aquiverif-outoksmail2025[.]gamer[.]gd
“Bienvenido”
aquiverif-outoksmail2025.gamer.gd — 확인되지 않음. 브랜드 사칭: Outlook; 사기 유형: Tech Support Scam. 증거 요약: VirusTotal 14/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 97/100. 등록기관: Key Systems.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
This domain, aquiverif-outoksmail2025.gamer.gd, is assessed as an elevated-risk brand impersonation threat specifically designed for credential theft targeting Outlook users. Analysis indicates the infrastructure was deployed to mimic legitimate Microsoft authentication portals, with the page title 'Bienvenido' suggesting a localized attack vector aimed at Spanish-speaking users. The domain exhibits multiple high-risk indicators that align with known credential harvesting campaigns. Infrastructure analysis reveals the domain was registered on July 25, 2025, through Key Systems GmbH, a registrar frequently observed in transient phishing operations. It resolves to the IP address 185.27.134.231, hosted on AS34119 (Wildcard UK Limited) in Great Britain, an autonomous system previously associated with bulletproof hosting services. The domain appears on two security blocklists, PhishDestroy and PhishingDB, while VirusTotal detection metrics show 17 out of 95 security vendors flagging the domain as malicious. Notably, the absence of an SSL certificate further reduces legitimacy, as modern credential theft campaigns typically employ encryption to evade detection. To mitigate the risk posed by this credential theft operation, organizations should implement immediate countermeasures. Network-level protections should block both the domain and its resolving IP address (185.27.134.231) at firewalls and DNS resolvers. Security teams are advised to search authentication logs for connections originating from this domain or IP, particularly those occurring after July 25, 2025. End-user education should emphasize the risks of localized phishing pages, especially those using welcome messages in non-English languages. Given the domain's current offline status, continuous monitoring for re-emergence under similar naming conventions is recommended, as threat actors frequently reuse infrastructure patterns in subsequent campaigns.
보안 신호
위협 대응 Pipeline
공개 차단 목록 상태
VirusTotal 분석
보관된 증거
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.