app[.]hubdates[.]icu
“Connecting...”
Riepilogo delle prove
Analysis of the domain app.hubdates.icu indicates it was involved in a tech support scam impersonating Microsoft. The domain was registered on February 21, 2026, and resolved to the IP address 185.176.220.7, hosted by 2 Cloud Ltd. (AS39845) in Latvia. The SSL certificate used was classified as R13, a type often associated with low-cost or automated certificate issuance common in phishing infrastructure. At the time of assessment, the domain was offline, with a page title of 'Connecting...', which may suggest an incomplete or transitional state prior to takedown.
Fifteen of 95 security vendors on VirusTotal flagged the domain as malicious, and it appeared on at least one security blocklist, specifically PhishDestroy. Gridinsoft assigned a trust score of 0 out of 100, further supporting its classification as high-risk. No evidence of widespread Safe Browsing or OTX coverage was provided, but the combination of vendor detections and blocklist presence indicates a coordinated response to the threat. The exact content and functionality of the site remain unconfirmed, as no forensic capture or behavioural analysis was supplied.
However, the available data—including the 'tech support scam' classification and Microsoft impersonation—align with known patterns of fraudulent call-center or pop-up scams designed to deceive users into contacting fake support agents. Defenders should treat this domain as confirmed malicious infrastructure and ensure it is blocked at the DNS and network layers. Monitoring for re-registration or changes in hosting is recommended, given the domain's recent creation and the persistent nature of such campaigns.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 10/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ZONA SHORTDOT · PROVE PUBBLICHE
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo