honeyman1[.]cc
“Honeyman1.cc”
honeyman1.cc — Non vérifié. Usurpation de l'identité de la marque : Telegram; Type d'arnaque : Brand Impersonation. Résumé des preuves: VirusTotal 2/95 (alphaMountain.ai, Forcepoint ThreatSeeker); PhishDestroy score 56/100. Bureau d’enregistrement: Immaterialism.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain honeyman1.cc was observed delivering a brand‑impersonation campaign targeting Telegram. The site was registered on 15 June 2025 through the registrar Immaterialism and is currently taken offline. DNS resolution points to 172.66.0.70, an address owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The SSL certificate is issued by Google Trust Services under the WE1 designation, indicating a valid HTTPS endpoint at the time of capture. HTTP requests to the host returned a 409 Conflict status, a response often associated with misconfigured or intentionally blocked resources.
Infrastructure analysis shows the presence of Google Analytics and Cloudflare as the only detected technologies, suggesting the operators leveraged common web‑hosting services rather than bespoke malicious toolkits. Reputation signals are strongly negative. Gridinsoft assigned a trust score of 0 / 100, and two of ninety‑five VirusTotal scanners flagged the domain as malicious. The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy service. The page title returned by the server is “Honeyman1.cc”, providing no additional context about the payload.
No Safe Browsing, Open Threat Exchange, or public evidence URLs were identified in the available data set. Given the combination of a recent registration, low trust rating, Cloudflare‑based hosting, a valid Google‑issued TLS certificate, and detection by multiple security vendors, the domain should be treated as a high‑confidence Telegram impersonation vector. Defenders are advised to add honeyman1.cc to inbound and outbound filtering rules, monitor DNS queries for the listed nameservers (1‑you.njalla.no, 2‑can.njalla.in, 3‑get.njalla.fo), and ensure that any user‑initiated connections to the domain are blocked. Continuous re‑evaluation is recommended in case the site re‑appears, as the current offline status may be temporary.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 2 identified
Google Analytics is a free web analytics service that tracks and reports website traffic.
google.com Confiance à 100 %Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of honeyman1.cc · checked Mar 2, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif