dobraya-raduga.com.tr
“Steam Gift Activation”
dobraya-raduga.com.tr — Контент недоступен. Олицетворение бренда: Steam; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 21/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 3 alerts; Spamhaus DBL_SPAM; CF Radar malicious; PhishDestroy score 95/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
The domain dobraya-raduga.com.tr was registered on May 23, 2026 and currently resolves to IP 192.162.199.140, which is geolocated to Germany and attributed to Femo IT Solutions Limited. The site delivers an HTTP 200 response and presents the page title "Steam Gift Activation," indicating a brand‑impersonation campaign targeting Steam users. Technical fingerprints show the presence of Nginx, OpenResty, Prototype, Cloudflare, script.aculo.us, reCAPTCHA, jQuery UI, and the jQuery CDN, all served under a Let’s Encrypt YR2 certificate. Independent scoring assigns a Gridinsoft trust score of 0 / 100, and the domain appears on one public blocklist. VirusTotal analysis reports six of ninety‑one scanners flagging the domain, while AlienVault OTX lists it in two threat pulses. The domain is actively blocked by PhishDestroy and is classified as high‑risk. Content beyond the title has not been publicly dissected, so the exact malicious payload remains unclear. Defenders should treat the domain as malicious, enforce network‑level blocking, add it to URL filtering and DNS sinkhole rules, and monitor related IP and certificate indicators for potential reuse. Continuous threat‑intel feeds should be consulted for any updates on associated infrastructure or new detections.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | dobraya-raduga.com.tr |
malicious | Sinkholed |
| Hagezi Threat Feed | dobraya-raduga.com.tr |
malicious | Sinkholed |
| DNS4EU | dobraya-raduga.com.tr |
malicious | Sinkholed |
Forensic History & Detection Timeline
-
Domain Status Transition Aug 6, 2026 · 00:00 UTCDomain state transitioned from alive to dead.
-
Cloudflare Radar Scan Jun 9, 2026 · 05:27 UTCCloudflare Radar scan registered: View Radar report.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сбор доказательств
Статус в публичных блок-листах
Технологии · 11 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% уверенностиPrototype is a JavaScript Framework that aims to ease development of web applications.
www.prototypejs.org 100% уверенностиOpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.
openresty.org 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиreCAPTCHA is a free service from Google that helps protect websites from spam and abuse.
www.google.com 100% уверенностиjQuery UI is a collection of GUI widgets, animated visual effects, and themes implemented with jQuery, Cascading Style Sheets, and HTML.
jqueryui.com 100% уверенностиjQuery CDN is a way to include jQuery in your website without actually downloading and keeping it your website's folder.
code.jquery.com 100% уверенностиjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиАнализ VirusTotal
Сообщения сообщества
Сообщил 1 участник сообщества; впервые замечено 23.05.2026
- Сохранённые сообщения
- 1
- Уникальные URL
- 1
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание