blackbit-exchange-login[.]com
“Apache2 Ubuntu Default Page: It works”
Сводка доказательств
The domain blackbit-exchange-login.com is actively hosting a credential‑phishing site targeting exchange accounts. HTTP requests return status 200 and the default Apache2 Ubuntu page titled “Apache2 Ubuntu Default Page: It works”, indicating no overt phishing page was captured at the time of analysis. The site presents an SSL certificate issued to PhishDestroy / botadmin.destroy.tools, and resolves to the loopback address 127.0.0.1, a technique often used to evade external scanning. Nameservers are dns1.regway.com, dns2.regway.com, dns3.regway.com, and dns4.regway.com, and registration occurred on May 23 2026 via PDR Ltd. d/b/a PublicDomainRegistry.com. Threat intelligence records show the domain appears in one AlienVault OTX pulse and is listed on four external blocklists; Gridinsoft assigns a trust score of 0/100. VirusTotal reports a single positive detection out of 91 scanners. The scam type is identified as a “Fake Exchange”. Current status remains active and the risk level is high. Defenders should immediately block network traffic to the domain and add it to endpoint and DNS deny‑list filters. Continuous monitoring of DNS queries for the listed nameservers is advised, as is correlation of any authentication attempts to exchange services with this host. Because the site returns only a default Apache page, additional payloads may be deployed later; therefore, periodic re‑assessment of the URL content is recommended.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
7 внешних источников под наблюдением Совпадений нет
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание