challengez[.]net
Проверка домена challengez.net на фишинг и безопасность
“Global | eSports and Gaming Community”
challengez.net — Контент недоступен (HTTP 502). Олицетворение бренда: Celer; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 15/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 100/100. Регистратор: PDR.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This investigation confirms that the domain challengez.net was actively used for brand impersonation targeting the Celer brand before being taken offline. The domain was registered on December 01, 2025 through PDR Ltd. d/b/a PublicDomainRegistry.com and resolves to the IPv4 address 193.221.201.80, which is announced by AS205775 (NEON CORE NETWORK LLC) located in Germany. DNS resolution is provided by the four RegWay nameservers dns1.regway.com through dns4.regway.com. No TLS certificate was observed, indicating that the site operated over plain HTTP.
The visible page title, “Global | eSports and Gaming Community,” does not reference the targeted brand, suggesting that the site content was likely altered after initial detection or that the title was a placeholder. Reputation services assign extremely low trust scores, with Gridinsoft and Scamadviser each rating the domain 1 out of 100. Security vendors have flagged the domain widely: fifteen of ninety‑five VirusTotal scanners reported malicious activity, and the domain appears on one public blocklist, where it is listed by PhishDestroy. AlienVault OTX has referenced the domain in three separate threat pulses, reinforcing its association with malicious campaigns.
The current offline status indicates that the infrastructure has been dismantled or is no longer serving content, but the hosting IP and registrar details remain active and could be reused. Defenders should continue to block challengez.net at network perimeter and DNS layers, add the IP 193.221.201.80 to host‑based deny lists, and monitor for new domains registered by the same registrar or employing the same nameserver set. Ongoing vigilance against re‑use of the hosting provider and rapid sharing of indicators of compromise with threat‑sharing communities are recommended.
Сигналы безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание