authpanels[.]com
“Ledger Connect”
authpanels.com — Контент недоступен (HTTP 502). Олицетворение бренда: Ledger; Тип мошенничества: Impersonation. Сводка доказательств: VirusTotal 12/91 (alphaMountain.ai, BitDefender, CRDF, ESET, Forcepoint ThreatSeeker); URLQuery 1 alert; Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 100/100. Регистратор: Ultahost.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis as of July 23 2026 identifies authpanels.com as an actively hosted domain used for generic phishing. The domain was registered through Ultahost, Inc. and created on July 22 2026. Its authoritative DNS configuration lists four Ultahost nameservers (ns1.ultahost.com through ns4.ultahost.com). Resolution points to the IPv4 address 173.211.81.11, which is currently reachable and hosts the suspect content. The domain appears on one public security blocklist and has been explicitly blocked by the PhishDestroy community feed, confirming that it is being used in malicious campaigns.
A VirusTotal scan submitted the domain to 91 antivirus and URL‑reputation engines; none of the scanners returned a detection at the time of analysis, but the absence of a flag does not constitute evidence of legitimacy. No public page title, SSL certificate details, HTTP response codes, or Safe Browsing verdicts are available in the current intelligence set, leaving the exact content and credential‑harvesting mechanisms unverified. Likewise, there are no Open Threat Exchange (OTX) references or additional blocklist entries beyond the single listing, which limits the breadth of external corroboration. The lack of these data points should be considered a gap rather than an indication of benign behavior. Defenders should treat authpanels.com as a high‑confidence phishing indicator.
Recommended actions include adding the domain and its resolving IP address to DNS‑level deny lists, updating URL filtering policies to block any HTTP(S) request to the host, and monitoring network traffic for connections to 173.211.81.11. Continuous re‑scanning of the domain on multi‑vendor platforms such as VirusTotal is advised to capture any future changes in malicious payloads. Organizations using threat‑intelligence feeds should ensure that the PhishDestroy block is propagated across endpoint and gateway solutions.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | authpanels.com |
phishing | Phishing Block |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% уверенностиOpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.
openresty.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of authpanels.com · checked Jul 23, 2026
Доказательства и внешние отчеты
PD-20260723-8EDE8C Recipient: u-abuse@ultahost.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание