darkred-hippopotamus-178224[.]hostingersite[.]com
“Detran-ES · Serviços Rápidos”
darkred-hippopotamus-178224.hostingersite.com — Contenuto non disponibile. Riepilogo delle prove: VirusTotal 1/94 (LevelBlue); PhishDestroy score 55/100. Registrar: Hostinger.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy identifies darkred-hippopotamus-178224.hostingersite.com as a suspicious website currently under investigation for hosting generic phishing activity. The domain employs a crypto drainer kit, a malicious tool designed to siphon cryptocurrency from unsuspecting victims by intercepting wallet transactions and replacing them with fraudulent ones. No specific brand impersonation or well-known drainer framework has been confirmed yet, but the operational tactics align with common crypto-draining schemes targeting decentralized finance (DeFi) users and cryptocurrency traders. The domain's naming convention—using randomized adjectives and nouns—is a known evasion tactic to avoid immediate blacklisting while mimicking legitimate hosting services.
Technical indicators for this domain reveal several red flags. VirusTotal currently shows 0 detections out of 95 scanning engines, indicating it has not yet been widely flagged by security vendors, though this is not uncommon for newly activated threats. The domain resolves to IP address 2.57.91.73, which is operated by HOSTINGER operations, UAB, a legitimate hosting provider that may unknowingly host malicious content due to compromised or fraudulent account usage. The domain was registered on June 22, 2023, making it nearly a year old, which provides sufficient time for threat actors to refine their operations. Google Safe Browsing (GSB) has not yet flagged the domain, and no public blocklist entries were detected during the initial assessment. The presence of a DigiCert SSL certificate adds a false sense of legitimacy, as threat actors often leverage trusted certificate authorities to appear more credible to potential victims.
This domain remains active and is currently under investigation by PhishDestroy’s threat intelligence team. No official blocklisting or takedown actions have been initiated yet, but proactive monitoring is ongoing. While the immediate risk level is classified as 'under_investigation,' the combination of a crypto drainer kit, unflagged status, and hosting on a reputable provider suggests potential for escalation. Users are strongly advised to avoid interacting with this domain, verify any unsolicited cryptocurrency-related links, and use security tools such as wallet defenses or transaction simulations to detect drainer scripts. Remaining risk is moderate due to the domain’s age and undetected status, warranting heightened caution among cryptocurrency users.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Registration: hostingersite.com
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain hostingersite.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 3 identified
Hostinger is an employee-owned Web hosting provider and internet domain registrar.
www.hostinger.com Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo