ysb3[.]co
Проверка домена ysb3.co на фишинг и безопасность
“bet365”
ysb3.co — Контент недоступен (HTTP 502). Олицетворение бренда: Adobe; Тип мошенничества: Crypto Gambling. Сводка доказательств: VirusTotal 17/95 (alphaMountain.ai, BitDefender, CyRadar, ESET, Emsisoft); URLQuery 100 det.; URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 95/100. Регистратор: GoDaddy.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, ysb3.co, poses a high-risk threat as an Adobe brand impersonation phishing site. It is designed to deceive users into believing they are interacting with legitimate Adobe services, potentially leading to credential theft, unauthorized software downloads, or financial fraud. The site was observed displaying a page title associated with bet365, a gambling platform, which may indicate an attempt to obfuscate its true purpose or exploit unrelated traffic sources. Analysis indicates the domain is part of a broader campaign targeting users seeking Adobe software or support, leveraging brand trust to execute malicious activities. Infrastructure analysis reveals ysb3.co was registered on November 26, 2023, through GoDaddy.com, LLC, and resolves to the IP address 34.96.219.82, hosted on Google LLC’s infrastructure (AS396982) in Hong Kong. The domain is flagged by 17 out of 95 security vendors on VirusTotal, appears on two security blocklists, and is explicitly labeled as phishing by Google Safe Browsing. The SSL certificate, issued by Let’s Encrypt (R13), provides minimal encryption but does not validate the site’s legitimacy. Additional intelligence sources, including PhishDestroy and PhishingDB, have independently confirmed the domain’s malicious nature, reinforcing its classification as a high-risk threat. Users who visited ysb3.co should immediately terminate any active sessions and avoid downloading or executing any files from the site. If credentials or payment information were entered, affected accounts should be secured by changing passwords and enabling multi-factor authentication where available. Devices used to access the domain should be scanned for malware using updated security tools. Network administrators are advised to block the domain and its associated IP (34.96.219.82) at the perimeter to prevent further exposure. Monitoring for unusual account activity or unauthorized software installations is recommended for at least 30 days following exposure.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Casino / Gambling License Verification
Технологии · 4 identified
Popular CSS framework for responsive, mobile-first web development.
Modern mobile touch slider with hardware-accelerated transitions.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание