Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@ptisp.pt.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
referestrategia[.]pt
“Index of /”
referestrategia.pt — Непроверенный. Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 17/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 4 alerts; Google Safe Browsing flagged; PhishDestroy score 95/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, referestrategia.pt, is identified as a generic phishing site designed to harvest user credentials through deceptive login interfaces. Analysis indicates no direct association with a specific brand or drainer kit, though the presence of an open directory listing (Index of /) suggests potential staging or misconfiguration commonly observed in hastily deployed phishing infrastructure. The domain lacks overt branding, increasing the likelihood of broad, opportunistic targeting rather than a spear-phishing campaign against a particular organization. Technical indicators confirm the domain's malicious nature. VirusTotal reports 17 out of 95 security vendors flagging referestrategia.pt as malicious. The domain was registered on October 23, 2023, and resolves to the IP address 5.253.183.22, hosted on AS24768 (ALMOUROLTEC SERVICOS DE INFORMATICA E INTERNET LDA) in Portugal. Google Safe Browsing explicitly classifies the domain as phishing, and it appears on one security blocklist. The SSL certificate is issued by Let's Encrypt (R13), a common choice for both legitimate and malicious sites due to its free and automated issuance process. As of the latest assessment, referestrategia.pt has been taken offline, likely in response to detection and reporting. However, the infrastructure remains a residual risk. The hosting provider and registrar may still retain logs or artifacts that could facilitate further malicious activity if the threat actor reacquires control. Organizations are advised to block the domain and IP at the perimeter, monitor for related indicators of compromise, and educate users on recognizing open directory listings as potential red flags. Given the domain's recent creation and rapid takedown, continued vigilance for similar domains leveraging the same IP or registrar is recommended.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | referestrategia.pt |
phishing | Phishing Block |
| Hagezi Threat Feed | referestrategia.pt |
malicious | Sinkholed |
| Quad9 DNS | referestrategia.pt |
malicious | Sinkholed |
| DNS4EU | referestrategia.pt |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% уверенностиOpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.
openresty.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of referestrategia.pt · checked Mar 18, 2026
Доказательства и внешние отчеты
PD-20260318-7EFC7F Recipient: abuse@ptisp.pt Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание