Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
gl[.]euler[.]team
“Sign in · GitLab”
Resumo das evidências
This domain, gl.euler.team, is flagged as a credential theft operation targeting users through brand impersonation of GitLab. Analysis of the page title, "Sign in · GitLab," confirms the domain replicates GitLab’s authentication interface to deceive victims into submitting login credentials. No direct evidence of a crypto drainer kit was observed, but the infrastructure aligns with credential harvesting campaigns commonly used to facilitate secondary attacks, such as account takeovers or lateral movement in compromised environments. Technical indicators reveal the domain was registered on February 21, 2026, through Regional Network Information Center, JSC dba RU-CENTER, a registrar frequently associated with malicious infrastructure. It resolves to the IP address 91.103.212.254, and while it employs a Let’s Encrypt SSL certificate to appear legitimate, the domain is detected by 1 of 95 security vendors on VirusTotal. It appears on a single security blocklist, and its Gridinsoft trust score is 0/100, further corroborating its malicious classification. Detected technologies include Ruby, Ubuntu, Ruby on Rails, and Nginx, a stack consistent with phishing kits designed for scalability and evasion. As of the latest assessment, gl.euler.team has been taken offline, likely in response to detection by security mechanisms such as PhishDestroy. However, the remaining risk persists due to the potential for re-deployment under a new domain or IP address. Organizations and users are advised to monitor for similar impersonation attempts, particularly those mimicking GitLab or other developer platforms. Network-level blocking of the IP 91.103.212.254 and domains registered through the same registrar during the observed timeframe is recommended. Additionally, users should verify the authenticity of login pages by checking domain names, SSL certificates, and URL paths before entering credentials.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260216-E46901- Título da página capturada
- Sign in · GitLab
- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Acceptable Use Policy (AUP): The domain gl.euler.team is engaged in phishing activities, which directly contravenes the AUP's prohibition against illegal activities, fraud, and deception.
Terms of Service (TOS): The ongoing use of this domain for phishing purposes constitutes a violation of the TOS, which reserves the right to suspend or terminate services for any illegal or harmful activities.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and the use of such access to commit fraud.
Wire Fraud Statute (18 U.S.C. § 1343): This law makes it illegal to use electronic communications to execute a scheme to defraud, which is applicable to phishing activities.
CAN-SPAM Act (15 U.S.C. § 7701): This U.S. law regulates commercial email and prohibits deceptive practices, including phishing.
Regulatory Note: Failure to take immediate action against this domain may result in liability under applicable laws and could lead to regulatory scrutiny. Non-compliance with your AUP and TOS may also expose your organization to reputational damage and legal consequences.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
VirusTotal
3 → 2
-
VirusTotal
3 → 2
-
VirusTotal
3 → 2
-
VirusTotal
3 → 1
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Registration: euler.team
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain euler.team behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Inteligência forense
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of gl.euler.team · checked Jun 26, 2026
Análise da configuração do site
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo