Güvenlik raporuna geç
⚠️
Bu alan adı, zararlı olarak işaretlenmiştir
Güvenlik motorları bir algılama bildiriyor: 2. Çok dikkatli olun — kimlik bilgilerini veya kişisel bilgileri girmeyin.
Etki alanı güvenliği ve tehdit istihbaratı

russs-pasport[.]com

“Нужен паспорт России? Без предоплаты с проводкой по базе”

Tehdit kararı Kritik 76/100 kanıt puanı
Kullanılabilirlik Doğrulanmamış Kesin bir akım yanıtı saklanmadı
VirusTotal algılamaları: 2/94 Spamhaus DBL: DBL_PHISH Dolandırıcılık türü: Generic Phishing
OTX: 1 ref 15.06.2026

Kanıt özeti

KRİTİK
Evidence score
76/100

This domain, russs-pasport.com, is identified as a generic phishing operation targeting individuals seeking fraudulent Russian passports. Analysis of the page title, "Нужен паспорт России? Без предоплаты с проводкой по базе," indicates a scam offering counterfeit government documents without upfront payment, leveraging claims of database verification to appear legitimate. No specific brand impersonation or cryptocurrency drainer kit is evident, but the scheme aligns with broader document fraud and identity theft operations. The domain lacks direct ties to known phishing frameworks but exhibits characteristics of low-effort, high-volume social engineering campaigns designed to exploit individuals in need of forged credentials.

Technical indicators confirm elevated risk levels. The domain resolves to IP address 185.110.92.47 and was registered on March 27, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. VirusTotal detection shows 7 out of 95 security vendors flagging the domain as malicious, while AlienVault OTX records its presence in one threat intelligence pulse. The domain appears on a single security blocklist and holds a Gridinsoft trust score of 0/100. Google Safe Browsing status is not explicitly provided, but the combination of registrar reputation, detection rates, and blocklist inclusion strongly suggests malicious intent.

As of the latest assessment, russs-pasport.com has been taken offline, likely due to enforcement actions or hosting provider intervention. The domain is blocked by at least one security solution, and its infrastructure has been disrupted. However, residual risk persists due to the potential for threat actors to re-establish operations under a new domain or IP address. Individuals who may have interacted with this domain are advised to monitor for unauthorized identity usage, particularly in relation to government-issued documents. Organizations should update security controls to block the IP address 185.110.92.47 and domains registered via NICENIC INTERNATIONAL GROUP CO., LIMITED, as part of proactive threat mitigation. Continuous monitoring of related infrastructure is recommended to detect potential resurgence or lateral movement within the same threat cluster.

VirusTotal
VirusTotal
2 det.
OTX references
TLS sertifikası
Süresi dolmuş veya doğrulanmamış
Yaş
5 mo
Gözlemlenen durum
Doğrulanmamış
PhishDestroy
DestroyList
Listelenmiş

Data Coverage

VirusTotal 2 / 94 URLQuery kontrol edilmedi PhishStats kontrol edilmedi OTX 1 community reference CF Radarı no data URLScan capture not submitted URLScan verdict değerlendirme yok DNS engellemeleri kontrol edilmedi TLS Süresi dolmuş veya doğrulanmamış WHOIS 5 mo old Ekran görüntüsü 2 captures · 2 sources Yönlendirme zinciri araştırılmadı
Ağ Güvenliği İstihbaratıRegistrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer:

Tehdit Müdahale Pipeline

Keşif
Checks
Reports
Erişilebilirlik
9/11

Engelleme listesi kapsamı

10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026

10 izlenen harici kaynak Eşleşme yok

Tespit zaman çizelgesi

  1. VirusTotal

    2 → 7

Kaydedilen görüntü

Sayfa başlığı
Нужен паспорт России? Без предоплаты с проводкой по базе
TLS sertifikası
Süresi dolmuş veya doğrulanmamış · Düzenleyen Let's Encrypt / R13

Etki Alanı Analizi

Alan adı
Sunucu / ASN nginx · AS21276 Expert Solutions Georgia LLC
IP itibarı IP abuse confidence 0/100 0 reports checked 14.07.2026
IP adresi 185.110.92.47 NL
Coğrafi konumNL Meppel, NL
AS21276 · XSG Netherlands
KayıtOluşturuldu 27.03.2026 (136d)
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
İlk Kez Tespit Edildi15.06.2026
Ad sunucularıgerald.ns.cloudflare.com
TLS parmak izi
TLS gözlemi01.04.2026 tarihinden itibaren geçerli03.05.2026 tarihinde tarandı
TLS özne alternatif adlarıwww.russs-pasport.com
ICANN OVERSIGHT

Akreditasyon ve RAA bağlamı

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Hiçbir şey otomatik olarak gönderilmez.
Bu Alan Adını Bildir Kanıt sunun ve başkalarını korumaya yardımcı olun

VirusTotal Analizi

2 / 94 güvenlik sağlayıcıları bu alanı işaretledi
View on VT
Last analyzed
Fortinet
SOCRadar
Site Performans Analizi

Google PageSpeed Insights — mobile performance audit of russs-pasport.com · checked Jun 26, 2026

90
Good
Performance
FCP
1.99s
First Contentful Paint
LCP
3.34s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
1.99s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Bu Siteden Etkilendiniz mi?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.

Europol
AB ülkeniz için resmi raporlama kanalını bulun
National police directory
Kurtarma dolandırıcılarına dikkat edin! Suçlular, araştırmacı, avukat veya kurtarma görevlisi gibi davranarak mağdurlarla tekrar iletişime geçebilir. Peşin ücret ödemeyin veya kimlik bilgilerinizi paylaşmayın. Geri ödeme dolandırıcılığı hakkında daha fazla bilgi edinin →

Yerel Yetkililere Bildirin

resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.

97 ülke rehberi
Yapay zeka destekli taslak — olay ayrıntıları yapay zeka sağlayıcısı tarafından işlenir Kendiniz inceleyin ve gönderin

Herhangi Bir Alan Adını Kontrol Et

Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi

Şimdi Tara

Oltalama Olayını Bildir

Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun

Bildir

Canlı Tehdit Akışı

Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri

İzle

Gelişmelerden Haberdar Olun, Güvende Kalın

Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin

Canlı Tehdit Akışı Bu İlanı İtiraz Et

Harici araçlar

HTML · IFRAME

Bu Raporu Yerleştir

Bu tehdit bilgisini web sitenizde veya blogunuzda paylaşın

embed.html
<iframe
  src="https://phishdestroy.io/tr/embed/domain/russs-pasport.com"
  title="PhishDestroy threat report for russs-pasport.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Çok İçten Bir Teşekkür Mektubu

Hicivli taslak oluşturucu

Alıcı
Ücret bağlamı

Hicivli taslak. Ücret rakamları tahminidir; bu alan adına kesin olarak atfedildikleri iddia edilmez.