MALICIOUS — CRITICAL
devicevrfy[.]net
The domain devicevrfy.net was registered on April 28, 2026 through Fewmoretaps OU d/b/a Trustname.com and is currently resolved to the Cloudflare‑owned address 104.21.11.114, which is geolocated to Canada.
- VirusTotal
- 4/91
- Blocklists
- No stored match
- Доступность
- Последний известный активный · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
devicevrfy.net — Последний известный активный (HTTP 200). Сводка доказательств: VirusTotal 4/91 (ADMINUSLabs, G-Data, Gridinsoft, Sophos); PhishDestroy score 76/100. Регистратор: Fewmoretaps OU d/b/a T….
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
The domain devicevrfy.net was registered on April 28, 2026 through Fewmoretaps OU d/b/a Trustname.com and is currently resolved to the Cloudflare‑owned address 104.21.11.114, which is geolocated to Canada. The site presents an HTTP 200 response with the page title “An Error Occurred: OK”, a generic indicator that the landing page has not been publicly catalogued. Cloudflare’s DNS is used (diva.ns.cloudflare.com, henry.ns.cloudflare.com). The TLS certificate is issued by Let’s Encrypt (E7), confirming the presence of encryption but offering no credibility.
The domain appears on a single security blocklist and is actively blocked by PhishDestroy. It has been referenced in one AlienVault OTX pulse and received detections from four of ninety‑one VirusTotal scanners, suggesting that multiple security vendors have flagged the host as malicious. Independent reputation scoring is extremely low, with Gridinsoft assigning a trust score of 0 out of 100. No additional intelligence about the specific brand or service being impersonated is available; the only observable artifact is the generic error page title.
Consequently, the primary uncertainty lies in the exact phishing template and the targeted audience, which cannot be confirmed without direct content analysis. Defenders should treat devicevrfy.net as a high‑risk indicator: add the domain and its resolving IP to web‑filter deny lists, monitor DNS queries for the Cloudflare nameservers, and enforce TLS inspection to capture any payload that may be delivered over the encrypted channel. Continuous re‑scanning with multi‑engine services is advised to capture any evolving signatures, and any inbound traffic to the IP should be logged and, where possible, redirected to a sinkhole for further forensic examination.
Охват данных12 recorded checks
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.