h1[.]pekaw[.]click
“Site is created successfully!”
h1.pekaw.click — Непроверенный. Тип мошенничества: Generic Phishing. Сводка доказательств: VirusTotal 11/93 (Criminal IP, CyRadar, ESET, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; PhishDestroy score 88/100. Регистратор: Sav.com.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, h1.pekaw.click, is flagged as a generic phishing site designed to mimic a legitimate web hosting or site creation service. Analysis of the page title, 'Site is created successfully!', suggests an attempt to deceive users into believing their fraudulent site setup was successful, likely as part of a broader phishing campaign. No specific brand impersonation or crypto drainer kit signatures were identified, but the domain exhibits characteristics consistent with low-effort phishing infrastructure, such as the absence of an SSL certificate and a generic page title. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 178.16.53.103, hosted on AS202412 (Omegatech LTD) in the Netherlands. It was registered on August 30, 2025, through Sav.com, LLC. VirusTotal detection shows 11 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and is not currently listed in Google Safe Browsing (GSB). No SSL certificate is present, increasing the likelihood of interception or manipulation of user data. As of the latest assessment, h1.pekaw.click has been taken offline, reducing immediate exposure risk. However, the domain's recent creation date and the use of a known bulletproof hosting provider suggest potential for re-emergence under a similar or altered infrastructure. Organizations are advised to block the domain and its associated IP (178.16.53.103) at the perimeter. Users should verify site authenticity before entering credentials, particularly on domains with recent creation dates or lacking SSL certificates. Monitoring for related domains registered through the same registrar (Sav.com, LLC) may help preempt future threats from this actor.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: pekaw.click
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain pekaw.click behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of h1.pekaw.click · checked Mar 6, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание