recov-authority[.]com
“Recov-authority.com | Unlock your account”
Kanıt özeti
This domain, recov-authority.com, is identified as a credential theft phishing operation targeting users through fraudulent recovery service impersonation. Analysis indicates the site was designed to mimic legitimate account recovery portals, tricking victims into submitting sensitive login credentials, including usernames, passwords, and multi-factor authentication codes. No direct evidence of a crypto drainer kit or wallet-draining payload was observed, but the infrastructure aligns with credential harvesting campaigns commonly used to facilitate subsequent account takeovers or financial fraud. Infrastructure analysis reveals the domain was registered on April 02, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. The domain resolves to the IP address 188.114.97.3, which has been linked to other malicious activities in recent threat intelligence reports. At the time of assessment, the domain was flagged by 17 out of 95 security vendors on VirusTotal, indicating a moderate-to-high confidence in its malicious classification. It appears on one security blocklist, and while Google Safe Browsing (GSB) status is not explicitly provided, the domain's inclusion in PhishDestroy’s blocklist further corroborates its fraudulent nature. The creation date, combined with the rapid detection by security vendors, suggests a short-lived but aggressive campaign. The domain is currently offline, reducing immediate exposure risk to end users. However, the infrastructure remains a latent threat, as the registrar and hosting IP have not been fully remediated. Historical DNS records and cached content may still pose risks if accessed through archival services or local resolver caches. Organizations are advised to proactively block the domain and associated IP at the network perimeter, while end users should verify recovery requests through official channels only. Given the elevated risk level, continuous monitoring of related domains registered under the same registrar or resolving to the same IP is recommended to preempt potential follow-up campaigns.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260402-863A96- Yakalanan sayfa başlığı
- Recov-authority.com | Unlock your account
- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | recov-authority.com |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Tespit zaman çizelgesi
-
VirusTotal
10 → 17
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of recov-authority.com · checked Jun 26, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin