a-r-d-i-c[.]site
“Marketz Group | Consultores | Marketing | Representantes Comerciales y Ventas”
a-r-d-i-c.site — Последний известный активный (HTTP 301). Сводка доказательств: VirusTotal 5/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_SPAM; PhishDestroy score 83/100. Регистратор: Ultahost.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain a-r-d-i-c.site was registered on May 17, 2026 through Ultahost, Inc. The site presents a page titled “Marketz Group | Consultores | Marketing | Representantes Comerciales y Ventas”, a common tactic for brand impersonation. The TLS certificate is issued by Let’s Encrypt (R13), indicating a short‑lived, freely‑issued certificate. Technical resolution shows the domain mapping to IP address 159.100.6.19, which resolves to a host in Germany associated with Ultahost, Inc. The authoritative name servers are ns1.ultahost.com through ns4.ultahost.com, all under the same registrar. HTTP requests return a 301 redirect, suggesting the operator is controlling traffic flow to a secondary landing page. Threat intelligence indicates the domain appears in a single AlienVault OTX pulse and is listed on one public blocklist maintained by PhishDestroy. Gridinsoft assigns a trust score of 0 out of 100, and VirusTotal reports detection by one of ninety‑five scanning engines, reinforcing the malicious classification. No further intelligence about the campaign’s payload, credential harvesting mechanism, or affiliated infrastructure is currently available. Defenders should block both the domain and its resolved IP address at perimeter firewalls and DNS filtering solutions. Monitoring for the use of the same name server set and similar page titles can aid in early detection of related sites. Continuous re‑analysis of VirusTotal and other multi‑engine scanners is advised to capture any emerging detections that may raise the confidence level of the threat.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание