gajahbesar[.]xyz
gajahbesar.xyz — Непроверенный. Сводка доказательств: VirusTotal 8/91 (alphaMountain.ai, Bfore.Ai PreCrime, CRDF, Forcepoint ThreatSeeker, Gridinsoft); PhishDestroy score 83/100. Регистратор: Namecheap.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain gajahbesar.xyz is currently offline but has been flagged as malicious by 4 out of 92 vendors on VirusTotal. It was registered through Namecheap and hosted on a CloudFlare IP address located in Canada. Despite its offline status, it has been included in one public blocklist, specifically by PhishDestroy.
This domain was likely involved in phishing activities, exploiting its brief active period to target unsuspecting users. The SSL certificate was issued by Let's Encrypt, a common choice for phishing domains due to its free and automated nature. The use of CloudFlare for hosting indicates an attempt to mask the origin server's IP and possibly leverage CloudFlare's security features to prolong the domain's lifespan.
The fact that gajahbesar.xyz is now offline suggests that either the phishing campaign was short-lived or the domain was taken down due to detection and reporting. The presence of the domain on PhishDestroy's blocklist underscores its malicious intent, even though it is no longer active. This case highlights the importance of rapid detection and response to phishing threats, as domains can quickly go offline after achieving their malicious objectives.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание