h2[.]etop[.]ink
“Site is created successfully!”
Сводка доказательств
On July 23 2026 analysts observed that the domain h2.etop.ink is currently offline but retains several indicators of malicious infrastructure. The domain was registered through Sav.com LLC on 30 August 2025 and is hosted on the IPv4 address 178.16.53.103, which resolves to the Netherlands under ASN 202412 (Omegatech LTD). No TLS certificate is presented, confirming that the site was served over plain HTTP. The authoritative name servers are augustus.ns.cloudflare.com and laura.ns.cloudflare.com, both belonging to Cloudflare’s DNS service, a common choice for fast‑changing malicious sites.
Gridinsoft assigned a trust score of 0 out of 100, reflecting a complete lack of reputation. The page title returned by the HTTP response is “Site is created successfully!”, which offers no functional description and may be used to obscure the underlying intent. VirusTotal recorded 15 detections out of 93 scanning engines, indicating that a minority of vendors have identified the domain as malicious. The domain appears on a single security blocklist and is actively blocked by the PhishDestroy filtering service.
The risk rating assigned by internal scoring is elevated, consistent with the combination of low trust score, lack of encryption, and multi‑vendor detections. Because the site is offline, dynamic behavior cannot be verified, and the exact phishing payload or credential‑harvesting mechanism remains unknown. Defenders should continue to enforce blocklist rules for h2.etop.ink, monitor the hosting IP 178.16.53.103 for any re‑activation, and consider adding the domain to outbound URL filtering policies. Ongoing observation of the associated Cloudflare name servers is recommended, as they may be reused for future phishing infrastructure.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Registration: etop.ink
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain etop.ink behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of h2.etop.ink · checked Mar 2, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание