register-aerospace[.]com
Проверка домена register-aerospace.com на фишинг и безопасность
“Aerospace”
register-aerospace.com — Контент недоступен (HTTP 502). Олицетворение бренда: Discord; Тип мошенничества: Wallet/seed Phishing. Сводка доказательств: VirusTotal 2/95 (G-Data, Webroot); 1 external blocklist match (ScamSniffer); PhishDestroy score 58/100. Регистратор: ERANET INTERNATIONAL.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain register-aerospace.com was registered on September 09, 2025 through ERANET INTERNATIONAL LIMITED. It resolves to 104.21.112.1, an address owned by Cloudflare (AS13335) located in the United States. The site presents a page titled “Aerospace” and does not serve an SSL certificate. Analysis identifies the domain as a wallet/seed phishing campaign that impersonates the Discord brand. The Gridinsoft trust score is 0 out of 100, reflecting extreme malicious confidence.
VirusTotal recorded two positive detections out of ninety‑five scanners, and the domain appears on two public blocklists, specifically PhishDestroy and ScamSniffer. Both Cloudflare nameservers archer.ns.cloudflare.com and vida.ns.cloudflare.com are configured for the domain. The current operational status is offline, but historic activity indicates that the infrastructure was used to lure victims into providing cryptocurrency wallet seeds under the guise of a Discord‑related request. Defenders should treat register-aerospace.com as a confirmed malicious indicator. Immediate actions include adding the domain and its resolving IP address to network‑level deny lists, updating URL filtering policies, and ensuring that any endpoint protection solutions flag the domain as hostile.
Because the domain is hosted on a shared Cloudflare edge, related subdomains may be provisioned in the future; continuous monitoring of the IP 104.21.112.1 for new DNS records is advisable. The lack of TLS does not mitigate risk, as the site can still deliver phishing content over HTTP. Correlation with other observed Discord‑impersonation campaigns should be performed, and any detection of wallet‑seed harvesting attempts should trigger incident response procedures. Until the domain is permanently taken down, security teams should maintain the blocklist entries and audit logs for any attempted connections.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание