royalcoinshug[.]com
“1 new message”
royalcoinshug.com — Контент недоступен (HTTP 502). Олицетворение бренда: Aave. Сводка доказательств: VirusTotal 14/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Google Safe Browsing flagged; PhishDestroy score 92/100. Регистратор: PDR.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of royalcoinshug.com shows a recently created (21 Feb 2026) domain that was taken offline but left a forensic trail indicating a high‑risk generic phishing operation. The site was protected by a Let’s Encrypt R13 certificate and served over HTTP/3, employing a front‑end stack that included D3, xCharts, Bootstrap, LiteSpeed, Select2, jQuery and FancyBox. Google Safe Browsing flagged the domain for social engineering, and VirusTotal recorded 14 of 93 security vendors marking it as malicious, reinforcing the suspicion of a phishing payload. Gridinsoft assigned a trust score of 0 / 100, and the domain appears on one additional security blocklist besides PhishDestroy, confirming its inclusion in active threat feeds.
Infrastructure analysis reveals the host IP 198.251.81.188 belongs to AS53667 (FranTech Solutions) in the United States, with authoritative nameservers ns17.asurahosting.com and ns18.asurahosting.com, typical of disposable hosting services. The only visible page element is a title reading "1 new message," providing no further insight into the targeted brand or credential‑collection mechanism. Consequently, the precise impersonated entity remains uncertain, and no payload samples have been captured.
Defenders should immediately block the domain and its hosting IP at DNS and firewall layers, ingest the associated hash and indicator data into SIEM and EDR solutions, and monitor for re‑registration or similar patterns from the same ASN or hosting provider. Email gateways should be tuned to flag messages containing the domain or related social‑engineering cues, and threat‑intelligence teams should track the ASN for future malicious registrations. Continuous re‑scanning of the domain, should it reappear, is advised to capture any evolving payloads or new indicators.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 8 identified
Popular CSS framework for responsive, mobile-first web development.
High-performance web server compatible with Apache configurations.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of royalcoinshug.com · checked Mar 2, 2026
Доказательства и внешние отчеты
PD-20260219-1D6292 Recipient: emmabest45@proton.me Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание