onefootballs[.]club
onefootballs.club — Непроверенный. Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. Регистратор: Global Domain Group.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain onefootballs.club has been identified as a high-risk credential phishing site. Analysis indicates that the domain, registered through Global Domain Group LLC on May 27, 2026, is currently active and resolves to the IP address 188.114.97.3, which is located in CA and managed by CloudFlare, Inc. The domain's nameservers are melany.ns.cloudflare.com and trace.ns.cloudflare.com, suggesting the use of CloudFlare's DNS services for potential obfuscation or DDoS protection. The page title 'Just a moment...' is commonly used to mask the true nature of the site, often displaying a loading screen to delay and mislead users. This technique can be used to evade initial detection and allow the attackers to gather more information about the visitor before redirecting them to a phishing page. The domain has been flagged by 2 out of 95 security vendors on VirusTotal and has a Gridinsoft trust score of 0/100, indicating a low level of confidence in its legitimacy. The domain appears on three security blocklists and is blocked by PhishDestroy, MetaMask, and SEAL, further corroborating its malicious intent. Defenders should monitor network traffic for connections to this domain and block it at the firewall or DNS level to prevent potential credential theft. Additionally, users should be educated to recognize and avoid such deceptive pages, especially when they encounter unexpected loading screens or are asked to provide sensitive information. Regular updates to security software and maintaining a list of known malicious domains can help mitigate the risk of falling victim to such attacks.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание