enterpriseenrollment.berkleyoll-gas.com
“Service unavailable”
enterpriseenrollment.berkleyoll-gas.com — 마지막으로 알려진 활성 (HTTP 302). 증거 요약: VirusTotal 5/89 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, PhishFort, SOCRadar); PhishDestroy score 83/100. 등록기관: Wild West Domains.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
증거 요약
enterpriseenrollment.berkleyoll-gas.com is a subdomain of berkleyoll-gas.com. PhishDestroy first observed the hostname on Sep 16, 2026. The captured page title is “Service unavailable”. Current evidence score: 83/100 (critical).
One source contains a positive finding: VirusTotal. VirusTotal recorded 5 detections among 89 engines: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, PhishFort, SOCRadar on Sep 23, 2026 at 04:47 UTC. Non-positive and contextual checks: The separate external-blocklist snapshot contained no matches on Sep 23, 2026 at 02:20 UTC. Google Safe Browsing returned no flag on Sep 23, 2026 at 04:47 UTC.
HTTP 302 was recorded on Sep 23, 2026 at 01:36 UTC. Registration records for the registrable domain berkleyoll-gas.com list Wild West Domains, LLC as the registrar and Sep 10, 2026 as the creation date. Registration preceded first observation by 6 days. At collection time, the hostname resolved to 13.74.111.192 on AS8075 (Microsoft Corporation). The recorded endpoint location is Dublin, IE. TLS metadata lists Microsoft Corporation / Microsoft TLS G2 RSA CA OCSP 04 as the certificate issuer with validity through Feb 25, 2027; checked Sep 21, 2026 at 13:02 UTC.
Stored content provides classification context, but only one source contains a positive finding. The stored fields do not identify an impersonated brand or victim interaction.
Forensic History & Detection Timeline
-
Threat First Observed Sep 21, 2026 · 12:03 UTCDomain ingestion complete. Initial state is marked as alive.
위협 대응 Pipeline
공개 차단 목록 상태
탐지 회피 분석
클로킹 및 트래픽 분산 점검
아직 스캔되지 않았습니다
크롤러와 브라우저 간의 차이는 아직 보고된 바가 없습니다.
이 호스트에 대해 저장된 크롤러 대 브라우저 관측 데이터와, 케이타로 스타일의 트래픽 분배 시스템을 위한 실시간 지문 확인 정보.
- 저장된 은신 플래그
- 아직 스캔되지 않았습니다
- 마지막 은폐 스캔
스캐너 메모: redirect: raw=redirect_302; http=302; via=https_proxy; location=https://intune.microsoft.com/
도메인 인텔리전스
기술 세부 정보DNS, SSL SAN, 타임스탬프
VirusTotal 분석
커뮤니티 인텔리전스
커뮤니티 신고 1건
범주PHISHING
The PhishFort Detection System has flagged this as a domain threat, classified as null. Threat detected at 2026-09-16T05:50:32.297Z.
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.