darb[.]rtaty[.]com
“Welcome to nginx!”
Сводка доказательств
The domain darb.rtaty.com, impersonating x.com, has a critical threat score of 95/100 and is currently down. It has been flagged as malicious by 10 out of 95 security vendors, including notable names like Fortinet and Sophos, and is listed on one public blocklist. Google Safe Browsing has not flagged this domain, indicating it may not have been widely recognized before its takedown.
Registered with Alibaba Cloud Computing Ltd. on February 21, 2026, the domain was first detected on January 30, 2026. The hosting IP is 43.162.124.181, which may require further investigation for related malicious activities. Block the domain at the perimeter and submit a report to the registrar's abuse desk for further action.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260130-A297C9- Заголовок сохранённой страницы
- Welcome to nginx!
- PDF-файл
- PDF с доказательствами
Полный текст доказательств
Acceptable Use Policy: The domain darb.rtaty.com is engaged in phishing activities, which directly contravenes your AUP prohibiting illegal activities and deception.
Terms of Service: The operation of this domain constitutes a violation of your TOS, which reserves the right to suspend or terminate services for any activities related to fraud and phishing.
Applicable Laws (CN):
Cybersecurity Law of the People's Republic of China: This law prohibits the use of the internet for illegal activities, including phishing and fraud.
Criminal Law of the People's Republic of China (Article 286): This article criminalizes fraud, including online deception and phishing schemes.
Regulatory Note: Failure to take immediate action against this domain may result in regulatory scrutiny and potential liability under applicable laws. Non-compliance could expose your organization to legal repercussions and damage your reputation.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | darb.rtaty.com |
malicious | Sinkholed |
| Cloudflare DNS | darb.rtaty.com |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Registration: rtaty.com
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain rtaty.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание