enel-rimborso[.]replit[.]app
“500 Server Error”
enel-rimborso.replit.app — 확인되지 않음. 증거 요약: VirusTotal 16/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Cluster25); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. 등록기관: GOOGL-2 (ASN: 396982).
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Analysis of enel-rimborso.replit.app indicates a high-risk phishing domain targeting Enel customers, currently offline as of July 24, 2026. The domain, hosted on Google Cloud infrastructure (IP 34.117.33.233, AS396982 Google LLC), was flagged by 16 of 95 security vendors on VirusTotal and blocked by PhishDestroy. Google Safe Browsing classified the site as social engineering, aligning with its apparent billing refund theme. The domain's HTTP status returned a 500 Server Error, suggesting either a takedown or backend misconfiguration. SSL certificate issued by Google Trust Services (WR3) confirms encrypted connections, though this does not mitigate the phishing intent.
Infrastructure analysis reveals the domain was registered through Google's ASN 396982, leveraging Google Cloud, HSTS, and HTTP/3 technologies. No nameservers were detected (NS_NOT_FOUND), which may indicate a temporary or incomplete setup. The Scamadviser trust score of 1/100 further supports its malicious classification. While the exact content of the phishing kit remains unanalyzed, the domain name and Safe Browsing flags strongly suggest it impersonated Enel's billing or refund portal to harvest credentials or payment details.
Defenders should treat this domain as compromised and prioritize blocking at DNS and web gateway levels. The IP 34.117.33.233 and associated Google Cloud infrastructure should be monitored for additional phishing domains. Given the domain's current offline status, further forensic analysis may be limited, but historical WHOIS or passive DNS data could reveal registration patterns or linked campaigns. No evidence of lateral movement or C2 infrastructure was observed in the provided data.
보안 신호
네트워크 보안 인텔리전스
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
Registration: replit.app
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For the registrable domain replit.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
사용 기술 · 5 identified
Suite of cloud computing services running on Google infrastructure.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Content delivery network built on Google global edge infrastructure.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 분석
보관된 증거
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.