checks[.]ltd
Проверка домена checks.ltd на фишинг и безопасность
“Google Chrome - The Fast & Secure Web Browser Built to be Yours”
checks.ltd — Контент недоступен (HTTP 502). Олицетворение бренда: Google; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 4/94 (ADMINUSLabs, alphaMountain.ai, Fortinet, SOCRadar); PhishDestroy score 65/100. Регистратор: NameSilo.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, checks.ltd, was created on 01 April 2025 and is currently taken offline. Infrastructure analysis shows it resolves to 142.251.154.119, an IP owned by AS13335 Cloudflare, Inc. and located in the United States. The authoritative name servers are lorna.ns.cloudflare.com and sri.ns.cloudflare.com, indicating the use of Cloudflare’s DNS service. Registration was performed through NameSilo, LLC, a registrar that does not impose strict verification, which is consistent with many short‑lived malicious registrations.
The site’s page title, as observed in prior scans, reads “Google Chrome – The Fast & Secure Web Browser Built to be Yours,” and the domain is classified as a brand‑impersonation campaign targeting Google. It appears on one public security blocklist and is blocked by the PhishDestroy feed. VirusTotal analysis shows that 4 of 94 scanning engines flagged the domain, confirming a low‑to‑moderate detection rate. No additional public threat‑intel sources such as OTX or Google Safe Browsing entries are currently cited for this FQDN.
Because the domain is offline, live HTTP response codes, SSL certificate details, and trust‑score metrics cannot be collected at this time. Defenders should continue to monitor the associated IP address and Cloudflare name‑server pair for any re‑activation, add the FQDN to internal deny lists, and consider sharing the indicator set with upstream blocklist operators. Correlation with other Cloudflare‑hosted malicious domains may reveal shared tooling. Until the domain reappears, the primary mitigation is to keep the indicator blocked and to watch for any future registration of similar “checks.*” patterns that target the Google brand.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260315-14989B Recipient: abuse@namesilo.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание