ref-link-dit5mfs31bi3kt27[.]com
“ref-link-dit5mfs31bi3kt27.com”
Kanıt özeti
PhishDestroy has identified ref-link-dit5mfs31bi3kt27.com as an elevated-risk domain engaged in generic phishing, specifically targeting users for credential theft. This site was designed to trick visitors into entering sensitive information under false pretenses. The domain has been taken offline, but its infrastructure remains a concern for potential reactivation or similar threats.
Data from multiple intelligence sources underscores the risk. VirusTotal reports that 2 out of 95 security vendors flag this domain as malicious, indicating consistent detection across the security community. The domain was registered on April 28, 2026, through Fewmoretaps OU d/b/a Trustname.com, a registrar sometimes associated with questionable domains. It resolves to IP address 62.60.226.89 and uses a Let's Encrypt SSL certificate (E7), which is common among both legitimate and malicious sites. The domain appears on at least one security blocklist, and its current status shows it has been taken offline. These indicators collectively point to a coordinated phishing operation designed to harvest credentials.
Users who may have encountered this domain should be aware that it was part of a credential theft scheme. Even though the site is offline, any passwords or personal details entered there should be changed immediately on the affected services. Enable two-factor authentication on all accounts as an added layer of security. Monitor accounts for unusual activity and consider running a security scan on devices that visited the site. PhishDestroy recommends staying vigilant against similar phishing domains that may appear with slight variations in the domain name.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | ref-link-dit5mfs31bi3kt27.com |
malicious | Sinkholed |
| Hagezi Threat Feed | ref-link-dit5mfs31bi3kt27.com |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler
4 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin