js12130[.]vip
js12130.vip — Contenuto non disponibile (HTTP 503). Riepilogo delle prove: VirusTotal 5/91 (alphaMountain.ai, Bfore.Ai PreCrime, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 78/100. Registrar: Gname.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
The domain js12130.vip was registered on 15 March 2026 through Gname.com Pte. Ltd. and is currently hosted on the IP address 172.65.235.97. The authoritative name servers for the zone are a.share-dns.com, a11.share-dns.com, b.share-dns.net, and b11.share-dns.net, indicating use of a shared DNS service. VirusTotal reports that one out of ninety‑five scanning engines has flagged the domain, suggesting at least minimal detection by security vendors. The domain is listed on a single public blocklist and has been actively blocked by the PhishDestroy mitigation platform, confirming that it is being treated as malicious by at least one commercial anti‑phishing service. The domain remains active as of the report date, 21 July 2026, and no evidence of takedown or sink‑hole operation has been observed. Analysis of the available data does not reveal a specific brand or service that the site is attempting to impersonate; the page title and content have not been publicly disclosed. Consequently, the exact phishing campaign vector, credential‑stealing technique, or targeted user demographic cannot be confirmed at this time. The limited detection footprint—only one vendor flag and a single blocklist entry—may indicate a low‑profile operation or recent deployment that has not yet been widely shared among threat‑intel feeds. Defenders should add the IP address 172.65.235.97 and the domain js12130.vip to URL filtering and DNS sinkhole policies. Monitoring of the shared DNS nameservers for additional domains that resolve to the same IP can help uncover related infrastructure. Organizations using web‑proxy or secure web‑gateway solutions should ensure that traffic to this domain is blocked, and incident response teams should remain alert for any credential‑theft attempts that reference the domain. Continuous re‑evaluation of VirusTotal and other multi‑engine scanners is recommended, as additional detections may emerge as the campaign matures.
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Dati e relazioni esterne
PD-20260721-1CFCB2 Recipient: complaint@gname.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo