pending-guestf81553[.]com
“pending-guestf81553.com – Information Portal”
pending-guestf81553.com — Непроверенный. Тип мошенничества: Banking Phishing. Сводка доказательств: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); Spamhaus DBL_MALWARE; CF Radar malicious; PhishDestroy score 98/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain pending-guestf81553.com has been identified as a high-risk banking phishing site, active as of July 12, 2026. This domain, registered through Dynadot LLC on November 14, 2025, has been flagged by 18 out of 95 security vendors on VirusTotal, indicating a significant level of concern among the cybersecurity community. The domain is currently blocked by PhishDestroy and PhishingDB, and it has been mentioned in 15 threat intelligence pulses on AlienVault OTX. These blocks and detections suggest that the domain is being actively monitored and mitigated due to its involvement in banking phishing activities. The domain's SSL certificate is issued by Google Trust Services, which might be used to lend a false sense of legitimacy to unsuspecting users. Infrastructure analysis reveals that the domain is hosted in the United States and is managed by Cloudflare, with nameservers elsa.ns.cloudflare.com and malcolm.ns.cloudflare.com. The IP address 188.114.96.3, associated with AS13335 Cloudflare, Inc., further suggests that the attackers are leveraging reputable hosting services to evade detection. The current HTTP status of 521 indicates a connectivity issue, which might be a temporary state or a deliberate tactic to avoid scrutiny. Despite the page title 'pending-guestf81553.com – Information Portal,' the exact content and structure of the website have not been analyzed, and it is recommended that network defenders and security professionals take immediate action to block this domain and educate users about the risks of banking phishing. The Gridinsoft trust score of 0/100 underscores the domain's high risk and the need for vigilant monitoring and proactive defense measures.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание