aster-ex[.]com
Verificação de phishing e segurança de aster-ex.com
“FASTPANEL”
aster-ex.com — Conteúdo indisponível (HTTP 502). Tipo de golpe: Social Media Phishing. Resumo das evidências: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 65/100. Registrador: Tucows.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of aster-ex.com, created on 14 October 2025 and hosted behind Cloudflare (AS13335) in the United States, shows that the domain has been identified as a social media phishing vector. The site resolved to IP 104.21.18.219 and used the Cloudflare nameservers kyrie.ns.cloudflare.com and may.ns.cloudflare.com. No TLS certificate was presented, indicating that the HTTP service was either absent or served without encryption at the time of inspection. The page title returned by the server was "FASTPANEL", which does not correspond to any known legitimate brand and suggests the use of a generic control‑panel interface. Gridinsoft assigned a trust score of 0 out of 100, reflecting extreme malicious confidence.
The domain appears on a single security blocklist and has been explicitly blocked by PhishDestroy. VirusTotal scans reported that three of ninety‑five antivirus engines flagged the domain, confirming the presence of malicious components. The registrar listed is Tucows Domains Inc., a common registrar for both benign and abusive registrations. The domain is currently taken offline, which limits real‑time observation, but the historical indicators remain sufficient for defensive actions. The lack of an SSL certificate further reduces the credibility of any login interface that might have been presented, as browsers would flag the connection as insecure.
Because the domain is hosted on Cloudflare’s infrastructure, any future relocation of the malicious content could inherit the same IP range, so threat intelligence feeds should correlate activity with the 104.21.18.219 address. The single blocklist listing indicates limited exposure but does not diminish the elevated risk rating assigned by analysts. Defenders should continue to block the domain at network perimeters, ensure that any references to the resolved IP 104.21.18.219 are denied, and monitor for potential re‑use of the associated Cloudflare account.
Sinais de segurança
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo