ondoislucky[.]com
“404 Not Found”
This domain, ondoislucky.com, is flagged as an active generic phishing site with high-risk indicators. Registered on October 23, 2024, through Network Solutions, LLC, the domain currently resolves to IP 162.241.226.16, hosted on AS31898 (Oracle Corporation) in the US. Infrastructure analysis reveals nameservers ns1.bluehost.com and ns2.bluehost.com, a common hosting provider configuration. The domain returns an HTTP 302 redirect status, suggesting it may be part of a larger redirection chain leading to malicious content, though the final destination remains unconfirmed. A 404 Not Found page title is currently observed, which may indicate temporary downtime or an attempt to evade detection. The domain appears on 15 threat intelligence pulses in AlienVault OTX and is blocked by at least two security blocklists, including PhishDestroy and PhishingDB. Eighteen of 95 security vendors on VirusTotal have flagged the domain as malicious. MX records indicate mail.ondoislucky.com as the primary mail server, which could be leveraged for phishing email campaigns. The SSL certificate, issued by Sectigo Limited, is a standard Domain Validation (DV) type, providing no additional trust indicators. Defenders should treat this domain as actively malicious. Recommended actions include blocking the domain and its resolved IP at the network level, monitoring for associated email traffic, and investigating any redirection chains originating from this domain. The exact phishing target or campaign type remains unconfirmed due to limited page content analysis, but the infrastructure and detection patterns align with known phishing operations.
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources · synchronisées le 10/08/2026
Chronologie de détection
Observations enregistrées par ordre chronologique.
-
Observation enregistrée
Observation enregistrée : alive → dead
-
Cloudflare Radar
Cloudflare Radar : observé pour la première fois comme https://radar.cloudflare.com/scan/f7aff69b-0cc8-47c9-9e6a-9a6a331e8273
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif