site-3fejh9hgr[.]godaddysites[.]com
“Anmeldung UPC Mail”
site-3fejh9hgr.godaddysites.com — 콘텐츠를 사용할 수 없음. 브랜드 사칭: Godaddy. 증거 요약: VirusTotal 13/93 (alphaMountain.ai, BitDefender, CRDF, Forcepoint ThreatSeeker, G-Data); PhishDestroy score 89/100. 등록기관: GoDaddy.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Analysis as of July 24 2026 indicates that the sub‑domain site-3fejh9hgr.godaddysites.com was used to host a phishing page titled “Anmeldung UPC Mail”. The domain is registered through GoDaddy.com, LLC and has been active since 18 Nov 2013. DNS resolution points to IP 13.248.243.5, which belongs to Amazon.com, Inc. (AS16509) and is located in the United States. The host is served behind GoDaddy’s default nameservers cns1.secureserver.net and cns2.secureserver.net, and the TLS certificate presented is a Go Daddy Secure Certificate Authority – G2 issued to GoDaddy.com, Inc., confirming the legitimate certificate chain but offering no protection against malicious content. The page was flagged by PhishDestroy and is listed on one security blocklist.
VirusTotal scans show that 13 of 93 antivirus or URL‑reputation engines flagged the domain, indicating a moderate detection rate. HTTP probing returned a 404 status code, and the current operational status is recorded as offline, suggesting the phishing page has been taken down. Nonetheless, the historical evidence of phishing activity remains relevant for threat‑intel correlation. Defenders should continue to monitor the IP address 13.248.243.5 for any re‑use in future campaigns, especially since the Amazon hosting environment is frequently leveraged for transient malicious infrastructure.
Existing blocklist entries should be maintained, and any outbound traffic to this host should be denied or logged. Because the domain’s registration details are publicly available and the SSL certificate is valid, reputation‑based filtering alone may not be sufficient; supplemental URL‑reputation checks and cross‑reference with the 13 VirusTotal detections are advisable. In environments where users may receive emails purporting to be from UPC, security awareness training should highlight the “Anmeldung UPC Mail” title as a known indicator of compromise. Continuous review of GoDaddy‑hosted sub‑domains for similar patterns is recommended.
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
Registration: godaddysites.com
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For the registrable domain godaddysites.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 분석
보관된 증거
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.