scottytheai[.]com
“Scotty AI | Top Crypto AI Platform”
Сохранённое обнаружение
Обнаружена маскировка
- Тип маскировки
status_split- Оценка маскировки
- 4/6
Сводка доказательств
scottytheai.com is currently active and classified as a high‑risk generic phishing site. The domain was registered on April 28 2023 through Tucows Domains Inc. and resolves behind Cloudflare’s network, which provides DDoS mitigation and SSL termination. An HTTP 200 response is returned for the landing page, indicating that the site is presently serving content.
Infrastructure analysis reveals that the site enforces HTTP Strict Transport Security (HSTS) and supports HTTP/3, suggesting a modern TLS configuration. Embedded third‑party services include Google Tag Manager, Google Analytics, and the advertising platform Adform, all of which can be leveraged for tracking or payload delivery. The presence of Cloudflare also masks the origin IP, complicating attribution.
Threat intelligence shows the page title “Scotty AI | Top Crypto AI Platform”, a branding pattern commonly abused in crypto‑related phishing campaigns. VirusTotal reports two detections out of ninety‑five scanners, confirming malicious behavior. The domain appears on one security blocklist and is listed by PhishDestroy as a confirmed phishing host, reinforcing the high‑risk assessment.
Defenders should immediately block scottytheai.com at the DNS and proxy layers and add it to endpoint URL filtering policies. Continuous monitoring of DNS queries for the domain and its associated CNAME records is advised, as threat actors may pivot to sibling domains hosted on the same Cloudflare account. Incident response teams should also scan inbound traffic for payloads linked to the identified analytics and advertising services, and consider sinkholing the domain to disrupt ongoing campaigns. User reports indicating credential harvesting attempts should be escalated to the phishing response team for forensic capture of submitted data.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии
Выявлено 6 технологий с высокой уверенностью
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание