ai[.]sadman[.]vip
ai.sadman.vip — Conteúdo indisponível (HTTP 502). Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 16/91 (BitDefender, Cluster25, CRDF, CyRadar, ESET); PhishDestroy score 95/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain ai.sadman.vip is currently active and identified as a generic phishing site impersonating a fake login page. As of the latest assessment, the domain remains operational and poses a high risk to users who may be tricked into entering sensitive information. The exact brand being impersonated is not specified, but the nature of the threat suggests it could be targeting multiple brands or services.
Infrastructure analysis reveals that ai.sadman.vip is flagged by 16 of 95 security vendors on VirusTotal, indicating a significant level of suspicion among the cybersecurity community. The domain resolves to the IP address 104.21.72.222, which is located in the United States and is part of AS13335, owned by Cloudflare, Inc. The SSL certificate for the domain is issued by Google Trust Services / WE1, providing a false sense of security to unsuspecting users. The domain appears on 1 security blocklist and is blocked by PhishDestroy, a known cybersecurity service. The creation date of the domain is not provided, but the recent appearance on blocklists suggests it may be a relatively new threat.
Given the current active status of ai.sadman.vip, it is recommended that network administrators and security teams implement immediate blocking measures to prevent access to this domain. Users should be educated to verify the legitimacy of login pages they encounter, especially those that appear to be associated with well-known brands. Regular updates to security software and phishing detection tools are essential to mitigate the risk posed by this and similar threats. Additionally, organizations should monitor their network logs for any attempts to access this domain and take appropriate action to secure compromised accounts.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo