radyum[.]se[.]net
“radyum.se.net | 522: Connection timed out”
radyum.se.net — Non vérifié. Résumé des preuves: VirusTotal 10/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, ESET); URLQuery 100 det.; 1 external blocklist match (ScamSniffer); PhishDestroy score 95/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of the domain radyum.se.net, observed on July 24 2026, indicates that it was being used for a generic phishing operation before being taken offline. The domain resolves to the IP address 104.21.48.1, which is hosted by Cloudflare (ASN 13335) and geolocated to the United States. Both authoritative nameservers—alaric.ns.cloudflare.com and kira.ns.cloudflare.com—are Cloudflare‑managed, confirming the use of a reputable CDN for rapid deployment and potential concealment of the underlying infrastructure. The site presented the HTTP status “522: Connection timed out” in its page title, and no TLS certificate was observed, suggesting that the service was either mis‑configured or deliberately left without encryption to simplify traffic interception.
Reputation data is extremely poor: Gridinsoft assigned a trust score of 0 / 100, and the domain appears on two independent blocklists, specifically PhishDestroy and ScamSniffer. VirusTotal scanned the host and recorded nine positive detections out of ninety‑five antivirus engines, reinforcing the malicious classification. The combination of low trust scoring, blocklist presence, and multi‑vendor detections aligns with the elevated risk rating assigned by the analyst. Because the domain is currently offline, active probing is not possible, and no further content analysis (e.g., login pages, credential‑stealing forms) is available.
Consequently, the exact phishing template, targeted brand, or victim demographic remain unknown. Defenders should continue to block any DNS resolution to 104.21.48.1 that originates from radyum.se.net, enforce outbound filtering for HTTP traffic to the domain, and monitor for similar Cloudflare‑hosted sub‑domains that exhibit the same 522 status pattern. Adding the domain to internal blocklists and sharing the indicator set with upstream threat‑sharing platforms will help prevent re‑use of the same infrastructure in future campaigns.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif