auth-id[.]css[.]register2564[.]org
auth-id.css.register2564.org 피싱 및 보안 점검
“Domain Default page”
auth-id.css.register2564.org — 콘텐츠를 사용할 수 없음 (HTTP 502). 브랜드 사칭: Base; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 12/95 (alphaMountain.ai, BitDefender, CyRadar, ESET, Fortinet); PhishDestroy score 91/100. 등록기관: PDR.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Evidence Analysis
Analysis of auth-id.css.register2564.org indicates that the domain was registered on November 17, 2021 through PDR Ltd. d/b/a PublicDomainRegistry.com and resolves to the IPv4 address 27.254.145.131, which is announced by AS9891 (CS LOXINFO Public Company Limited) and geolocated to Thailand. The domain is presently offline, and no TLS certificate was observed, meaning any attempt to establish an encrypted session would fail. The sole page title returned from the HTTP response is “Domain Default page”, providing no further context about the content served. The site is classified as a brand‑impersonation campaign targeting the “base” brand, and it has been listed on at least one public phishing blocklist, specifically PhishDestroy.
VirusTotal reports that 12 of 95 security vendors have flagged the domain, reinforcing the malicious assessment. Reputation services assign extremely low trust scores: Scamadviser rates the domain 1/100 and Gridinsoft 0/100, reflecting a high likelihood of abuse. Nameservers th113.hostatom.com and th114.hostatom.com are associated with the hosting provider, but no additional infrastructure details are available.
Because the domain is already taken offline, active mitigation is limited; however, defenders should continue to block the domain at DNS and proxy layers, monitor for any resurrection or similar patterns in newly registered domains using the same registrar or hosting infrastructure, and update detection rules to incorporate the observed indicators such as the IP address 27.254.145.131, the registrar PDR Ltd., and the specific nameserver set. Uncertainty remains regarding the exact phishing landing page and whether credential‑harvesting kits were employed, as no page content was captured before the takedown. Ongoing vigilance is advised.
데이터 적용 범위13 recorded checks
보안 신호
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
Registration: register2564.org
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For the registrable domain register2564.org behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 분석
증거 및 외부 보고서Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.