huo[.]be
“Earn rewards when you get started on OKX | My referral code: 97597037 | OKX Europe”
Riepilogo delle prove
On June 1, 2024, PhishDestroy identified huo.be as an active generic phishing domain engineered to harvest credentials through QR code redirections. The domain exhibits low sophistication yet remains unclassified by major blocklists, suggesting active targeting of unsuspecting users. No specific brand impersonation or drainer kit linkage has been observed, though the domain's resolution pattern aligns with campaigns distributing malicious QR codes in public spaces and digital flyers. The threat remains under investigation due to its elevated risk classification and absence of detection signatures. Immediate attention is warranted to prevent widespread compromise.
Technical indicators reveal huo.be was registered on January 25, 2019, through an unspecified registrar and resolves to the IP address 54.215.31.113 via a Let’s Encrypt SSL certificate. VirusTotal currently flags the domain with a clean score of 3/95 detections, while Google Safe Browsing (GSB) has yet to categorize it as malicious. The domain has not been listed on any major threat intelligence platforms, underscoring its stealthy deployment and limited exposure. These conditions suggest a newly activated or resurfaced campaign, leveraging long-standing domains to evade automated detection.
As of this advisory, huo.be remains active and unblocked by standard defenses, with no confirmed takedown efforts in progress. Security teams are advised to implement network-level blocking for the IP address 54.215.31.113 and the domain itself, while monitoring for QR code-based lures associated with this infrastructure. The residual risk remains elevated due to the absence of detections and the domain’s seemingly legitimate SSL certificate. Users should treat any QR codes leading to huo.be with extreme caution and report suspicious activity to their SOC for immediate triage. Proactive hunting for similar domains registered in 2019 is recommended to preempt potential spillover campaigns.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of huo.be · checked Apr 8, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo