Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@omegatech.sc.
The latest stored availability evidence still shows the domain reachable; 2 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
bitrefill-pay[.]at
“Bitrefill Checkout”
bitrefill-pay.at — Непроверенный. Сводка доказательств: VirusTotal 8/91 (ChainPatrol, alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, G-Data); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
PhishDestroy first observed bitrefill-pay.at on Aug 19, 2026. The captured page title is “Bitrefill Checkout”. Current evidence score: 95/100 (critical).
Positive findings are stored from 4 sources: VirusTotal, MetaMask, SEAL, and Spamhaus DBL. VirusTotal recorded 8 detections among 91 engines: ChainPatrol, alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, SOCRadar, Sophos on Aug 22, 2026 at 01:58 UTC. MetaMask and SEAL listed the hostname in the separate external-blocklist snapshot on Aug 22, 2026 at 02:20 UTC. Spamhaus DBL: DBL_PHISH on Aug 20, 2026 at 02:30 UTC. Non-positive and contextual checks: On Aug 22, 2026 at 01:59 UTC, AlienVault OTX listed 4 community pulse references (not vendor detections); Google Safe Browsing returned no flag. URLQuery recorded no positive detection; no observation timestamp was retained. URLScan completed without a malicious verdict (score 0) on Aug 19, 2026 at 23:08 UTC.
The collector marked the hostname reachable on Aug 20, 2026 at 22:15 UTC, but did not retain the HTTP response code. At collection time, the hostname resolved to 158.94.210.56. The recorded endpoint location is Amsterdam, NL. The stored server header is nginx/1.30.3. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. TLS metadata lists Let's Encrypt as the certificate issuer.
The content indicators and 4 positive source findings support the current phishing classification. The stored fields do not identify an impersonated brand or victim interaction.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 2 identified
Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 100% уверенностиNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of bitrefill-pay.at · checked Aug 20, 2026
Доказательства и внешние отчеты
PD-20260819-99B9E3 Recipient: abuse@omegatech.sc Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание