sdg392[.]it
“Welcome aboard”
sdg392.it — Não verificado. Representação da marca: Genericcrypto; Tipo de golpe: Impersonation. Resumo das evidências: VirusTotal 2/95 (SOCRadar, Trustwave); URLScan malicious verdict; PhishDestroy score 71/100. Registrador: 1 Api.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain sdg392.it was created on 12 August 2025 and is registered through 1 Api GmbH. Technical analysis shows the domain resolves to IP address 104.21.4.213, which belongs to AS13335 operated by Cloudflare, Inc., and is geolocated in the United States. The site was served over HTTPS using a Google Trust Services certificate issued to the WE1 authority, confirming a valid TLS handshake at the time of capture. Cloudflare’s services, including HTTP/3, are observed in the response headers, and the authoritative name servers are aria.ns.cloudflare.com and arturo.ns.cloudflare.com.
The only visible page element is the title “Welcome aboard,” but the site has been taken offline, limiting any current content inspection. VirusTotal scans recorded detections by two of ninety‑five security vendors, indicating that at least a minority of scanners flagged the domain as malicious. The domain appears on a single security blocklist and has been specifically blocked by the PhishDestroy mitigation service.
While the limited data prevents a full description of the phishing payload, the combination of recent registration, Cloudflare hosting, a valid SSL certificate, and vendor detections align with typical infrastructure used for credential‑harvesting sites. Defenders should add sdg392.it to URL filtering rules, block the associated IP 104.21.4.213 at network perimeter devices, and monitor for other newly registered domains using the same registrar or Cloudflare name servers. Continuous re‑scanning of the domain is recommended in case the site reappears, and any observed traffic to the IP should be logged for further threat‑intel correlation.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo