सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 18। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

runescapearts[.]forums[.]events[.]quitting[.]giveaway[.]gul[.]org-fm-678-223-176-122345492-182-342[.]ru

“runescapearts.forums.events.quitting.giveaway.gul.org-fm-678-223-176-122345492-182-342.ru”

धमकी भरा फैसला गंभीर 95/100 साक्ष्य स्कोर
उपलब्धता असत्यापित वर्तमान पहुंच योग्यता असत्यापित है
वायरस का कुल पता लगाना: 18/91 घोटाले का प्रकार: Fake Airdrop
29/05/2026
रिपोर्ट सारांश

runescapearts.forums.events.quitting.giveaway.gul.org-fm-678-223-176-122345492-182-342.ru — असत्यापित. घोटाले का प्रकार: Fake Airdrop. साक्ष्य सारांश: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); PhishDestroy score 95/100. रजिस्ट्रार: REGRU-RU.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
44D46B2B
स्कोर
95/100

This domain, runescapearts.forums.events.quitting.giveaway.gul.org-fm-678-223-176-122345492-182-342.ru, is identified as a generic phishing threat targeting users of the massively multiplayer online role-playing game RuneScape. Analysis indicates the domain was designed to mimic legitimate RuneScape community forums or event pages, specifically leveraging the theme of a 'quitting giveaway' to lure victims into disclosing account credentials or financial information. The structure of the domain, incorporating terms like 'forums,' 'events,' and 'giveaway,' suggests an attempt to exploit user trust in community-driven content and in-game rewards. No specific drainer kit or malware family has been conclusively linked to this domain at this time, though the tactics align with common phishing campaigns targeting gaming communities. Infrastructure analysis reveals several critical technical indicators. The domain was registered on March 28, 2026, through REGRU-RU, a registrar frequently associated with malicious activity. It resolves to the IP address 185.82.200.115, which has been observed in prior phishing campaigns. The domain is flagged by 19 out of 95 security vendors on VirusTotal, indicating a high level of consensus regarding its malicious nature. Additionally, it appears on two security blocklists and is actively blocked by multiple threat intelligence feeds. The domain employs a Let's Encrypt SSL certificate, a tactic often used by threat actors to create a false sense of security for potential victims. Google Safe Browsing (GSB) status is not explicitly provided, but the domain's presence on multiple blocklists suggests it would likely be flagged. As of the latest assessment, the domain has been taken offline, reducing immediate risk to end users. However, the infrastructure supporting this campaign may remain active, and similar domains could emerge using comparable naming conventions or hosting patterns. Users who interacted with this domain are advised to immediately reset their RuneScape account credentials and enable multi-factor authentication. Organizations should update their blocklists to include the domain and its resolving IP address, 185.82.200.115, to prevent future access. Given the elevated risk level and the domain's association with credential theft, continued monitoring of related infrastructure is recommended to mitigate potential follow-up attacks or rebranding efforts by the same threat actors.

VirusTotal
VirusTotal
18 det.
URLScan
यूआरएलस्कैन
TLS प्रमाणपत्र
Let's Encrypt
आयु
5 mo
देखी गई स्थिति
असत्यापित
PhishDestroy
विनाश सूची
सूचीबद्ध
डेटा कवरेज VirusTotal 18 / 91 यूआरएलक्वेरी जाँच नहीं की गई फ़िशस्टैट्स जाँच नहीं की गई ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक 14 जाँच पूरी — कोई ब्लॉक नहीं TLS valid certificate, 39d कौन है 5 mo old स्क्रीनशॉट बाहरी कैप्चर चेन पुनर्निर्देशित करें जांच नहीं की गई

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
10/12

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

पेज शीर्षक
runescapearts.forums.events.quitting.giveaway.gul.org-fm-678-223-176-122345492-182-342.ru
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt · valid for 39 days

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN AS60117 Host Sailor Ltd
IP प्रतिष्ठा abuse score 0/100 0 reports checked 12/08/2026
Registrar (base domain) REGRU-RU RU(RU)
दुरुपयोग संपर्कabuse@hostsailor.com
IP पता 185.82.200.115 NL
भौगोलिक स्थानNL Naaldwijk, NL
नेटवर्कAS60117 · Host Sailor Ltd
रिवर्स IPviewdns.info → rapiddns.io →
Registration (base domain)org-fm-678-223-176-122345492-182-342.ru · निर्मित 28/03/2026 (146d) Expires 28/03/2027
Elapsed Since First Report 19 days
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: असत्यापित.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला29/05/2026
DOM Analysisanalyzed 30/05/2026score 0/100
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://runescapearts.forums.events.quitting.giveaway.gul.org-fm-678-223-176-122345492-182-342.ru/portal/medieval-competitors-voting-authentication-yit54ui5tu6y74iuy2iutjgh23441
नेमसर्वरns1.ihordns.netns2.ihordns.net
TLS Fingerprint
TLS Observationvalid from 06/05/2026scanned 30/05/2026
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

18 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed Previous stored snapshot: 18 detections
ADMINUSLabs
alphaMountain.ai
BitDefender
Chong Lua Dao
Cluster25
CRDF
साइरेडार
ईएसईटी
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
कास्परस्की
Lionic
SOCRadar
सोफोस
VIPRE
वेबरूट

साक्ष्य और बाहरी रिपोर्टें

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/runescapearts.forums.events.quitting.giveaway.gul.org-fm-678-223-176-122345492-182-342.ru"
  title="PhishDestroy threat report for runescapearts.forums.events.quitting.giveaway.gul.org-fm-678-223-176-122345492-182-342.ru"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>