MALICIOUS — CRITICAL
earnwalking.com için kimlik avı ve güvenlik kontrolü
earnwalking[.]
Analysis indicates that earnwalking.com was registered on May 12 2026 through Global Domain Group LLC.
- VirusTotal
- 5/91
- Blocklists
- No stored match
- Kullanılabilirlik
- Bilinen son aktif · HTTP 302
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
earnwalking.com — Bilinen son aktif (HTTP 302). Dolandırıcılık türü: Generic Phishing. Kanıt özeti: VirusTotal 5/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_SPAM; PhishDestroy score 80/100. Kayıt kuruluşu: Global Domain Group.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
Analysis indicates that earnwalking.com was registered on May 12 2026 through Global Domain Group LLC. The domain resolves to IP address 91.218.49.176 with an IP location listed as UA under Virtual Systems LLC. Current status remains active and the HTTP response returns status code 200. Infrastructure analysis reveals the nameservers jill.theonionhost.com and ray.theonionhost.com along with an SSL certificate from Let's Encrypt R12. The observed page title matches Earn Walking — Walk, map, earn.
This domain appears on exactly one security blocklist where it is blocked by PhishDestroy. Gridinsoft reports a trust score of 24 out of 100. VirusTotal shows detections from two out of 95 security vendors while AlienVault OTX lists the domain in one threat intelligence pulse. These indicators align with the recorded threat type of generic phishing and high risk classification.
Uncertainties remain around the exact duration of active operation since registration and any potential future changes to the hosting provider or nameserver configuration. No additional ASN details or brand impersonation targets are recorded in the available data.
Defenders should implement network blocks for the resolved IP address and associated nameservers to limit exposure. Continuous monitoring of traffic to 91.218.49.176 is advised along with review of any inbound links referencing the domain title. Existing blocklist entries provide a baseline for immediate containment actions while further correlation with internal logs can confirm involvement in phishing campaigns.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı13 recorded checks
Güvenlik Sinyalleri
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.