deshlboard-asset[.]it[.]com
“Texdatalex Systems - Premier Event Management & Hosting Solutions”
deshlboard-asset.it.com — Непроверенный. Олицетворение бренда: Aave; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 2/91 (alphaMountain.ai, Gridinsoft); PhishDestroy score 56/100. Регистратор: UK Intis Telecom.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, deshlboard-asset.it.com, was observed as an offline site that previously hosted a brand‑impersonation campaign targeting the cryptocurrency platform aave. Registration data indicate the domain was created on 23 October 1992 and is registered through Intis Telecom Ltd in the United Kingdom. The authoritative name servers are ns1.it.com, ns2.it.com, and ns3.it.com, and DNS resolution points to the IP address 104.21.48.1, which belongs to ASN 13335 operated by Cloudflare, Inc. in the United States. No TLS certificate was presented for the host, meaning any HTTP traffic would have been unencrypted.
The page title returned from the last known HTTP response reads “Texdatalex Systems – Premier Event Management & Hosting Solutions,” which bears no obvious relation to the aave brand and suggests the site was used as a front for the impersonation. Reputation scoring from Gridinsoft assigns a trust score of 0 out of 100, indicating a high confidence of malicious intent. VirusTotal analysis shows that 2 of 95 scanned security vendors flagged the domain, and it appears on a single public blocklist. Additionally, the domain is listed as blocked by PhishDestroy.
The combination of a low trust score, partial vendor detections, and blocklist listings confirms the domain’s involvement in a brand‑impersonation scheme. Defenders should add the domain and its resolving IP to network‑level deny lists, ensure that any residual DNS records are removed, and monitor Cloudflare‑owned address space for similar future abuse. Because the site is currently offline, no further content analysis is possible, and the exact phishing payload or credential‑collection mechanisms remain unknown. Continuous vigilance is recommended, especially for users of the aave platform, to prevent exposure to similar impersonation attempts.
Сигналы безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание