5gf1d[.]baollll2[.]cc
“随心而为,随性而活”
5gf1d.baollll2.cc — Скрытый · достижимый. Тип мошенничества: Generic Phishing. Сводка доказательств: VirusTotal 16/91 (ADMINUSLabs, BitDefender, Chong Lua Dao, CyRadar, ESET); CF Radar malicious; cloaking observed; PhishDestroy score 100/100. Регистратор: NameSilo.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, 5gf1d.baollll2.cc, is flagged as a generic phishing site targeting users through a Chinese-language lifestyle-themed portal. The page title "随心而为,随性而活" suggests an attempt to lure victims into engaging with content that may lead to credential harvesting or malware delivery. No specific brand impersonation or cryptocurrency drainer kit signatures were identified in initial analysis, though the infrastructure aligns with broader phishing campaigns observed in the wild. Analysis indicates the domain was registered on February 21, 2026, through NameSilo, LLC, and resolves to the IP address 45.145.72.188, hosted under AS201106 (Spartan Host Ltd) in the United States. VirusTotal reports 18 out of 95 security vendors flagging the domain as malicious, while it appears on one security blocklist. The SSL certificate is issued by Let's Encrypt (R12), a common choice for both legitimate and malicious sites due to its accessibility. No Google Safe Browsing (GSB) detections were noted at the time of assessment. The domain is currently offline, likely due to takedown actions or infrastructure adjustments by the threat actor. While the immediate risk is mitigated, the registration and hosting patterns suggest potential for re-emergence under similar domains. Users are advised to monitor for related phishing attempts, particularly those leveraging Chinese-language lures or lifestyle-themed content. Network defenders should update blocklists to include the domain and associated IP, while verifying no residual connections exist in logs or proxy configurations.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 1 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of 5gf1d.baollll2.cc · checked Mar 2, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание