing vector.
Defenders should add esanraxo-530btc.it to network‑level deny lists, enforce URL filtering, and monitor DNS queries for lookups to this name. Continuous re‑evaluation is advised, as further crawling or sandbox analysis may reveal additional payloads, credential‑stealing forms, or affiliate redirects. Until more detailed content is harvested, the recommended mitigation is to block the domain at the perimeter and alert endpoint protection solutions to treat any connections as malicious.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Technologies · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif