MALICIOUS — HIGH
help[.]ipsconfirm[.]com
The domain help.ipsconfirm.com was registered on March 12, 2026 through Hello Internet Corp and is currently hosted behind Cloudflare’s network (AS13335).
- VirusTotal
- 1/94
- Blocklists
- No stored match
- Kullanılabilirlik
- İçerik kullanılamıyor · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
help.ipsconfirm.com — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: Steam; Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 1/94 (SOCRadar); URLQuery 1 alert; URLScan malicious verdict; PhishDestroy score 66/100. Kayıt kuruluşu: Hello Internet.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
help.ipsconfirm.com — Phishing Investigation Report
The domain help.ipsconfirm.com was registered on March 12, 2026 through Hello Internet Corp and is currently hosted behind Cloudflare’s network (AS13335).
The domain help.ipsconfirm.com was registered on March 12, 2026 through Hello Internet Corp and is currently hosted behind Cloudflare’s network (AS13335). DNS resolution points to 172.67.134.2 and the authoritative nameservers are luciane.ns.cloudflare.com and piers.ns.cloudflare.com. No custom SSL certificate is observed; the site relies on Cloudflare‑provided TLS. An HTTP request returns the page title "Attention Required! | Cloudflare", which is the standard Cloudflare challenge page rather than a phishing landing page.
Despite the benign title, the domain is listed as a credential phishing site by multiple intelligence sources. It has been blocked by PhishDestroy and appears on one external blocklist. VirusTotal analysis shows a single detection out of 94 security vendors, indicating that at least one scanner identified malicious behavior. Detected technologies include Cloudflare Browser Insights, Cloudflare services, and HTTP/3, all typical of Cloudflare‑protected sites.
The current operational status is offline, suggesting the site has been taken down or is temporarily unavailable. Uncertainty remains around the actual payload or phishing content because no content beyond the Cloudflare challenge page has been captured. Defenders should continue to block the domain at the DNS layer, monitor the IP address for any re‑hosting activity, and add the domain to internal blocklists. Given the registrar, hosting, and detection history, any future re‑activation should be treated as high‑confidence phishing and blocked immediately.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | help.ipsconfirm.com |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Registration: ipsconfirm.com
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain ipsconfirm.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of help.ipsconfirm.com · checked Mar 12, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
PD-20260312-73388C Recipient: abuse@hello.co Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.