MALICIOUS — CRITICAL
aco07ui[.]vip
The domain aco07ui.vip was registered on 26 November 2025 through Gname.com Pte.
- VirusTotal
- 5/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilità
- Ultimo attivo conosciuto · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is complaint@gname.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
aco07ui.vip — Ultimo attivo conosciuto (HTTP 301). Tipo di truffa: Generic Phishing. Riepilogo delle prove: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. Registrar: Gname.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
The domain aco07ui.vip was registered on 26 November 2025 through Gname.com Pte. Ltd. and is currently active, resolving to 172.67.182.141, an IP owned by Cloudflare (AS13335) located in the United States. DNS resolution uses the Cloudflare nameservers bruce.ns.cloudflare.com and sreeni.ns.cloudflare.com. The site presents an HTTP 301 redirect and serves a TLS certificate issued by Google Trust Services under the WE1 profile, indicating a valid HTTPS endpoint. The page title returned from the host is "SILVERPS"; no additional content has been publicly disclosed. Reputation scoring is extremely low, with Gridinsoft assigning a trust score of 0/100. Threat intelligence sources flag the domain: AlienVault OTX lists it in one pulse, and VirusTotal reports detections from 2 of 91 security vendors. It appears on three public blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL. While the exact phishing campaign details (e.g., targeted brands or credential‑stealing forms) remain unknown, the combination of recent registration, low trust score, active blocklist presence, and confirmed detections classifies the domain as a high‑risk generic phishing infrastructure. Defenders should block the domain and its associated IP at network perimeters, monitor DNS queries for the listed nameservers, and update endpoint protection signatures to include the observed indicators. Continuous observation is advised to capture any emerging payloads or victimization patterns.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | aco07ui.vip |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
PD-20260617-85C098 Recipient: complaint@gname.com Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.