pem-pros[.]com
Проверка домена pem-pros.com на фишинг и безопасность
“Pathfinder Exchange Market”
pem-pros.com — Контент недоступен (HTTP 502). Тип мошенничества: Fake Exchange. Сводка доказательств: VirusTotal 14/91 (ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); PhishDestroy score 92/100. Регистратор: Amazon.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain pem-pros.com is assessed as having an elevated risk level, specifically for credential theft. This domain was registered through Amazon Registrar, Inc. and currently resolves to the IP address 104.26.15.69, which is located in the United States and associated with AS13335 Cloudflare, Inc. The domain was created on October 21, 2025, and is currently offline. VirusTotal reports that 11 out of 95 security vendors flag this domain as malicious, and it appears on one security blocklist, including PhishDestroy. The domain lacks an SSL certificate, which is a common indicator of a phishing site, as legitimate services typically use HTTPS to secure user data.
Infrastructure analysis reveals that pem-pros.com was registered through Amazon Registrar, Inc., a reputable registrar, but this does not necessarily indicate benign intent. The domain's IP address is hosted by Cloudflare, Inc., which is often used to mask the true origin of malicious activities. The creation date of October 21, 2025, suggests that this domain is relatively new, which is a common trait of phishing sites. The lack of an SSL certificate and the presence on one security blocklist further corroborate the elevated risk level. The page title 'Pathfinder Exchange Market' may be an attempt to impersonate a legitimate service, drawing users into providing their credentials.
To mitigate the risk of credential theft, users should avoid interacting with pem-pros.com until it is fully vetted and confirmed safe by multiple security sources. Organizations should update their firewall and DNS settings to block this domain and educate employees on the signs of phishing, such as suspicious page titles and the absence of SSL certificates. Regularly monitoring user accounts for unauthorized access and enabling multi-factor authentication (MFA) can also help prevent successful credential theft attacks.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание