Vai al rapporto di sicurezza
Sicurezza del dominio e intelligence sulle minacce
heat-tobacco.com favicon

heat-tobacco.com

“Buy Cigarettes Online | Heat-Tobacco Duty-Free Worldwide”

Verdetto di minaccia Critico Punteggio delle prove 81/100
Disponibilità Non verificato La raggiungibilità attuale non è verificata
Elenco delle minacce PhishDestroy archiviate Simulazione del marchio: Visa
OTX: 3 refs 11/09/2026 Visa
Actions API
⚠️
Suspicious Domain — Listed on PhishDestroy
Elenco delle minacce PhishDestroy archiviate. VirusTotal analysis stored; no vendor detections were recorded at check time. Prestare estrema cautela: non inserire credenziali o informazioni personali.
Riepilogo del rapporto

heat-tobacco.com — Non verificato. Simulazione del marchio: Visa; Tipo di truffa: Impersonation. Riepilogo delle prove: VirusTotal 0/89; PhishDestroy score 81/100. Registrar: eNom.

L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.

Riepilogo delle prove

CRITICO
Punteggio
81/100

PhishDestroy first observed heat-tobacco.com on Sep 11, 2026. Stored content metadata identifies Visa as the apparent target. The captured page title is “Buy Cigarettes Online | Heat-Tobacco Duty-Free Worldwide”. Stored page analysis classifies the content as impersonation. Campaign clustering links the hostname to the Unknown kit. Current evidence score: 81/100 (critical).

No independent positive verdict is present in the stored third-party checks. On Sep 20, 2026 at 17:31 UTC, VirusTotal recorded 0 detections among 89 engines; Google Safe Browsing returned no flag. AlienVault OTX listed 3 community pulse references (not vendor detections) on Sep 20, 2026 at 17:32 UTC. The separate external-blocklist snapshot contained no matches on Sep 20, 2026 at 18:20 UTC. URLScan completed without a malicious verdict (score 0) on Sep 19, 2026 at 03:30 UTC.

The collector marked the hostname reachable on Sep 19, 2026 at 22:01 UTC, but did not retain the HTTP response code. Registration records for the domain list eNom, LLC as the registrar and May 28, 2020 as the creation date. At collection time, the hostname resolved to 46.23.109.208 on AS213373 (IP Connect Inc). The recorded endpoint location is Amsterdam, NL. The stored server header is nginx/1.31.1. DOM analysis on Sep 19, 2026 at 02:20 UTC returned 81/100. The evidence archive retains 1 visual capture from PhishDestroy. TLS metadata lists Let's Encrypt / YR1 as the certificate issuer with validity through Nov 13, 2026; checked Sep 19, 2026 at 01:02 UTC.

The classification is based on stored page-analysis fields; no independent positive third-party verdict is stored.

VirusTotal
VirusTotal
0 det.
OTX references
URLScan
URLScan
Certificato TLS
Let's Encrypt / YR1
Età
6.3 yr
Stato osservato
Non verificato
PhishDestroy
Elenco da eliminare
Presente
Copertura dei dati VirusTotal checked — no detections recorded OTX 3 community references CF Radar scan completed URLScan capture rapporto memorizzato URLScan verdict Analisi completata TLS valid certificate, 53d WHOIS 77 mo old Screenshot cattura esterna

Forensic History & Detection Timeline

This timeline displays historical security and status checkpoints observed by the PhishDestroy automated monitoring network. It records domain lifecycle updates, scanner changes, and threat telemetry over time.
  1. VirusTotal Detections Update Sep 20, 2026 · 19:31 UTC
    VirusTotal scanner detections updated from 2 to 0. Resolved alerts: SOCRadar, VIPRE.
  2. Threat First Observed Sep 18, 2026 · 19:53 UTC
    Domain ingestion complete. Initial state is marked as alive.

Pipeline di risposta alle minacce

Scoperta
Checks
Reports
Disponibilità
12/14

Stato della lista di blocco pubblica

Evasion analysis

Cloaking & traffic-distribution check

Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.

Stored cloaking flag
Not yet scanned
Last cloaking scan

Scanner note: timeout: raw=timeout; http=0; via=http_proxy; error=HTTPConnectionPool(host='104.253.77.144', port=5566): Read timed out. (read timeout=7)

Live TDS fingerprint check
Seven Keitaro fingerprints plus a crawler-versus-browser comparison, run from the PhishDestroy scanner when this section scrolls into view.
Waiting

Acquisizione salvata · 1 source

Analisi dei domini

Dominio
URLScan Verdict Analisi completata score 0 report ↗
Server / ASN nginx/1.31.1 · AS213373 IP Connect Inc
Reputazione IP abuse score 63/100 44 reports Web SpamPort ScanHackingBrute-ForceBad Web BotWeb App Attack checked 19/09/2026
OTX Tags 2026-09activeall-domainsblocklistcontentcryptodominidrainerfraudmonthlyphishdestroyphishingscam
RegistrazioneCreato 28/05/2020
Dettagli tecniciDNS, SAN SSL, timestamp
Rilevato per la prima volta11/09/2026
DOM Analysisanalyzed 19/09/2026score 81/1001 brand signal
IoC Extractionscanned 19/09/20260 wallet · 0 Telegram IoCs
Nameservertodd.ns.cloudflare.com
MX Records10 emx.mail.ru
TLS Fingerprint
TLS Observationvalid from 15/08/2026scanned 19/09/2026
TLS SAN Domainswww.heat-tobacco.com
Favicon Hash
Titolo della pagina
Buy Cigarettes Online | Heat-Tobacco Duty-Free Worldwide
Impersonates
Visa
Certificato TLS
Valid transport encryption · Emesso da Let's Encrypt / YR1 · valid for 53 days
Tecnologie · 12 identified
Detected via Cloudflare Radar · Wappalyzer engine
Segnala questo dominio Invia le prove e contribuisci a proteggere gli altri

Analisi di VirusTotal

0 / I fornitori di sicurezza 89 hanno contrassegnato questo dominio
View on VT
Last analyzed First positive detection Previous stored snapshot: 2 detections
No VirusTotal engine marked the domain malicious in the stored analysis.
Analisi delle prestazioni del sito

Google PageSpeed Insights — mobile performance audit of heat-tobacco.com · checked Sep 20, 2026

55
Needs Work
Performance
FCP
9.3s
First Contentful Paint
LCP
13.73s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
121ms
Total Blocking Time
SI
9.3s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Intelligence della comunità

1 segnalazione della comunità

CategoriaOTHER

I am not a victim and lost no money. I placed a test order to document the payment mechanism and did not pay. I am reporting a network of fraudulent online tobacco stores and the cryptocurrency addresses they use to collect payment. WEBSITES heat-tobacco.com tobaccobase.com

Dati e relazioni esterne

Community Scam Report — ChainAbuse
1 report filed for heat-tobacco.com (1 written by a person) · category: Other · source checked
“I am not a victim and lost no money. I placed a test order to document the payment mechanism and did not pay. I am reporting a network of fraudulent online tobacco stores and the cryptocurrency addresses they use to collect payment. WEBSITES heat-tobacco.com tobaccobase.com cigsmoker.com cigarettesroad.com COLLECTION ADDRESSES USDT (TRC20): TC27nGjYFbxRehEQAojRBT8HTkdh1wEZ6R Bitcoin: 1P7WEgF8sZmcQ7cwiUNSV8gdP57XrYZzJv The BTC address has received 0.12697152 BTC across 161 transact”
— reported by Anonymous on Sep 11, 2026 · Source: ChainAbuse (TRM Labs) — full report and evidence there.

Questo sito ti ha influenzato in qualche modo?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.

Europol
Trova il canale di segnalazione ufficiale per il tuo paese dell'UE
National police directory
Attenzione ai truffatori che promettono il recupero dei fondi! I criminali possono contattare nuovamente le vittime fingendo di essere investigatori, avvocati o agenti di recupero. Non pagare commissioni anticipate né condividere credenziali. Scopri di più sulle frodi relative ai sussidi di recupero →

Segnalalo alle autorità locali

Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.

Elenco di 97 paesi
Bozza assistita dall'intelligenza artificiale: i dettagli dell'incidente vengono elaborati dal fornitore di intelligenza artificiale Controllalo e invialo tu stesso

Verifica qualsiasi dominio

Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica

Scansiona ora

Segnala un tentativo di phishing

Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità

Segnala

Feed in tempo reale sulle minacce

Segnalazioni recenti di phishing e modifiche osservate della disponibilità

Monitora

Rimani informato, rimani al sicuro

Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo

Feed in tempo reale sulle minacce Contesta questo annuncio
HTML · IFRAME

Incorpora questo rapporto

Condividi queste informazioni sulle minacce sul tuo sito web o sul tuo blog

embed.html
<iframe
  src="https://phishdestroy.io/it/embed/domain/heat-tobacco.com"
  title="PhishDestroy threat report for heat-tobacco.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>