Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@living-bots.net.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
fahri-kayran[.]de
“Fahri Kayran - Das bin ich!”
fahri-kayran.de — Непроверенный. Сводка доказательств: VirusTotal 10/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker); PhishDestroy score 93/100. Регистратор: Living-bots.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
fahri-kayran.de was registered on 21 February 2026 through the registrar Living-bots and is hosted on an address in Germany (45.88.111.197, AS44486 synlinq.de). The authoritative nameservers are ns1.dnslinq.de and ns2.dnslinq.de. The site presents a TLS certificate issued by Let’s Encrypt (R13) and returns an HTTP 301 redirect. The page title returned by the server is “Fahri Kayran - Das bin ich!”. Automated analysis identified a stack that includes Plesk, Apache HTTP Server, Unpkg, OWL Carousel, jQuery and Font Awesome. The Gridinsoft trust score is 0 out of 100, indicating a lack of reputation.
VirusTotal has recorded five detections out of ninety‑three scanners, and the domain appears on one public phishing blocklist as well as the PhishDestroy blocklist. AlienVault OTX lists the domain in a single threat‑intel pulse. The risk level is classified as high and the threat type is generic phishing; the domain remains active as of the report date 24 July 2026. The available evidence confirms that the infrastructure is newly created, uses common web‑hosting components, and has already attracted modest detection from security vendors. However, the specific phishing payload, targeted victim set, and any credential‑harvesting pages have not been observed, leaving the exact attack vector uncertain. Defenders should prioritize immediate blocking of the domain and its resolved IP address at perimeter firewalls and proxy layers.
Adding the domain to internal URL filtering and threat‑intelligence feeds will ensure continued visibility. Continuous monitoring of the IP range owned by AS44486 and periodic re‑scans with VirusTotal or similar platforms are recommended to capture any escalation in malicious activity. Organizations that rely on the listed web technologies should be aware of potential abuse of these components for drive‑by or credential‑stealing scripts.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 6 identified
Most widely used open-source HTTP server software.
Fast CDN for everything on npm — serves raw files from npm packages.
Touch-enabled jQuery plugin for responsive carousel sliders.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Icon font library.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of fahri-kayran.de · checked Mar 2, 2026
Доказательства и внешние отчеты
PD-20260202-8F8F16 Recipient: abuse@living-bots.net Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание