rohab[.]ro
“Hacked By MR.GREEN”
証拠の概要
The domain rohab.ro presents a compromised web page with the title "Hacked By MR.GREEN," indicating a defacement incident where an attacker has replaced the original site content. The threat posed is that the compromised domain could be used to host malicious content, distribute malware, or serve as a landing page for phishing campaigns, leveraging the defacement as a signal of control.
Technical analysis reveals 6 out of 95 VirusTotal vendors flagged the domain as malicious, including ADMINUSLabs, alphaMountain.ai, CRDF, CyRadar, and ESET. The domain is registered with Romarg SRL, hosted on IP 50.87.229.231 in the United States under AS46606 Unified Layer, and uses nameservers ns1.bluehost.com and ns2.bluehost.com. It was created on February 21, 2026, and employs a Let's Encrypt SSL certificate (R13). One blocklist entry exists.
The site is currently offline, reducing immediate risk of active exploitation. However, the recent creation date, defacement, and multiple vendor detections indicate a high risk level for any future reactivation or redirection. Monitoring is recommended.
送信済み証拠のスナップショット
- 送信日時
- 台帳レコード
- 1
- ケース ID
PD-20260128-57B873- 取得ページのタイトル
- Hacked By MR.GREEN
- PDF 資料
- 証拠 PDF
証拠全文
Section 3.1 of the AUP: The domain rohab.ro is engaged in phishing activities, which directly contravenes the prohibition against illegal activities and fraud.
Section 5 of the TOS: The hosting provider reserves the right to suspend or terminate services for violations, and the ongoing phishing activities constitute a clear breach of this policy.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is relevant in cases of phishing.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals using electronic communications, including phishing.
CAN-SPAM Act (15 U.S.C. § 7701): This act regulates commercial email and prohibits misleading information, which is applicable to phishing schemes.
Regulatory Note: Non-compliance with your Acceptable Use Policy and applicable laws may expose your organization to legal liability and regulatory scrutiny. Immediate action is recommended to mitigate potential risks.
Data Coverage
ネットワークセキュリティインテリジェンス
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | rohab.ro |
malicious | Sinkholed |
脅威対応 Pipeline
ブロックリストの確認範囲
監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月11日
検出タイムライン
使用技術
高確信度で特定された技術:1 件
VirusTotalによる分析
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください