Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@ifastnet.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
habilitar-email365[.]hstn[.]me
“habilitar-email365.hstn.me”
habilitar-email365.hstn.me — Não verificado. Resumo das evidências: VirusTotal 11/91 (BitDefender, Cluster25, CRDF, Emsisoft, Fortinet); URLQuery 2 alerts; PhishDestroy score 88/100. Registrador: Porkbun.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis as of July 20, 2026 identifies habilitar-email365.hstn.me as an active malicious infrastructure used for generic phishing. The domain was registered on June 03, 2019 through Porkbun LLC and continues to resolve to the IPv4 address 185.27.134.125. The hosting IP is currently listed on a single security blocklist, PhishDestroy, indicating that at least one network security product has flagged the domain for malicious activity. VirusTotal scans show that three of ninety‑one independent security vendors have flagged the domain, reinforcing the suspicion of abuse. The domain’s nameserver configuration is not publicly observable (NS_NOT_FOUND), which can hinder rapid takedown but does not affect its operational capability. No additional intelligence such as SSL certificate details, HTTP response codes, or page title is available at this time, leaving the exact content and targeting of the phishing campaign unverified. Defenders should consider adding habilitar-email365.hstn.me to blocklists at perimeter and endpoint solutions, monitor traffic to the associated IP address 185.27.134.125, and investigate any authentication attempts that reference Microsoft Office 365 services, as the subdomain suggests a possible focus on compromising email accounts. Ongoing observation of the IP’s hosting provider and any future detection updates will be necessary to assess whether the infrastructure expands or changes. The limited detection footprint underscores the importance of proactive containment despite the relatively low number of vendor flags.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% de confiançaOpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.
openresty.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of habilitar-email365.hstn.me · checked Jul 20, 2026
Evidências e relatórios externos
PD-20260720-51A8E9 Recipient: abuse@ifastnet.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo