MALICIOUS — HIGH
defender[.]services
The domain defender.services, associated with a high threat score of 85/100, has been identified as a generic phishing operation and is currently down.
- VirusTotal
- 1/93
- Blocklists
- 2 · MetaMask, SEAL
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
defender.services — Контент недоступен (HTTP 502). Олицетворение бренда: ["solana"]. Сводка доказательств: VirusTotal 1/93 (SOCRadar); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Регистратор: Hostinger.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
The domain defender.services, associated with a high threat score of 85/100, has been identified as a generic phishing operation and is currently down. It has been flagged by 1 out of 95 security vendors, with SOCRadar being the notable vendor that detected it as malicious. The domain is listed on 3 public blocklists, but it is not flagged by Google Safe Browsing, indicating a potential gap in detection coverage.
Registered with HOSTINGER operations, UAB, the domain was created on February 21, 2026, and was first seen on February 14, 2026. The hosting IP address is 216.198.79.65. The lack of a specific brand being impersonated suggests a broad targeting strategy typical of generic scams.
Given the high threat score and confirmed malicious activity, block the domain at the perimeter and submit a report to the registrar's abuse desk for further investigation.
Охват данных12 recorded checks
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/1798f86c/player_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
PD-20260214-CF4187 Recipient: abuse@hostinger.com Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.