6h505[.]com
Проверка домена 6h505.com на фишинг и безопасность
“welcome!”
6h505.com — Скрытый · достижимый (HTTP 200). Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 20/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); CF Radar malicious; cloaking observed; PhishDestroy score 100/100. Регистратор: GoDaddy.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
PhishDestroy first observed 6h505.com on Feb 26, 2026. The captured page title is “welcome!”. Stored page analysis classifies the content as credential phishing. Evidence score: 100/100 (critical).
3 independent sources recorded positive findings: VirusTotal, DNS security resolvers, and Cloudflare Radar. VirusTotal recorded 20 detections among 93 engines: ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet on Jul 9, 2026 at 08:16 UTC. DNS security checks returned 2 blocking results across 14 tested policies: Cloudflare Family, Cloudflare Security; no observation timestamp was retained. Cloudflare Radar classified the hostname as malicious and placed it in the phishing category; its verdict timestamp was not retained.
Cloaking was recorded with HTTP 200 on Aug 9, 2026 at 02:18 UTC. The cloaking probe recorded status split conditional delivery at 1/100 on Aug 9, 2026 at 02:18 UTC: alive_content: raw=ok; http=200; via=https_proxy; server=ip-10-123-124-237.ec2.internal. Registration records for the domain list GoDaddy.com, LLC as the registrar and Feb 21, 2026 as the creation date. At collection time, the hostname resolved to 45.138.71.205 on AS35251 (ANTI-DDOS, US). The evidence archive retains 2 visual captures from PhishDestroy and URLScan.
Охват данных12 recorded checks
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.