gxmuseum[.]com
“http://www.gxmuseum.com/”
Kanıt özeti
Analysis of gxmuseum.com indicates a newly registered domain created on 11 March 2026. The domain resolves to 38.182.198.115, an address assigned to ASN 140224 (Nebula Global LLC) and geolocated in Hong Kong. Registration was performed through eName Technology Co., Ltd., and the authoritative name servers are ns1.judns.com and ns2.judns.com. An HTTP request returns a 301 permanent redirect response, and the site presents a TLS certificate issued by Let’s Encrypt with R13 validity.
The only observable page element is the title "http://www.gxmuseum.com/", which mirrors the URL; no additional content has been captured. VirusTotal reports that the domain was scanned by 94 vendors and received no detection flags, but this absence of alerts does not constitute a safety guarantee. The domain appears in 22 AlienVault OTX pulses, is listed on three public security blocklists, and is actively blocked by PhishDestroy, MetaMask, and SEAL. These signals collectively classify the domain as a high‑risk phishing infrastructure.
While the exact phishing payload or targeted brand has not been disclosed, the combination of recent registration, hosting in a region frequently used for malicious campaigns, a valid SSL certificate, and multiple blocklist references suggests intentional abuse. Defenders should deny any outbound connections to the IP address, add the domain to DNS and URL filtering policies, monitor for future resolution changes, and consider sharing the indicator set with threat‑sharing communities. Continued observation is advised, as the site may later host credential‑stealing pages or redirect victims to additional malicious resources.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Tespit zaman çizelgesi
-
Alan adı durumu
Erişilebilir → Erişilemiyor
-
Alan adı durumu
Erişilemiyor → Erişilebilir
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin