dev[.]go-to[.]rest
Проверка домена dev.go-to.rest на фишинг и безопасность
“GTR”
dev.go-to.rest — Контент недоступен (HTTP 404). Олицетворение бренда: Telegram; Тип мошенничества: Brand Impersonation. Сводка доказательств: VT 15/93 (Abusix, Criminal IP, alphaMountain.ai, Certego, Cluster25); URLQuery 0; URLScan no malicious verdict; GSB no flag; BL 0; PD 100/100. Регистратор: Name.com.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
PhishDestroy first observed dev.go-to.rest on Feb 2, 2026. A positive finding was recorded by VirusTotal. Evidence score: 100/100.
VirusTotal recorded 15 detections among 93 engines: Abusix, Criminal IP, alphaMountain.ai, Certego, Cluster25, CRDF, Fortinet, Gridinsoft on Jul 18, 2026 at 18:45 UTC. The external blocklist snapshot contained no matches on Aug 7, 2026 at 14:20 UTC. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict (score 0) on Mar 28, 2026 at 11:49 UTC. PhishStats returned no feed match on Mar 3, 2026 at 08:07 UTC.
HTTP 404 was recorded on Aug 7, 2026 at 01:55 UTC; content was unavailable. Registration records list Name.com, Inc. as the registrar. At collection time, the domain resolved to 37.27.6.109. Collected metadata identifies Telegram as the apparent target. Captured page title: “GTR”. PhishDestroy classified the observed content as Brand Impersonation. DOM analysis completed on Apr 23, 2026 at 07:20 UTC; stored DOM score 10/100. IoC extraction completed on Aug 2, 2026 at 04:01 UTC; stored 0 format-validated wallet addresses and 1 Telegram indicator.
Stored full analysis23.07.2026
The domain dev.go-to.rest was observed by PhishDestroy and classified as a brand‑impersonation campaign targeting Telegram users. Registration data shows the domain was created on 21 February 2026 through Name.com, Inc., and it resolves to the IPv4 address 37.27.6.109, which is assigned to the Hetzner Online GmbH network in Finland (AS 24940). The hosting provider is identified by the IP’s autonomous system, confirming the infrastructure is located in Europe. DNS resolution is handled by Cloudflare, using the authoritative nameservers tim.ns.cloudflare.com and sue.ns.cloudflare.com.
No TLS certificate was presented when the host was queried, and the HTTP response returned a 404 status, indicating the web resource is not publicly serving content at the time of analysis. The page title reported by scanners is “GTR”, which does not reference the targeted brand and suggests the payload page has been removed or is otherwise inaccessible. Gridinsoft assigned a trust score of 0 out of 100, and the domain appears on a single external blocklist, reinforcing the malicious assessment. VirusTotal scans recorded 15 detections out of 93 participating security vendors, confirming that multiple anti‑malware engines flag the domain as malicious.
The overall risk rating is elevated, and the current operational status is offline, meaning the site is no longer reachable but the infrastructure may be reused. Defenders should continue to block the domain and its associated IP address, add the domain to internal URL filtering policies, and monitor for newly registered domains that reuse the same registrar, nameserver configuration, or hosting ASN. Continuous threat‑intel feeds should be consulted for any reappearance of the same indicators, and any inbound traffic to 37.27.6.109 should be inspected for residual malicious payloads.
Сигналы безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: go-to.rest
Аккредитация и контекст RAA
Аккредитация и контекст RAA
ICANN получила деньги. Подотчётность так и не появилась.
For the registrable domain go-to.rest behind this subdomain, the registrar above operates under an ICANN contract. ICANN collects annual, variable and transaction-based fees tied to registrations, renewals and transfers.
Аккредитация: монетизирована. Подотчётность: пожалуйста, проверьте позже.
Затем начинается магия: ICANN пишет RAA §3.18, регистратор расследует злоупотребления внутри собственной клиентской базы, а жертвы бесплатно предоставляют доказательства, пока каждый уровень ждёт, что действовать начнёт кто-то другой. Если благодаря этому жертвы чувствуют себя в большей безопасности — отлично: счёт сделал своё дело.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Об этом отчете: dev.go-to.rest
В этом отчете представлены последние сохраненные доказательства, доступные PhishDestroy. Временные метки источника отображаются там, где они доступны; Вердикты о доступности и поставщика могут измениться после сбора.
Захваченный сайт отображал заголовок страницы “GTR” и мог выдавать себя за Telegram.
Начиная с 07.08.2026, dev.go-to.rest обнаруживался механизмами безопасности 15.
Если вы считаете, что это объявление неточно, подать апелляцию. Чтобы узнать о нашей методологии, посетите Страница часто задаваемых вопросов.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание