refuel[.]eu[.]com
“Stratosphere Gas Zip - Bridging the Future of Aerospace Energy”
Resumo das evidências
Analysis of the domain refuel.eu.com, registered on February 21, 2026, indicates a confirmed brand impersonation targeting Revolut, a known financial services provider. The domain is currently offline, but infrastructure evidence reveals multiple indicators of malicious intent. It resolved to IP address 172.67.193.123, hosted on Cloudflare's network (AS13335) in the United States. Nameservers point to CentralNic (ns1.centralnic.net through ns4.centralnic.net), a common provider for both legitimate and malicious domains, while the registrar is Instra Corporation Pty Ltd. The domain's MX records show a wildcard null configuration (eu-com-wildcard-null-mx.centralnic.net), a pattern often used to avoid email-based detection or to mask operational infrastructure. Gridinsoft assigns a trust score of 0/100, reflecting high-risk classification.
Three of 93 security vendors on VirusTotal flagged the domain as malicious, though this does not constitute a full consensus. The domain appears on one security blocklist, and PhishDestroy has blocked it, further supporting the elevated risk assessment. The page title, 'Stratosphere Gas Zip - Bridging the Future of Aerospace Energy,' does not align with financial services or the Revolut brand, suggesting either obfuscation or a placeholder used during domain staging. The SSL certificate (E5) is valid but does not mitigate the domain's fraudulent purpose.
While the exact content of the site remains unanalyzed, the combination of infrastructure, detection flags, and brand impersonation classification confirms its role in a phishing operation. Defenders should treat this domain as compromised and maintain blocklist entries. Organizations should monitor for related domains using the same registrar, nameserver, or hosting patterns, particularly those leveraging Cloudflare or CentralNic infrastructure. If internal logs show user interaction with refuel.eu.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo