onefootballs[.]club
onefootballs.club — Não verificado. Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. Registrador: Global Domain Group.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain onefootballs.club has been identified as a high-risk credential phishing site. Analysis indicates that the domain, registered through Global Domain Group LLC on May 27, 2026, is currently active and resolves to the IP address 188.114.97.3, which is located in CA and managed by CloudFlare, Inc. The domain's nameservers are melany.ns.cloudflare.com and trace.ns.cloudflare.com, suggesting the use of CloudFlare's DNS services for potential obfuscation or DDoS protection. The page title 'Just a moment...' is commonly used to mask the true nature of the site, often displaying a loading screen to delay and mislead users. This technique can be used to evade initial detection and allow the attackers to gather more information about the visitor before redirecting them to a phishing page. The domain has been flagged by 2 out of 95 security vendors on VirusTotal and has a Gridinsoft trust score of 0/100, indicating a low level of confidence in its legitimacy. The domain appears on three security blocklists and is blocked by PhishDestroy, MetaMask, and SEAL, further corroborating its malicious intent. Defenders should monitor network traffic for connections to this domain and block it at the firewall or DNS level to prevent potential credential theft. Additionally, users should be educated to recognize and avoid such deceptive pages, especially when they encounter unexpected loading screens or are asked to provide sensitive information. Regular updates to security software and maintaining a list of known malicious domains can help mitigate the risk of falling victim to such attacks.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo