gwem76x[.]life
“GET-X”
gwem76x.life — Непроверенный. Сводка доказательств: VirusTotal 10/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); Spamhaus DBL_SPAM; PhishDestroy score 88/100. Регистратор: URL Solutions.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis indicates that the domain gwem76x.life is actively flagged as a high-risk phishing site targeting credentials under the page title 'GET-X'. Registered on February 21, 2026, through URL Solutions, Inc., the domain resolves to the IP address 186.2.165.69, hosted by Iqweb LLC in the United Arab Emirates. Infrastructure analysis reveals the use of nameservers ns1.pananames.com through ns4.pananames.com, a pattern commonly observed in phishing campaigns leveraging bulk domain registration services. The domain is currently detected by 2 of 93 security vendors on a widely used scanning platform, with additional blocking by at least one dedicated anti-phishing system. The SSL certificate is classified as R11, a designation often associated with low-trust or automated certificate issuance, further reducing confidence in the domain's legitimacy. Technologies detected on the site include Node.js, Google Cloud, Vue.js, Nuxt.js, Nginx, Amazon Web Services, and reCAPTCHA, suggesting a moderately sophisticated infrastructure that may be used to evade basic detection mechanisms or simulate legitimacy. The HTTP status code 301 indicates a permanent redirect, though the destination remains unconfirmed. The domain appears on one security blocklist as of the report date. While the exact brand or service being impersonated is not explicitly identified in available data, the page title 'GET-X' may imply a focus on credential harvesting or account takeover attempts. Defenders are advised to treat this domain as malicious and implement blocking at the DNS or network level. Further investigation into associated IP ranges, certificate histories, and redirect chains is recommended to identify related infrastructure. Given the active status and high-risk classification, monitoring for new domains registered under the same nameservers or IP space may aid in preemptive mitigation.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 14 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Suite of cloud computing services running on Google infrastructure.
Progressive JavaScript framework for building user interfaces.
Hybrid Vue framework for server-side rendering and static sites.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Cloud computing platform offering compute, storage, and networking services.
Google's bot-challenge service. On phishing sites, used to appear legitimate and filter out automated scanners.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comContent delivery network built on Google global edge infrastructure.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comAmazon Web Services CDN for low-latency content delivery.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание