cloudns[.]to
“404 Not Found”
Detecção armazenada
Alerta de cloaking
- Tipo de cloaking
status_split- Pontuação de cloaking
- 1/6
Resumo das evidências
On 24 July 2026 the domain cloudns.to was observed as part of a generic phishing infrastructure. The domain was registered on 29 August 2025 through the Government of the Kingdom of Tonga and is delegated to the authoritative nameservers ns1.cloudns.to and ns2.cloudns.to. DNS resolution points to the IPv4 address 78.159.156.219, which belongs to AS25211 Euro Crypt EOOD and is geolocated in the Netherlands. No TLS certificate is presented for the host, and an HTTP request returns the title “404 Not Found”, indicating that any intended landing page is currently unavailable.
The domain currently appears offline, and the hosting provider has taken the service down. Threat intelligence sources indicate that 16 of 95 security vendors on VirusTotal have flagged the domain, and AlienVault OTX lists it in two separate threat pulses. PhishDestroy has added the domain to its blocklist, and a single additional security blocklist also lists it. Gridinsoft assigns a trust score of 0 out of 100.
The elevated risk rating reflects the combination of active detection, blocklist inclusion, and low trust score despite the offline status. Defenders should continue to block any traffic to cloudns.to at the network perimeter and DNS resolver level, monitor for any resurgence of the IP address 78.159.156.219, and update endpoint protection signatures that reference the domain or its associated IP. Because the site currently returns a 404 response and lacks an SSL certificate, any future re‑activation would likely involve a new payload or redirection, so continuous threat‑intel feed ingestion is advised. The limited public information means that the exact phishing campaign details remain unknown, and further analysis should be performed if the domain becomes reachable again.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo