abrmot.pro
“Terms of Service”
abrmot.pro — Контент недоступен (HTTP 404). Олицетворение бренда: Unknown; Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 26/89 (AILabs (MONITORAPP), alphaMountain.ai, BitDefender, Certego, Chong Lua Dao); URLQuery 9 alerts; Spamhaus DBL_MALWARE; PhishDestroy score 95/100. Регистратор: Global Domain Group.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
This domain, abrmot.pro, is flagged as a high-risk credential theft operation. Analysis indicates the infrastructure is designed to harvest user login credentials through deceptive landing pages, likely mimicking legitimate authentication portals. No direct association with a specific brand or drainer kit has been confirmed, though the domain’s structure and behavior align with credential harvesting campaigns targeting financial or corporate accounts. Infrastructure analysis reveals the following technical indicators: the domain was registered on July 8, 2026, through Global Domain Group LLC and currently resolves to the IP address 188.114.97.3. Security vendor assessments on VirusTotal show 16 out of 95 detections, while the domain appears on one security blocklist. The SSL certificate is issued by Google Trust Services, a common tactic to lend superficial legitimacy to malicious sites. No Google Safe Browsing (GSB) flags were reported at the time of analysis. The domain remains active and unresolved by the registrar, posing an ongoing risk to users. While some security filters, including Hagezi, have blocked access, the infrastructure’s persistence suggests continued targeting. Organizations and individuals are advised to implement DNS-level blocking for 188.114.97.3 and monitor for related subdomains or redirects. Users should verify authentication portals independently and avoid entering credentials on untrusted sites, even if they appear secure.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | kaleda.pro |
malicious | Sinkholed |
| Hagezi Threat Feed | kaleda.pro |
malicious | Sinkholed |
| Cloudflare DNS | kaleda.pro |
malicious | Sinkholed |
| Quad9 DNS | kaleda.pro |
malicious | Sinkholed |
| Cloudflare DNS | abrmot.pro |
malicious | Sinkholed |
| Hagezi Threat Feed | abrmot.pro |
malicious | Sinkholed |
| DigiCert UltraDNS | abrmot.pro |
malicious | Sinkholed |
| DNS4EU | abrmot.pro |
malicious | Sinkholed |
| Quad9 DNS | abrmot.pro |
malicious | Sinkholed |
Forensic History & Detection Timeline
-
Domain Status Transition Sep 4, 2026 · 00:15 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Sep 4, 2026 · 00:00 UTCDomain state transitioned from alive to dead.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённое наблюдение
Зафиксированное различие заголовков
Сохранённый снимок · 3 sources
Аналитика доменов
Технические деталиDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of abrmot.pro · checked Jul 9, 2026
Доказательства и внешние отчеты
PD-20260712-6A08E6 Recipient: abuse@globaldomaingroup.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание