Перейти к отчёту о безопасности
Checked 09.08.2026 Ref 35EEF126

MALICIOUS — CRITICAL

Проверка домена content-x.kr на фишинг и безопасность

content-x[.]kr

Analysis of the domain content-x.kr shows a newly registered internet resource that is actively being used for a phishing campaign.

83/100 evidence score · Critical
VirusTotal
3/91
Blocklists
2 · MetaMask, SEAL
Доступность
Последний известный активный · HTTP 200
Report / Add Evidence Appeal this listing
2026-07-28 17:20 UTCПоследний известный активный · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Этот домен был отмечен как вредоносный
Механизмы безопасности сообщают об обнаружении: 3. Публичные черные списки, сообщающие о совпадении: 2. Будьте предельно осторожны — не вводите учетные данные или личную информацию.
Jump to section
Краткий обзор отчёта

content-x.kr — Последний известный активный (HTTP 200). Сводка доказательств: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. Регистратор: Gabia.

Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.

Evidence Analysis

Ref 35EEF126

Analysis of the domain content-x.kr shows a newly registered internet resource that is actively being used for a phishing campaign. The domain was created on July 28, 2026 and is registered through Gabia, Inc. It is hosted on the IP address 216.150.16.1 and uses the authoritative name servers ns1.vercel-dns.com and ns2.vercel-dns.com, indicating that the underlying web service is likely powered by Vercel’s hosting platform. The domain is currently listed on two public blocklists, PhishDestroy and SEAL, and both lists flag it as a phishing‑related resource.

VirusTotal records indicate that the domain was examined by 91 antivirus and URL‑reputation engines; none of the engines returned a detection at the time of scanning, which does not constitute a safety assurance. No additional data such as SSL certificate details, HTTP response codes, page title, or content snapshots are available in the intelligence set, leaving the exact appearance and payload of the site unknown. Given the recent creation date, the presence on dedicated phishing blocklists, and the resolution to a public IP address, defensive teams should treat content-x.kr as a high‑confidence phishing indicator.

Recommended actions include adding the domain to outbound and inbound URL filtering rules, monitoring DNS query logs for lookups to the associated nameservers, and extending threat‑intel feeds to capture any future changes in its status. Continuous re‑evaluation is advised, as further reconnaissance may reveal additional infrastructure or victim targeting patterns.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
3 det.
Сертификат TLS
Let's Encrypt
Возраст
12d Very New!
Зафиксированный статус
Последний известный активный 200
PhishDestroy
DestroyList
В списке
Охват данных12 recorded checks
VirusTotal 3 / 91 URLQuery не проверено PhishStats не проверено OTX no community references CF Radar scan completed URLScan capture сохраненный отчет URLScan verdict Анализ завершён DNS-блокировки не проверено TLS valid certificate, 89d WHOIS 12d old Снимок экрана 2 captures · 2 sources Цепочка перенаправлений не исследовано

Процесс реагирования на угрозы

Открытие
Checks
Reports
Доступность
11/13
Угроза устранена
content-x.kr обнаружены и помещены в очередь для полного анализа
28.07.2026
URLScan.io Capture
Stored URLScan report with capture artifacts
28.07.2026
URLScan Verdict
Анализ URLScan завершен; этот результат веб-захвата не меняет вердикт об угрозе странице · score 0
29.07.2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
Web Archive
Preserved in Wayback Machine — historical evidence archived
28.07.2026
VirusTotal
3/91 recorded on VirusTotal
08.08.2026
Google Safe Browsing
28.07.2026
Обнаружение списков заблокированных адресов
Найдено в 2 blocklists: MetaMask, SEAL
09.08.2026
Forensic Evidence Collected
Stored evidence from URLScan.io, stored screenshot
28.07.2026
Technical Analysis Recorded
Отчет содержит сохраненные технологии или результаты судебно-медицинской экспертизы.
09.08.2026
Complaint Draft Available
Подача не фиксируется. Вы можете создать проект, просмотреть его и самостоятельно отправить в соответствующий орган.
Опубликовано «DestroyList»
28.07.2026
Monitoring Continues
Домен остается доступным или доступ к нему ограничен; будущие проверки могут обновить это наблюдение.

Статус в публичных блок-листах

Сохранённый снимок

Аналитика доменов

Домен
URLScan Verdict Анализ завершён score 0 report ↗
Сервер / ASN Vercel · AS16509 Amazon.com, Inc.
IP Context Vercel shared edge origin IP hidden Репутация Edge-IP не связана с этим доменом.
Регистратор Gabia
Контакт для жалобabuse@vercel.com
IP-адрес 216.150.16.193 CDN
ГеолокацияUS Walnut, US
СетьAS16509 · Vercel, Inc
Обратный поиск IPviewdns.info → rapiddns.io →
Исходный IP-адрес скрыт за прокси-сервером CDN. Результаты обратного IP-адреса для граничного адреса содержат несвязанных клиентов; для определения источника требуется пассивный DNS или данные прозрачности сертификатов.
РегистрацияСоздано 28.07.2026 (12d · Very New!) Expires 28.07.2027
Статус HTTP200
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Впервые обнаружено28.07.2026
DOM Analysisanalyzed 28.07.2026score 83/100
IoC Extractionscanned 29.07.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://content-x.kr/
Серверы имёнns1.vercel-dns.comns2.vercel-dns.com
TLS Fingerprint
TLS Observationvalid from 28.07.2026scanned 28.07.2026
Favicon Hash
Заголовок страницы
CONTENT-X | 콘텐츠 운영
Сертификат TLS
Valid transport encryption · Выдан Let's Encrypt · valid for 89 days
Технологии · 6 identified
Node.js
Programming languages

Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.

nodejs.org 100% уверенности
React
JavaScript frameworks

React is an open-source JavaScript library for building user interfaces or UI components.

reactjs.org 100% уверенности
Vercel
PaaS

Vercel is a cloud platform for static frontends and serverless functions.

vercel.com 100% уверенности
Next.js
JavaScript frameworks Web frameworks

Next.js is a React framework for developing single page Javascript applications.

nextjs.org 100% уверенности
HSTS
Безопасность

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org 100% уверенности
Webpack
Miscellaneous

Webpack is an open-source JavaScript module bundler.

webpack.js.org 100% уверенности
Detected via Cloudflare Radar · Wappalyzer engine
Пожаловаться на этот домен Предоставьте доказательства и помогите защитить других

Анализ VirusTotal

3 / Поставщики средств безопасности 91 отметили этот домен
View on VT
Last analyzed First positive detection Previous stored snapshot: 3 detections
CRDF
Gridinsoft
SOCRadar

Архивные доказательства

Wayback Machine Snapshot
Исторический снимок доступен для проверки доказательств.
View Archive
Анализ производительности сайта

Google PageSpeed Insights — mobile performance audit of content-x.kr · checked Jul 28, 2026

54
Needs Work
Performance
FCP
16.97s
First Contentful Paint
LCP
17.12s
Largest Contentful Paint
CLS
0.077
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
16.97s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Stored Capture Evidence 1 snapshot

Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.

Archived HTTP response HTTP 200
Requested URL: http://content-x.kr/
Final URL: https://content-x.kr/
CONTENT-X | 콘텐츠 운영
안전한 콘텐츠 생성과 검토를 위한 운영 도구
Реагирование
HTTP 200
HTML body
36.4 KB
Compressed
8.8 KB
Links
5 internal · 0 external
Detected technologies
react
Selected response headers
Cache-Control: private, no-cache, no-store, max-age=0, must-revalidate
Content-Encoding: gzip
Content-Type: text/html; charset=utf-8
Server: Vercel
X-Powered-By: Next.js
Security headers present
Strict-Transport-Security
HSTS: observed DNSSEC: not observed WAF / firewall: not observed Cloaking flag: not observed
All stored response-header names (14)
ВозрастCache-ControlContent-EncodingContent-TypeDateLinkServerStrict-Transport-SecurityVaryX-Matched-PathX-Powered-ByX-Vercel-CacheX-Vercel-IdTransfer-Encoding
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.

Европол
Найдите официальный канал отчетности для вашей страны ЕС
National police directory
Остерегайтесь мошенников, предлагающих услуги по восстановлению данных! Преступники могут снова связаться с жертвами, притворяясь следователями, адвокатами или агентами по восстановлению. Не платите авансовые платежи и не делитесь учетными данными. Узнайте больше о мошенничестве при получении компенсаций →

Сообщите об этом в местные органы власти

Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.

Каталог 97 стран
Черновик по шаблону • помощь AI с формулировками включается только с отдельного согласия. Просмотрите и отправьте его самостоятельно
Вставить этот отчетRead-only HTML widget
HTML · IFRAME

Вставить этот отчет

Разместите эту информацию об угрозах на своём сайте или в блоге

embed.html
<iframe
  src="https://phishdestroy.io/ru/embed/domain/content-x.kr"
  title="PhishDestroy threat report for content-x.kr"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>