hofaso[.]do
“.”
Riepilogo delle prove
The domain hofaso.do was registered on 21 February 2026 and is presently taken offline. DNS resolution points to the IPv4 address 185.231.33.130, which is announced by AS211720 belonging to Datashield, Inc. and geolocated to South Carolina, United States. The host presents an SSL certificate identified as R12, indicating the use of a short‑lived or self‑signed certificate typical of malicious infrastructure. Reputation services have flagged the domain: three of ninety‑three VirusTotal scanners reported detections, and the site is listed on a single external blocklist.
Additionally, the PhishDestroy feed has actively blocked the domain. The page title returned by HTTP queries is a single period (“.”), providing no insight into the intended impersonated brand or lure technique. No public evidence of the landing page content, credential‑capture forms, or redirect behavior is available, and the site does not appear to be serving active traffic at the time of analysis. Given the limited but concrete indicators—recent registration, dedicated IP under a known hosting ASN, low‑level TLS certificate, and multi‑vendor detection—it is prudent for defensive teams to treat hofaso.do as a malicious phishing vector until further remediation.
Organizations should add the domain and its resolving IP address to network‑level deny lists, enforce DNS filtering that incorporates the observed blocklist entry, and ensure that web‑proxy and email security gateways reference the PhishDestroy feed. Continuous monitoring of the IP space owned by Datashield, Inc. may reveal additional related artifacts. Because the site is offline, active response options such as sinkholing are not applicable, but threat‑intel correlation with other observed campaigns that share the same ASN or certificate profile could surface broader attribution.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo