outdesk[.]app
“SMARTDESK - CRM”
Сводка доказательств
The domain outdesk.app was registered on 21 February 2026 through NiceNIC International Group Co., Limited and is currently pointing to the IP address 185.197.182.32. The address resolves to Germany and is announced by ASN 51396 (Pfcloud UG). DNS resolution is served by two Cloudflare name‑servers, chelsea.ns.cloudflare.com and steven.ns.cloudflare.com. No TLS certificate is presented, and HTTP requests receive a 302 redirect response. The landing page reports the title “SMARTDESK ‑ CRM”, which suggests a credential‑collection site targeting users of a CRM product, but the content of the page has not been publicly disclosed.
Three of ninety‑three VirusTotal scanners have flagged the domain as malicious, and it appears on a single external blocklist that is currently enforced by the PhishDestroy service. Its risk rating is classified as high and the operational status is listed as active. The limited detection footprint—only three vendor detections and one blocklist entry—indicates that the site may be newly deployed or using evasion techniques that avoid broader detection. At present, the concrete malicious behavior observed is limited to the redirection and the absence of transport‑layer encryption, which are common tactics for credential‑harvesting sites.
Defenders should block outbound connections to 185.197.182.32 and add outdesk.app to URL filtering policies. Monitoring of DNS queries for the Cloudflare name‑servers associated with this domain can provide early warning of future infrastructure changes. Because the page title references “SMARTDESK”, organizations using that brand should treat any unsolicited login prompts from this domain as suspicious. Continuous re‑evaluation is recommended as additional threat‑intel sources may update the detection count or blocklist presence.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260214-36266B- Заголовок сохранённой страницы
- SMARTDESK - CRM
- PDF-файл
- PDF с доказательствами
Полный текст доказательств
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | outdesk.app |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание