MALICIOUS — CRITICAL
storageboost[.]work[.]gd
11 of 93 security engines flagged the domain; the latest stored check returned HTTP 200.
- VirusTotal
- 11/93
- Blocklists
- No stored match
- Disponibilidade
- Último ativo conhecido · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@colocrossing.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
storageboost.work.gd — Último ativo conhecido (HTTP 200). Resumo das evidências: VirusTotal 11/93 (ADMINUSLabs, CyRadar, ESET, Fortinet, Google Safebrowsing); URLQuery 5 alerts; Google Safe Browsing flagged; Spamhaus DBL_BOTNET; CF Radar malicious; PhishDestroy score 100/100. Registrador: Key Systems.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
This report analyzes the threat posed by the domain storageboost.work.gd.
The site presents a generic directory listing with the title "Index of /", indicating no specific brand or service is impersonated. The primary threat is social engineering, as confirmed by Google Safe Browsing, which flags the domain for this category. The site likely served as a landing page to deceive visitors into taking actions that compromise their security.
Technical evidence shows the domain was created on 2026-02-24 and is registered with Key Systems GmbH. It resolves to IP address 104.168.70.40, hosted on AS36352 (HostPapa) in the United States. VirusTotal analysis indicates 11 out of 95 security vendors flagged the domain as malicious, with detections from ADMINUSLabs, CyRadar, ESET, Fortinet, and Google Safe Browsing. The SSL certificate is issued to "PhishDestroy / botadmin.destroy.tools," and the domain uses nameservers from dnsexit.com.
The domain is currently offline and inaccessible. Based on the confirmed social engineering flag and the high number of vendor detections, the risk level is assessed as high. The domain should be blocked and not visited.
Cobertura dos dados12 recorded checks
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | storageboost.work.gd |
phishing | Phishing Block |
| Cloudflare DNS | storageboost.work.gd |
malicious | Sinkholed |
| DigiCert UltraDNS | storageboost.work.gd |
malicious | Sinkholed |
| DNS4EU | storageboost.work.gd |
malicious | Sinkholed |
| Quad9 DNS | storageboost.work.gd |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externosIndependent lookups and source reports
PD-20260224-C357E7 Recipient: abuse@colocrossing.com Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.