info-simple[.]to
“404 Error”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
This domain, info-simple.to, is flagged as an elevated-risk generic phishing infrastructure designed to deceive users through a fake 404 error page. Analysis indicates the threat type does not target a specific brand but instead employs a low-interaction decoy to mask malicious intent, potentially redirecting victims to credential harvesters or malware distribution endpoints. The domain’s use of a fabricated error page suggests an attempt to evade detection while maintaining operational readiness for follow-on attacks. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain resolves to IP 95.129.234.38, hosted on AS57724 (DDOS-GUARD LTD, RU), a network frequently associated with bulletproof hosting. It was registered on August 15, 2025, through the Government of the Kingdom of Tonga’s registry, a jurisdiction with minimal enforcement oversight. Security vendors on VirusTotal flagged the domain at a ratio of 11/95, while it appears on at least one security blocklist. The SSL certificate, issued by Let’s Encrypt (R12), provides nominal encryption but lacks organizational validation, a common trait in phishing infrastructure. The domain’s current status is offline, though historical patterns suggest potential reactivation under altered configurations. Mitigation requires a multi-layered approach tailored to the observed threat characteristics. Network-level protections should block resolution to 95.129.234.38 and monitor for related domains registered via the Tonga ccTLD (.to). Endpoint security systems should prioritize detection of fake error pages, particularly those returning HTTP 404 responses without legitimate server logs. Organizations are advised to implement strict certificate validation policies, flagging domains with short-lived Let’s Encrypt certificates issued within the past 30 days. User awareness training should emphasize the risks of interacting with error pages from unfamiliar domains, even when no overt malicious content is displayed. Given the domain’s recent creation and rapid takedown, continuous monitoring for re-registration or DNS changes is recommended.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
VirusTotal
11 → 12
-
VirusTotal
12 → 11
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of info-simple.to · checked Mar 2, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo