allocation-slerf[.]lol
Kanıt özeti
Allocation-slerf.lol was registered on 18 October 2025 through NiceNIC International Group Co., Limited. The domain resolves to 172.67.195.179, an address owned by AS13335 Cloudflare, Inc. located in the United States. DNS records show the authoritative nameservers leah.ns.cloudflare.com and vicente.ns.cloudflare.com, indicating the use of Cloudflare’s DNS service. No TLS certificate was observed; the HTTPS endpoint returns no certificate, which is consistent with the current offline status.
Threat‑intelligence feeds list the domain on two blocklists, specifically PhishDestroy and ScamSniffer, and VirusTotal reports six detections out of ninety‑five scanned engines. Gridinsoft assigns a trust score of zero out of one hundred, reinforcing the low reputation. The HTTP response contains the title “Just a moment…”, but no further page content has been captured, leaving the exact phishing lure undefined. The evidence suggests that allocation‑slerf.lol is being leveraged for a generic phishing campaign, likely intended to redirect victims to a malicious landing page before the infrastructure is taken down.
Because the site is presently offline, active probing is limited to passive DNS and blocklist observations. Defenders should add the domain and its resolving IP to local blocklists, monitor the associated Cloudflare nameservers for re‑registration, and consider expanding heuristic rules to flag similar short‑lived .lol registrations. Continuous re‑scanning on VirusTotal or comparable platforms is recommended to capture any future payload changes. Until the site reappears, the immediate risk is mitigated, but the observed infrastructure indicates a reusable pattern that may be repurposed for future phishing operations.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Kaydedilmiş sonuç kanıtı
Sonuç ve kaldırma ilişkilendirmesi
- Sonuç
held- Erişilebilirlik
unreachable- Neden
registrar_client_hold- Aktör
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Mekanizma
client_hold- Güven
- 95%
- İlk gözlem
- Son gözlem
Tahmini erişilememe
Erişilemezliğe kadar geçen süre: 0 hKanıt SHA-256 0769154e889b
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
-
Erişilebilirlik
İlk kayıtlı değer: DNS etkin değil
f93a11f87e4d -
Erişilebilirlik
DNS etkin değil → Bilinmiyor
4e219cff538a -
Erişilebilirlik
Bilinmiyor → Etkin değil
208556e72888 -
Erişilebilirlik
Etkin değil → DNS etkin değil
1c52190a0bf5 -
Erişilebilirlik
DNS etkin değil → Bekletiliyor
b9c6b38cbcbc -
Erişilebilirlik
Bekletiliyor → DNS etkin değil
f52d526b76a1 -
Erişilebilirlik
DNS etkin değil → Bilinmiyor
b593afb0cf1c -
Erişilebilirlik
Bilinmiyor → Bekletiliyor
6dc01ce8e8e2 -
Erişilebilirlik
Bekletiliyor → Bilinmiyor
247b25bb037c
Tümünü göster (8)
-
Erişilebilirlik
Bilinmiyor → DNS etkin değil
6dfe9145995c -
Erişilebilirlik
DNS etkin değil → Bekletiliyor
982bf6f1873c -
Erişilebilirlik
Bekletiliyor → DNS etkin değil
641ed81dc4d5 -
Erişilebilirlik
DNS etkin değil → Bilinmiyor
da3eefba1db6 -
Erişilebilirlik
Bilinmiyor → Bekletiliyor
4043176a999c -
Erişilebilirlik
Bekletiliyor → Bilinmiyor
b6a9effc8680 -
Erişilebilirlik
Bilinmiyor → DNS etkin değil
d0b7046e8c2f -
Erişilebilirlik
DNS etkin değil → Bekletiliyor
0769154e889b
Topluluk raporları
1 topluluk üyesi tarafından bildirildi; ilk görülme 19.10.2025
- Kayıtlı raporlar
- 1
- Bildirilen benzersiz URL’ler
- 1
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Adli İstihbarat
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin