dev[.]about[.]daorel[.]ch
dev.about.daorel.ch 피싱 및 보안 점검
“Valo.taxi - नकद और सवारी”
dev.about.daorel.ch — 클로킹됨 · 접근 가능 (HTTP 502). 증거 요약: VirusTotal 11/91 (BitDefender, CRDF, ESET, Fortinet, G-Data); URLQuery 1 alert; cloaking observed; PhishDestroy score 100/100.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy identifies dev.about.daorel.ch as an active generic phishing domain under investigation, linked to a potential tech support scam campaign targeting unsuspecting users. The subdomain continues to pose generic phishing risks, specifically mimicking legitimate technical support interfaces to harvest user credentials or deploy malicious payloads. No specific drainer kit has been confirmed at this stage, but historical patterns suggest misuse of browser notifications or fake system alerts to trick users into granting permissions or downloading rogue executables. The threat type remains classified as generic_phishing due to the absence of direct brand impersonation in observed samples; however, the modus operandi aligns with known support-themed phishing lures. The domain dev.about.daorel.ch exhibits several concerning technical indicators. VirusTotal currently reports 6/95 detection engines flagging the site, indicating evasion against common antivirus and URL reputation systems. The domain resolves to IP address 185.149.120.183, hosted on infrastructure linked to prior low-reputation activity. The SSL certificate, issued by Let’s Encrypt, provides a superficial veneer of legitimacy, though automated certificates are frequently abused in short-lived phishing campaigns. While the exact creation date and registrar were not provided in the dataset, the domain’s recent activity flag (seed 5ad806) and lack of long-term presence suggest opportunistic deployment. Google Safe Browsing (GSB) status is not confirmed available in this snapshot, and no blocklist aggregator currently includes this domain in its feeds. Its current threat level is marked as under_investigation, pending further behavioral correlation or sinkhole analysis. Currently, the domain remains active and responsive, with no evidence of takedown or mitigation by hosting providers. PhishDestroy assesses the domain as posing a MEDIUM immediate risk due to its exploitation vector potential through browser abuse or social engineering. Users are strongly advised to avoid accessing dev.about.daorel.ch and to treat any related support-themed pop-ups or emails as suspicious. Security teams should monitor IP 185.149.120.183 and the ASN associated with this infrastructure for correlated malicious activity. Given the low detection rate and rapid deployment lifecycle, proactive blocking at the DNS or network level is recommended to prevent accidental exposure. The risk remains under investigation and may escalate if evidence of credential harvesting or malware delivery emerges
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | dev.about.daorel.ch |
phishing | Phishing Block |
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 신뢰도 100%Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com 신뢰도 100%Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 신뢰도 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 신뢰도 100%DDoS-Guard is a Russian Internet infrastructure company which provides DDoS protection, content delivery network services, and web hosting services.
ddos-guard.net 신뢰도 100%VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of dev.about.daorel.ch · checked May 3, 2026
증거 및 외부 보고서
PD-20260503-2018C0 Recipient: abuse@ddos-guard.net 이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.