yafin[.]top
yafin.top — Conteúdo indisponível (HTTP 502). Representação da marca: Genericcloudflare. Resumo das evidências: VirusTotal 12/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; PhishDestroy score 86/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis indicates that yafin.top was registered on February 21 2026 and currently resolves to 172.67.141.123, an address owned by Cloudflare (AS13335) located in the United States. The domain is presently taken offline, which limits immediate interaction but does not remove the underlying infrastructure from threat assessments. VirusTotal scans have returned 12 positive detections out of 93 submitted engines, demonstrating that multiple security products have identified malicious behavior associated with the host. Gridinsoft assigns a trust score of 0 out of 100, confirming a lack of confidence in the domain's legitimacy.
The SSL certificate is labeled WE1, indicating a weak or self‑signed certificate that fails standard trust validation. Reputation data shows the domain appears on a single security blocklist and is listed in one AlienVault OTX pulse, reflecting limited but existing community awareness. PhishDestroy has also blocked the domain, reinforcing its classification as a phishing vector. The combination of a recent creation date, Cloudflare front‑end, low trust score, multiple vendor detections, and inclusion on blocklists suggests the site was used for credential‑harvesting or similar phishing campaigns.
Because the site is offline, direct observation of content is unavailable; therefore, the exact phishing lure, targeted brand, or page structure remains unknown. Defenders should continue to block DNS resolution to 172.67.141.123, update intrusion detection signatures with the observed indicators, and monitor for any re‑use of the domain or associated IP range. Ongoing threat‑intel feeds should be queried for new pulses referencing yafin.top, and any outbound traffic to the IP should be investigated for potential data exfiltration attempts.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo