h1[.]olux[.]click
“Site is created successfully!”
h1.olux.click — Непроверенный. Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 17/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 98/100. Регистратор: Sav.com.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, h1.olux.click, is assessed as a high-risk credential harvesting phishing site. Analysis indicates it was actively used to deceive users into submitting sensitive login information, likely through spoofed authentication portals or fraudulent account verification pages. The infrastructure exhibits multiple red flags consistent with phishing operations, including the absence of encryption and rapid deployment following domain registration. Infrastructure analysis reveals the following technical indicators: the domain was registered on August 30, 2025, through Sav.com, LLC, and resolves to the IP address 178.16.53.103, hosted on AS202412 (Omegatech LTD) in the Netherlands. Security vendors flagged the domain with 17 detections out of 95 on VirusTotal, while Google Safe Browsing classified it as phishing. The page title 'Site is created successfully!' suggests automated or template-based deployment, a common tactic in phishing campaigns. The domain appears on at least one security blocklist and was subsequently taken offline, though residual risk may persist for users who interacted with it prior to deactivation. Mitigation measures should focus on credential security and infrastructure hardening. Organizations should immediately block the domain and its associated IP (178.16.53.103) at the network level, including DNS and proxy filters. Users who may have entered credentials on this site should reset passwords for all accounts where the same credentials were reused, prioritizing email, financial, and administrative access. Multi-factor authentication (MFA) should be enforced for all critical accounts to mitigate the impact of stolen credentials. Security teams should monitor for follow-up phishing attempts using similar domains or IPs within the same hosting provider (AS202412), as threat actors often reuse infrastructure across campaigns.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: olux.click
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain olux.click behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of h1.olux.click · checked Mar 1, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание