Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@timeweb.ru.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
remfix-santeh[.]online
“Success!”
remfix-santeh.online — Ultimo attivo conosciuto (HTTP 200). Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 13/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 99/100. Registrar: Registrar of Domain Na….
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy has identified remfix-santeh.online as a generic phishing domain designed to deceive visitors with a fraudulent 'Success!' page. This domain does not impersonate a specific brand but instead uses a generic lure to trick users into believing they have achieved some form of success, likely to harvest credentials or personal information. The domain was created on June 15, 2026, and is registered through Registrar of Domain Names REG.RU LLC. It resolves to IP address 147.45.157.4 and uses an SSL certificate issued to Hestia Control Panel / panel.sites.ru.
Technical analysis reveals that VirusTotal flags this domain with a score of 2 out of 95 security vendors, indicating some but not widespread detection. The domain appears on three security blocklists, and its current status is offline, meaning it has been taken down. No Google Safe Browsing status is available, but the combination of low detection rate and blocklist presence suggests moderate risk. The IP 147.45.157.4 may host other malicious content, so further investigation is warranted.
Currently, the domain is offline, which reduces immediate threat to users. However, similar domains may appear under different names. PhishDestroy recommends that users avoid interacting with unsolicited 'Success!' pages and never enter personal information on such sites. Organizations should monitor for similar domains and block the IP 147.45.157.4 if not already. Remaining risk is low due to domain takedown, but vigilance is advised as the threat actor may register new domains.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Dati e relazioni esterne
PD-20260617-32042C Recipient: abuse@timeweb.ru Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo