Перейти к отчёту о безопасности
Checked 09.08.2026 Ref 1C002F67

MALICIOUS — CRITICAL

Проверка домена waagent.net на фишинг и безопасность

waagent[.]net

This domain, waagent.net, is currently under investigation for phishing-related activity following its detection on one security blocklist and inclusion in a single.

76/100 evidence score · Critical
VirusTotal
3/91
Blocklists
No stored match
Доступность
Доступен · доступ ограничен · HTTP 403
Report / Add Evidence Appeal this listing
No capture stored

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Этот домен был отмечен как вредоносный
Механизмы безопасности сообщают об обнаружении: 3. Будьте предельно осторожны — не вводите учетные данные или личную информацию.
Jump to section
Краткий обзор отчёта

waagent.net — Доступен · доступ ограничен (HTTP 403). Сводка доказательств: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 76/100. Регистратор: Fewmoretaps OU d/b/a T….

Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.

Evidence Analysis

Ref 1C002F67

This domain, waagent.net, is currently under investigation for phishing-related activity following its detection on one security blocklist and inclusion in a single threat intelligence pulse within the AlienVault OTX platform. Registered on April 28, 2026, through Fewmoretaps OU operating under Trustname.com, the domain resolves to the IP address 172.67.176.122, which is part of Cloudflare’s infrastructure in Canada. The use of Cloudflare nameservers (sage.ns.cloudflare.com and sarah.ns.cloudflare.com) and a Google Trust Services SSL certificate (WE1) aligns with common patterns observed in both legitimate and malicious web properties, offering no definitive indication of intent on its own. Infrastructure analysis reveals that the domain returns an HTTP 403 status, suggesting access restrictions or a placeholder configuration rather than an openly accessible phishing page. While VirusTotal reports zero detections across 95 engines, this absence of flags does not confirm safety, as newly registered domains often evade initial detection. The domain’s presence on one blocklist and its mention in a threat intelligence pulse indicate preliminary suspicion, though the specific nature of the phishing threat—whether credential harvesting, malware distribution, or another scheme—remains unconfirmed due to limited technical evidence. Defenders should treat waagent.net as a potential threat vector until further analysis clarifies its behavior. Network-level monitoring for connections to 172.67.176.122 or DNS queries for the domain is recommended, particularly in environments where phishing campaigns are a known risk. The domain’s recent registration and Cloudflare hosting are not inherently malicious but warrant heightened scrutiny given the available indicators. Additional telemetry, such as payload analysis or user reports, would be necessary to determine the exact threat posed by this infrastructure.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
3 det.
OTX references
Сертификат TLS
Просрочен или не проверен -43d
Возраст
3 mo
Зафиксированный статус
Доступен · доступ ограничен 403
PhishDestroy
DestroyList
В списке
Охват данных12 recorded checks
VirusTotal 3 / 91 URLQuery не проверено PhishStats не проверено OTX 1 community reference CF Radar no data URLScan capture not submitted URLScan verdict вердикт недоступен DNS-блокировки не проверено TLS Просрочен или не проверен WHOIS 3 mo old Снимок экрана не зафиксировано Цепочка перенаправлений не исследовано
Данные сетевой безопасности Registrar context
Registrar context Trustname
Stored registration data identifies Trustname / Fewmoretaps OÜ (IANA 4318) as the registrar. PhishDestroy maintains a separate registrar investigation; that material is contextual and is not an independent detection for this domain.
Trustname Investigation

Процесс реагирования на угрозы

Открытие
Checks
Reports
Доступность
8/10
Угроза устранена
waagent.net обнаружены и помещены в очередь для полного анализа
15.06.2026
VirusTotal
3/91 recorded on VirusTotal
05.08.2026
Google Safe Browsing
29.04.2026
OTX Community References
1 community publication reference on AlienVault OTX. References are not vendor verdicts and are excluded from the evidence score.
29.04.2026
Registrar Context: Trustname
Separate registrar research is available. Registrar association is contextual and is not scored as an independent detection.
robots.txt Found
A valid robots.txt was observed; no disallowed/allowed paths were extracted
09.08.2026
Technical Analysis Recorded
Отчет содержит сохраненные технологии или результаты судебно-медицинской экспертизы.
09.08.2026
Complaint Draft Available
Подача не фиксируется. Вы можете создать проект, просмотреть его и самостоятельно отправить в соответствующий орган.
Опубликовано «DestroyList»
15.06.2026
Monitoring Continues
Домен остается доступным или доступ к нему ограничен; будущие проверки могут обновить это наблюдение.

Статус в публичных блок-листах

Аналитика доменов

Домен
Сервер / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Репутация Edge-IP не связана с этим доменом.
IP-адрес 172.67.176.122 CDN
ГеолокацияCA Toronto, CA
СетьAS13335 · Cloudflare, Inc.
Обратный поиск IPviewdns.info → rapiddns.io →
Исходный IP-адрес скрыт за прокси-сервером CDN. Результаты обратного IP-адреса для граничного адреса содержат несвязанных клиентов; для определения источника требуется пассивный DNS или данные прозрачности сертификатов.
РегистрацияСоздано 28.04.2026 (102d)
Статус HTTP403 Forbidden
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Впервые обнаружено15.06.2026
Серверы имёнsarah.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 30.03.2026scanned 28.04.2026
ICANN OVERSIGHT

Аккредитация и контекст RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Ничего не отправляется автоматически.
Пожаловаться на этот домен Предоставьте доказательства и помогите защитить других

Анализ VirusTotal

3 / Поставщики средств безопасности 91 отметили этот домен
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
CRDF
Gridinsoft
SOCRadar
Анализ конфигурации сайта
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.

Европол
Найдите официальный канал отчетности для вашей страны ЕС
National police directory
Остерегайтесь мошенников, предлагающих услуги по восстановлению данных! Преступники могут снова связаться с жертвами, притворяясь следователями, адвокатами или агентами по восстановлению. Не платите авансовые платежи и не делитесь учетными данными. Узнайте больше о мошенничестве при получении компенсаций →

Сообщите об этом в местные органы власти

Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.

Каталог 97 стран
Черновик по шаблону • помощь AI с формулировками включается только с отдельного согласия. Просмотрите и отправьте его самостоятельно
Вставить этот отчетRead-only HTML widget
HTML · IFRAME

Вставить этот отчет

Разместите эту информацию об угрозах на своём сайте или в блоге

embed.html
<iframe
  src="https://phishdestroy.io/ru/embed/domain/waagent.net"
  title="PhishDestroy threat report for waagent.net"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Очень искреннее благодарственное письмо

Генератор сатирических черновиков

Получатель
Контекст сборов

Это сатирический черновик. Суммы сборов являются оценочными; мы не утверждаем, что они точно относятся к этому домену.