MALICIOUS — CRITICAL
luno88[.]com
2 of 95 security engines flagged the domain.
- VirusTotal
- 2/95
- Blocklists
- No stored match
- Доступность
- Непроверенный
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
luno88.com — Непроверенный. Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 2/95 (Fortinet, Gridinsoft); PhishDestroy score 71/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Digest
luno88.com is classified critical with an evidence score of 71/100. 2 of 95 security engines flagged the domain. Registered 27 Aug 2025 via Gname.com Pte. Ltd., hosted on 156.244.20.138 (KAOPU-HK Kaopu Cloud HK Limited, HK, KR).
Stored generated summary (templated)cerebras · 24.07.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Analysis as of July 24 2026 indicates that the domain luno88.com was registered on August 27 2025 through Gname.com Pte. Ltd. and is hosted on the IP address 156.244.20.138, which belongs to AS138915 Kaopu Cloud HK Limited located in the Republic of Korea. The domain resolves to this single IPv4 address and uses the authoritative name servers a2.share-dns.com and b2.share-dns.net. No TLS certificate is presented, meaning communications are unencrypted. The page title returned from the host is the bare string “luno88.com”.
Threat intelligence platforms have placed the domain on one security blocklist and PhishDestroy has also blocked it. VirusTotal scanning shows that 2 of 95 AV engines flagged the domain as malicious, confirming a low‑to‑moderate detection consensus. The classification supplied is generic phishing, suggesting the site is intended to harvest credentials or personal data, although the exact lure or target brand is not disclosed. The domain is currently offline, which may indicate takedown or temporary suspension.
Uncertainty remains regarding the specific phishing kit, the victim population, and whether additional infrastructure such as command‑and‑control servers is linked to the same IP range. Defenders should continue to block the domain at the network perimeter, monitor DNS queries for the associated name servers, and add the IP address to blacklist feeds. Organizations using threat‑intelligence feeds should treat the 2/95 detection as an indicator of compromise and consider correlating any recent credential‑theft alerts with activity toward this host. Ongoing observation of the registrar Gname.com Pte. Ltd. for new registrations may help detect future campaigns using a similar supply chain.
Охват данных12 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.