goaltrail[.]ru[.]com
“Bulletproof Hosting”
Resumo das evidências
goaltrail.ru.com is a newly registered domain (creation date 21 February 2026) that currently resolves to the IPv4 address 103.50.161.106. The site returns HTTP 200 and presents a title of “Bulletproof Hosting”, suggesting the page is being used to masquerade as a hosting‑service login or control panel. The domain is listed as active and is hosted under the Sav.com, LLC registrar, with four centralnic.net nameservers (ns1–ns4.centralnic.net). The hosting IP belongs to ASN 394695, advertised by PDR and geolocated to India. The TLS certificate presented is identified as “R13”, indicating a recent, possibly self‑signed or low‑validation certificate. Threat intelligence feeds have flagged the domain: PhishDestroy has already added it to its blocklist, VirusTotal reports eight out of ninety‑five scanners rating the domain as malicious, and one external blocklist also lists it. Gridinsoft assigns a trust score of zero out of one hundred, reinforcing the malicious assessment. Analysis indicates that the infrastructure is characteristic of generic phishing campaigns that lease bulletproof hosting to evade takedown. The exact brand or service being spoofed is not disclosed in the visible content, and no phishing kit fingerprints have been observed, leaving the specific target ambiguous. Defenders should proactively block both the domain and its resolving IP, monitor DNS queries for similar sub‑domains under the same registrar, and enforce URL filtering for any pages presenting the “Bulletproof Hosting” title. Continuous re‑evaluation is advised, as the active status and low trust score suggest the site may evolve its payload or expand its phishing scope.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | quantumxy.ru.com |
malicious | Sinkholed |
| DNS0 Zero | fonts.cfd |
malicious | Sinkholed |
| DNS4EU | fonts.cfd |
malicious | Sinkholed |
| OpenDNS | goaltrail.ru.com |
phishing | Phishing Block |
| Hagezi Threat Feed | goaltrail.ru.com |
malicious | Sinkholed |
| DNS0 Zero | goaltrail.ru.com |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 13/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of goaltrail.ru.com · checked Mar 25, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo