hafilatbus[.]com
“Hafilat Card Recharge — Top up your transit card online in seconds”
Сводка доказательств
The domain hafilatbus.com has been flagged as a generic phishing threat, specifically impersonating the legitimate Hafilat transit card service to steal users' login credentials and payment information. This fraudulent site mimics the official Hafilat Card Recharge portal, tricking victims into entering sensitive data under the guise of topping up their transit card online. No specific crypto drainer kit was identified, but the site's deceptive design poses a significant risk to users seeking to recharge their transit cards.
Technical analysis reveals that hafilatbus.com was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to IP address 188.114.97.3. VirusTotal data shows 4 out of 95 security vendors flagging this domain as malicious. The SSL certificate is issued by Google Trust Services (WE1), and the domain was created on April 21, 2026. It currently appears on 1 security blocklist, and Google Safe Browsing (GSB) status is not explicitly mentioned but implied by the blocklist presence.
The domain has been taken down, but residual risk remains as similar domains may emerge. Users who have already interacted with hafilatbus.com should change their Hafilat account passwords immediately and monitor for unauthorized transactions. PhishDestroy recommends verifying any transit card recharge site through official channels before entering personal or payment information. Always check the URL carefully and avoid sites that pressure you to act quickly or offer unrealistic deals.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Статус домена
Недоступен → Доступен
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии
Выявлено 6 технологий с высокой уверенностью
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of hafilatbus.com · checked Apr 21, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание