immortal[.]rs
“Immortal”
Kanıt özeti
Analysis of the domain immortal.rs indicates it operated as a generic phishing site targeting user credentials. The domain was registered on March 06, 2026, through registrar Stanco d.o.o. and resolved to IP address 151.247.193.142, hosted under AS399486 (12651980 CANADA INC.) in France. Nameservers were delegated to ns1.eggywall.cc and ns2.eggywall.cc, a pattern consistent with bulletproof or low-reputation hosting infrastructure. The SSL certificate was issued by Let's Encrypt (serial E7), providing basic encryption without identity validation.
At the time of assessment, the domain was flagged by 16 of 94 security vendors on VirusTotal and appeared on one security blocklist, specifically PhishDestroy. The page title 'Immortal' suggests branding or thematic content, though the exact phishing lure or targeted brand remains unconfirmed due to the site being offline. No evidence links this domain to a specific scam type such as crypto, banking, or retail fraud. Defenders should treat immortal.rs as confirmed malicious infrastructure.
The IP address 151.247.193.142 and nameserver pair (ns1.eggywall.cc, ns2.eggywall.cc) should be blocked at the network perimeter. Historical DNS and SSL logs should be reviewed for connections to this domain or IP. Given the domain's recent registration and offline status, monitoring for re-activation or migration to new IPs is recommended. No further forensic artifacts are available due to the site's current inaccessibility.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260306-DB53CF- Yakalanan sayfa başlığı
- Immortal
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | immortal.rs |
malicious | Sinkholed |
| DigiCert UltraDNS | immortal.rs |
malicious | Sinkholed |
| OpenDNS | immortal.rs |
phishing | Phishing Block |
| Hagezi Threat Feed | immortal.rs |
malicious | Sinkholed |
| Quad9 DNS | immortal.rs |
malicious | Sinkholed |
| DNS4EU | immortal.rs |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Tespit zaman çizelgesi
-
VirusTotal
0 → 16
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin