treshs-ddlh-3f916985f3fc.herokuapp.com
“Welcome to Suite”
treshs-ddlh-3f916985f3fc.herokuapp.com — 最後に確認されたアクティブな状態 (HTTP 200). 証拠の概要: VirusTotal 11/89 (alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data); Google Safe Browsing flagged; PhishDestroy score 100/100.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
証拠の概要
PhishDestroy first observed treshs-ddlh-3f916985f3fc.herokuapp.com on Sep 17, 2026. The captured page title is “Welcome to Suite”. Current evidence score: 100/100 (critical).
Positive findings are stored from 2 sources: VirusTotal and Google Safe Browsing. VirusTotal recorded 11 detections among 89 engines: alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data, Google Safe Browsing, Kaspersky, LevelBlue, Lionic, Sophos, VIPRE on Sep 22, 2026 at 22:11 UTC. Google Safe Browsing flagged the domain: Social Engineering on Sep 23, 2026 at 04:00 UTC. Non-positive and contextual checks: The separate external-blocklist snapshot contained no matches on Sep 23, 2026 at 02:20 UTC.
HTTP 200 was recorded on Sep 23, 2026 at 01:00 UTC. At collection time, the hostname resolved to 3.209.172.72 on AS14618 (Amazon.com, Inc.). The recorded endpoint location is Ashburn, US. The stored server header is Heroku. TLS metadata lists Amazon / Amazon RSA 2048 M01 as the certificate issuer with validity through Jan 29, 2027; checked Sep 23, 2026 at 01:02 UTC.
The content indicators and 2 positive source findings support the current phishing classification. The stored fields do not identify an impersonated brand or victim interaction.
Forensic History & Detection Timeline
-
Status Check Sep 23, 2026 · 06:00 UTCTelemetry event observed.
-
Threat First Observed Sep 23, 2026 · 00:03 UTCDomain ingestion complete. Initial state is marked as alive.
脅威対応 Pipeline
公開ブロックリスト登録状況
探知・回避の分析
クローキングおよびトラフィック分散の確認
まだスキャンされていません
クローラーとブラウザの間に違いは見られていない
このホストに関するクローラーとブラウザの観測データの蓄積に加え、ケイタロ式トラフィック分散システム向けのリアルタイムフィンガープリントチェック。
- 保存されたクローキングフラグ
- まだスキャンされていません
- 前回のクローキングスキャン
- スキャナーが検知したサーバーヘッダー
Heroku
スキャナーに関する注記: alive_content: raw=ok; http=200; via=https_proxy; server=Heroku
ドメイン・インテリジェンス
技術詳細DNS、SSL SAN、タイムスタンプ
VirusTotalによる分析
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください