pastnineofficial[.]id
pastnineofficial.id — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 15/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); PhishDestroy score 95/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain pastnineofficial.id is currently listed as offline but remains flagged as a generic phishing threat. Infrastructure analysis shows the domain resolves to the IPv6 address 2606:4700:3034::ac43:cfbc, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. Both authoritative nameservers are hans.ns.cloudflare.com and june.ns.cloudflare.com, confirming that the domain is hosted behind Cloudflare’s DNS and CDN services. No TLS certificate is presented for the host, indicating that HTTPS was never configured before the takedown. Registry data reports that the domain was registered through Cloudflare, Inc., further confirming the use of Cloudflare’s registration platform.
Reputation services provide a consistent view of malicious intent. VirusTotal records indicate that fifteen out of ninety‑five scanning engines have flagged the domain, demonstrating a moderate level of detection across independent scanners. The domain appears on one public blocklist and has been incorporated into fifteen AlienVault OTX threat pulses, suggesting that it has been shared among threat‑intel communities. Gridinsoft assigns a trust score of zero out of one hundred, reinforcing the conclusion that the site is considered highly untrustworthy. PhishDestroy has actively blocked the domain, and the current status is marked as taken offline.
The available intelligence does not contain a page title, SSL details, or any observed content, leaving the exact phishing lure unknown. Because the domain’s infrastructure is fully attributable to Cloudflare, defenders should consider blocking the IPv6 address and the associated Cloudflare nameservers in their perimeter defenses. Network sensors should be configured to flag any DNS resolution attempts for pastnineofficial.id, and security appliances that reference reputation feeds should enforce the blocklist entry.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание