VirusTotal
14 / 91
“Outlook”
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@hetzner.com.
The latest stored availability evidence still shows the domain reachable; 8 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
scsalud.closer.website — Terakhir diketahui aktif (HTTP 301). Peniruan identitas merek: Microsoft; Jenis penipuan: Tech Support Scam. Ringkasan bukti: VirusTotal 14/91 (ADMINUSLabs, Chong Lua Dao, CyRadar, ESET, Forcepoint ThreatSeeker); URLQuery 3 alerts; CF Radar malicious; PhishDestroy score 100/100. Registrar: Go Daddy.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| CIRA Canadian Shield DNS | scsalud.closer.website |
malicious | Sinkholed |
| Cloudflare DNS | scsalud.closer.website |
malicious | Sinkholed |
| DNS4EU | scsalud.closer.website |
malicious | Sinkholed |
The domain scsalud.closer.website hosted a fraudulent web page titled "Outlook," impersonating the Microsoft brand to execute a tech support scam. This type of threat deceives visitors into believing they are accessing a legitimate Microsoft login page, aiming to steal credentials or personal information under the pretense of providing technical assistance.
Technical analysis reveals the site was flagged by 14 out of 95 VirusTotal vendors, with detections from ADMINUSLabs, Criminal IP, alphaMountain.ai, Cluster25, and CyRadar. It is listed on one blocklist. The domain was registered through Go Daddy, LLC and created on February 21, 2026. The site resolved to IP address 94.130.129.186, located in Germany and hosted by AS24940 Hetzner Online GmbH. It used an SSL certificate issued by Let's Encrypt (R13) and nameservers ns1.closer.ws and ns2.closer.ws.
The domain is currently offline and inaccessible. Based on the impersonation of Microsoft and the high detection rate across security vendors, the risk level is assessed as high. Users who may have interacted with this site should consider their credentials compromised and take appropriate security measures.
Data pengamatan perbandingan crawler versus browser yang telah disimpan untuk host ini, ditambah pemeriksaan sidik jari secara real-time untuk sistem distribusi lalu lintas bergaya Keitaro.
nginxCatatan pemindai: redirect: raw=redirect_301; http=301; via=http_proxy; location=https://scsalud.closer.website/; server=nginx
For the registrable domain closer.website behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
ns2.closer.wsLocation describes the IP network.
29254bca99ccefc0db8310f2291ea3b1e49fc42bc60c128833b122e7a2f6de4ecloser.websiteSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of scsalud.closer.website · checked Mar 2, 2026
15 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Dilaporkan oleh 1 anggota komunitas; pertama terlihat 18/01/2026
PD-20260118-690DCB Recipient: abuse@hetzner.com Policy Violations: Acceptable Use Policy (AUP): The domain scsalud.closer.website is engaged in phishing activities, which directly contravenes the AUP's prohibition of illegal activities, fraud, and deception. Terms of Service (TOS): The hosting provider reserves the right to suspend or terminate services for violations. The ongoing use of this domain for phishing purposes constitutes a clear violation of the TOS. Applicable Laws (Unknown): Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which includes phishing schemes aimed at obtaining sensitive information. Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities via electronic communications, including phishing attempts. CAN-SPAM Act (15 U.S.C. § 7701): This act regulates commercial email and prohibits deceptive practices in electronic communications, which are inherent in phishing activities. Regulatory Note: Failure to take immediate action against this domain may result in liability for facilitating illegal activities, including potential regulatory scrutiny and enforcement actions. It is imperative to comply with your AUP and TOS to mitigate legal risks.
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Template-based draft · optional AI wording assistance requires separate consent
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanLaporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauPantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive