blueroute[.]live
“Blue Route Logistics”
blueroute.live — Скрытый · достижимый (HTTP 502). Олицетворение бренда: Facebook; Тип мошенничества: E Commerce Scam. Сводка доказательств: VirusTotal 4/94 (alphaMountain.ai, Fortinet, Gridinsoft, SOCRadar); URLQuery 1 alert; cloaking observed; PhishDestroy score 71/100. Регистратор: Ultahost.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis on blueroute.live indicates the site was registered on 15 February 2026 through Ultahost, Inc and is hosted on a German address (159.100.6.19) operated by UltaHost Inc. The page title returned from the server is “Blue Route Logistics”, and the underlying stack consists of WordPress, MySQL, PHP, Bootstrap and several front‑end libraries such as jQuery Migrate, OWL Carousel and LiteSpeed as the web server. The site employed a Let’s Encrypt certificate issued under R13, confirming that TLS was correctly configured at the time of observation. VirusTotal scans show that four of ninety‑five security vendors flagged the domain, and the domain appears on a single external blocklist that is currently enforced by PhishDestroy. Gridinsoft assigns a trust score of 0 out of 100, reinforcing the low credibility assessment.
The domain is classified as an E‑Commerce scam and has been taken offline as of the report date. The authoritative nameservers are ns1‑ns4.ultahost.com, matching the registrar information. Uncertainty remains regarding the exact payload or credential‑harvesting mechanisms because the site is no longer reachable and no page content has been captured. No Safe Browsing, OTX, or additional blocklist entries are reported, and no further intelligence on phishing kits or compromised accounts has been disclosed.
Defenders should therefore treat the domain as a confirmed malicious indicator. Immediate actions include adding blueroute.live and its resolved IP address 159.100.6.19 to network‑level deny lists, confirming that existing web‑filtering solutions block the domain, and monitoring for any resurgence of the same hosting infrastructure or similar WordPress‑based deployments. Continuous review of threat‑intel feeds for new detections related to Ultahost hosting or the identified technology stack is recommended to catch potential re‑use of the infrastructure.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/1ebf2aa6/player_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 11 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
High-performance web server compatible with Apache configurations.
Touch-enabled jQuery plugin for responsive carousel sliders.
Plugin to detect and restore deprecated jQuery features.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of blueroute.live · checked Mar 18, 2026
Доказательства и внешние отчеты
PD-20260318-30F822 Recipient: u-abue@ultahost.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание