xn--dofus-rero-3cc[.]com
“DOFUS RETRO - HECATOMBE PANDALANCIEN”
xn--dofus-rero-3cc.com — Belum terverifikasi. Ringkasan bukti: VirusTotal 12/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); CF Radar malicious; PhishDestroy score 98/100. Registrar: Hosting Concepts.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain www.xn--dofus-rero-3cc.com was observed delivering a generic_phishing campaign targeting users of the online game DOFUS RETRO. The site is currently classified as high risk and remains active as of the report date, July 12, 2026.
Technical profiling shows the domain resolves to the IPv4 address 216.198.79.1, hosted within the Amazon.com, Inc. network (AS16509) in the United States. The domain was registered on December 03, 2025 through Hosting Concepts B.V. d/b/a Registrar.eu and uses Vercel’s DNS service (ns1.vercel-dns.com, ns2.vercel-dns.com). No TLS certificate was detected, and HTTP requests return a 200 status code.
Open source intelligence indicates the page title “DOFUS RETRO - HECATOMBE PANDALANCIEN” appears on the landing page, matching the advertised brand. The domain appears on one security blocklist and has been flagged by PhishDestroy. Gridinsoft assigned a trust score of 0 out of 100. AlienVault OTX lists the domain in fifteen separate threat pulses. VirusTotal analysis recorded four positive detections out of ninety‑five scanned security engines.
While the available data confirms the presence of phishing infrastructure, the exact content and credential‑harvesting mechanisms have not been publicly released. Absence of an SSL certificate may facilitate interception of traffic, but it also suggests a low‑cost deployment. No additional malicious payloads or command‑and‑control endpoints have been identified at this time.
Defenders should immediately block connections to www.xn--dofus-rero-3cc.com and its resolved IP address 216.198.79.1 at network perimeter and endpoint filters. Continuous monitoring of related ASN traffic and Vercel DNS queries is advised to detect potential replication. Updating URL filtering lists with the current blocklist entries and alerting SOC teams to any user‑initiated requests for the domain will reduce exposure to credential theft.
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Bukti Terarsip
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive