Перейти к отчёту о безопасности
⚠️
Этот домен был отмечен как вредоносный
Механизмы безопасности сообщают об обнаружении: 18. Будьте предельно осторожны — не вводите учетные данные или личную информацию.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is trustandsafety@support.aws.com. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
4 months
Reports sent
1
Latest case ID
PD-20260325-6ABA4E
Current status
Observed active at latest stored check
Безопасность домена и анализ угроз

login[.]onemilliondrive[.]com

Вердикт по угрозе Критический 95/100 оценка доказательств
Доступность Непроверенный Текущая доступность не проверена
Всего обнаружений вирусов: 18/94 URLQuery threat systems: 2 alerts Тип мошенничества: Generic Phishing
25.03.2026 1 Report Sent
Краткий обзор отчёта

login.onemilliondrive.com — Непроверенный. Тип мошенничества: Generic Phishing. Сводка доказательств: VirusTotal 18/94 (ADMINUSLabs, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLQuery 2 alerts; PhishDestroy score 95/100. Регистратор: Amazon.

Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.

Сводка доказательств
КРИТИЧЕСКИЙ
Ссылка
640D8C61
Оценка
95/100

This domain is flagged for credential phishing, specifically targeting users of cloud storage services with fake login portals. The risk level is classified as elevated due to its active impersonation of legitimate authentication interfaces, designed to harvest usernames, passwords, and potentially multi-factor authentication codes. Analysis indicates the domain was created recently, increasing suspicion of malicious intent given its short lifespan and immediate use in phishing campaigns. Infrastructure analysis reveals the domain login.onemilliondrive.com was registered on March 25, 2026, through Amazon Registrar, Inc. It resolves to the IP address 34.253.99.190, hosted on an AWS EC2 instance in the eu-west-1 region (Ireland). At the time of assessment, 18 out of 95 security vendors on VirusTotal flagged the domain as malicious. The domain appears on two security blocklists: PhishDestroy and PhishingDB. Its current status is offline, though this does not preclude future reactivation or reuse of associated infrastructure. Mitigation steps for this specific threat type include immediate blocking of the domain and its resolving IP (34.253.99.190) at the network perimeter. Organizations should deploy email filtering rules to quarantine messages containing the domain or its subdomains. Endpoint protection should be configured to detect and prevent access to known phishing URLs, particularly those mimicking cloud storage login pages. Security teams are advised to monitor for credential reuse attempts, as harvested credentials may be leveraged in follow-on attacks. User awareness training should emphasize the risks of entering credentials on unfamiliar login portals, even if they appear visually identical to legitimate services. Log analysis should focus on authentication attempts originating from the domain's IP or associated infrastructure to identify potential compromise.

VirusTotal
VirusTotal
18 det.
URLQuery
URLQuery
2 threat alerts
Сертификат TLS
Amazon RSA 2048 M04
Возраст
5 mo
Зафиксированный статус
Непроверенный
PhishDestroy
DestroyList
В списке
Reports Sent
1
Охват данных VirusTotal 18 / 94 URLQuery 2 threat-system alerts PhishStats не проверено OTX no community references CF Radar no data URLScan capture сохраненный отчет URLScan verdict вердикт недоступен DNS-блокировки не проверено TLS valid certificate, 67d WHOIS 5 mo old Снимок экрана 3 captures · 3 sources Цепочка перенаправлений не исследовано
Данные сетевой безопасности
Threat Detection Systems 2 alerts
Detection System Indicator Verdict Alert
OpenDNS login.onemilliondrive.com phishing Phishing Block
DNS4EU login.onemilliondrive.com malicious Sinkholed

Процесс реагирования на угрозы

Открытие
Checks
Reports
Доступность
9/10

Статус в публичных блок-листах

Сохранённый снимок

Сертификат TLS
Valid transport encryption · Выдан Amazon RSA 2048 M04 · valid for 67 days

Аналитика доменов

Домен
Сервер / ASN nginx · AS16509 Amazon.com, Inc.
Репутация IP abuse score 0/100 0 reports checked 13.08.2026
IP-адрес 34.253.99.190 IE
ГеолокацияIE Dublin, IE
СетьAS16509 · AWS EC2 (eu-west-1)
Обратный поиск IPviewdns.info → rapiddns.io →
Registration (base domain)onemilliondrive.com · Создано 25.03.2026 (141d)
Elapsed Since First Report 115 days
Что мы учитываем Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Непроверенный.
Что содержит каждый отчет Сохраненные записи исходящих отчетов могут ссылаться на доказательства, доступные на данный момент, такие как вердикты поставщиков, регистрационные данные, сведения о хостинге, классификации или снимки экрана. На этой странице не указывается точная доставленная полезная нагрузка, получение, подтверждение или действие получателя.
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Впервые обнаружено25.03.2026
IoC Extractionscanned 01.08.20260 wallet · 0 Telegram IoCs
Серверы имёнns-610.awsdns-12.net
MX Records10 inbound-smtp.us-west-2.amazonaws.com
TLS Observationvalid from 22.09.2025
Case ID
ICANN OVERSIGHT Registration: onemilliondrive.com

Аккредитация и контекст RAA

Registrar accreditation and DNS abuse obligations

For the registrable domain onemilliondrive.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Ничего не отправляется автоматически.
Пожаловаться на этот домен Предоставьте доказательства и помогите защитить других

Анализ VirusTotal

18 / Поставщики средств безопасности 94 отметили этот домен
View on VT
Last analyzed
ADMINUSLabs
BitDefender
Chong Lua Dao
CRDF
CyRadar
DNS8
Forcepoint ThreatSeeker
Fortinet
G-Data
«Касперский»
LevelBlue
Lionic
SafeToOpen
Seclookup
SOCRadar
Sophos
VIPRE
Webroot
Анализ конфигурации сайта
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
/index.php /$

Доказательства и внешние отчеты

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260325-6ABA4E Recipient: trustandsafety@support.aws.com
Page title stored with report: Microsoft Account - Sign In
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 990.5 KB

Повлиял ли на вас этот сайт?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.

Европол
Найдите официальный канал отчетности для вашей страны ЕС
National police directory
Остерегайтесь мошенников, предлагающих услуги по восстановлению данных! Преступники могут снова связаться с жертвами, притворяясь следователями, адвокатами или агентами по восстановлению. Не платите авансовые платежи и не делитесь учетными данными. Узнайте больше о мошенничестве при получении компенсаций →

Сообщите об этом в местные органы власти

Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.

Каталог 97 стран
Черновик по шаблону • помощь AI с формулировками включается только с отдельного согласия. Просмотрите и отправьте его самостоятельно

Проверить любой домен

Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.

Сканировать сейчас

Сообщить о фишинге

Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество

Сообщить

Поток оперативных данных об угрозах

Недавние сообщения о фишинге и наблюдаемые изменения доступности

Отслеживать

Будьте в курсе событий, берегите себя

Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание

Поток оперативных данных об угрозах Подать жалобу на это объявление
HTML · IFRAME

Вставить этот отчет

Разместите эту информацию об угрозах на своём сайте или в блоге

embed.html
<iframe
  src="https://phishdestroy.io/ru/embed/domain/login.onemilliondrive.com"
  title="PhishDestroy threat report for login.onemilliondrive.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Очень искреннее благодарственное письмо

Генератор сатирических черновиков

Получатель
Контекст сборов

Это сатирический черновик. Суммы сборов являются оценочными; мы не утверждаем, что они точно относятся к этому домену.