hollythesquirrel[.]xyz
hollythesquirrel.xyz — Контент недоступен. Сводка доказательств: VirusTotal 5/93 (alphaMountain.ai, Fortinet, Gridinsoft, Seclookup, SOCRadar); Spamhaus DBL_SPAM; PhishDestroy score 65/100. Регистратор: PDR.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of hollythesquirrel.xyz shows a domain created on December 29, 2025 and currently hosted behind Cloudflare infrastructure (ASN13335, United States). The domain resolves to IP address 172.67.223.162 and uses the Cloudflare nameservers amos.ns.cloudflare.com and dayana.ns.cloudflare.com. No TLS certificate is presented, indicating that the site is served without HTTPS encryption. A single HTTP response returned the page title "Just a moment...", which provides no additional context about the content or intended victim brand.
The domain is registered through PDR Ltd. d/b/a PublicDomainRegistry.com. Security telemetry indicates that five of ninety-three VirusTotal scanners flagged the domain, and it is listed on one security blocklist, specifically PhishDestroy, confirming that at least one reputable anti‑phishing feed has recognized it as malicious. Gridinsoft assigned a trust score of 0 out of 100, reinforcing the low confidence in its legitimacy. The site has been taken offline, but historical evidence suggests a generic phishing campaign.
Uncertainty remains regarding the specific brand or credential target, as no brand name appears in the page title or other collected attributes. Defenders should immediately block hollythesquirrel.xyz at DNS and proxy layers, monitor for any future resolution to the same Cloudflare IP range, and update intrusion detection signatures to flag HTTP responses containing the "Just a moment..." title from this domain. Continuous observation of the underlying Cloudflare IP block for any resurgence of phishing activity is advised, as infrastructure reuse is common in such campaigns.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание