s25bkhfr[.]top
“404 Not Found”
s25bkhfr.top — Контент недоступен (HTTP 502). Тип мошенничества: Generic Phishing. Сводка доказательств: VirusTotal 17/94 (ADMINUSLabs, alphaMountain.ai, CRDF, CyRadar, ESET); URLQuery 2 alerts; CF Radar malicious; PhishDestroy score 95/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, s25bkhfr.top, is flagged as a generic phishing infrastructure designed to harvest user credentials through deceptive login interfaces. Analysis indicates no direct association with a specific brand or drainer kit, suggesting a broad, opportunistic phishing campaign. The domain’s infrastructure lacks identifiable branding, increasing the likelihood of generic credential theft targeting multiple services or platforms. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 47.253.178.175, hosted on Alibaba Cloud’s US infrastructure. It was registered on April 04, 2025, through Gname.com Pte. Ltd., a registrar frequently utilized for short-lived phishing domains. VirusTotal detection metrics show 17 out of 95 security vendors flagging the domain as malicious. The domain appears on a single security blocklist and is currently blocked by at least one threat intelligence feed. No SSL certificate data is available, which may indicate either a lack of encryption or the use of self-signed certificates to evade detection. As of the latest assessment, s25bkhfr.top has been taken offline, reducing its immediate threat to end users. However, the infrastructure remains a residual risk due to the potential for re-activation or migration to a new domain. Organizations and individuals are advised to monitor for related indicators of compromise, including the IP address 47.253.178.175 and domains registered through the same registrar. Users who may have interacted with this domain should immediately reset credentials for any accounts accessed during the exposure window and enable multi-factor authentication where available. Network-level blocking of the IP and domain is recommended for proactive defense.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of s25bkhfr.top · checked Mar 21, 2026
Доказательства и внешние отчеты
PD-20260321-F23D38 Recipient: complaint@gname.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание