cdnm2[.]gotit[.]best
“Are You Human ?”
Сводка доказательств
PhishDestroy has identified cdnm2.gotit.best as a generic phishing domain with an elevated risk level. This domain was observed hosting a fake "Are You Human?" CAPTCHA page, a common tactic used to trick visitors into completing fraudulent verification steps that often lead to credential theft or malware delivery. The domain is currently offline, but its recent activity and design strongly indicate malicious intent.
The domain was created on September 25, 2025, and registered through Namecheap, a popular registrar often abused by threat actors. It resolves to IP address 172.67.181.128, which is associated with Cloudflare. VirusTotal analysis shows that 3 out of 95 security vendors flagged this domain as malicious, and it appears on one security blocklist. These technical indicators, combined with the generic phishing classification, suggest the domain was part of a targeted campaign exploiting user trust in CAPTCHA systems.
Users who encounter this domain should avoid interacting with any prompts or entering personal information. Since the threat is generic phishing, the primary risk is credential harvesting or malware installation through fake verification forms. PhishDestroy recommends verifying any unexpected CAPTCHA requests directly through the legitimate website's official channels. If you have already submitted data, change passwords immediately and enable multi-factor authentication. Report the domain to security teams and monitor accounts for suspicious activity.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260322-560D54- Заголовок сохранённой страницы
- Are You Human ?
- PDF-файл
- PDF с доказательствами
Правовое основание
Полный текст доказательств
Policy Violations: Domain Registration Agreement prohibits hacking, misuse of domain to conduct attacks, scam and fraudulent activities; AUP allows immediate suspension
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
VirusTotal
0 → 3
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Registration: gotit.best
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain gotit.best behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of cdnm2.gotit.best · checked Mar 22, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание