server[.]852852[.]vip
server.852852.vip için kimlik avı ve güvenlik kontrolü
“总后台”
server.852852.vip — İçerik kullanılamıyor (HTTP 502). Dolandırıcılık türü: Generic Phishing. Kanıt özeti: VirusTotal 9/91 (BitDefender, Fortinet, G-Data, Google Safebrowsing, LevelBlue); URLQuery 2 alerts; Google Safe Browsing flagged; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 81/100. Kayıt kuruluşu: GoDaddy.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, server.852852.vip, was set up as a convincing fake admin panel, likely designed to steal login credentials from unsuspecting users. The page title "总后台" (Chinese for "General Backend") suggests it impersonates a backend management system, possibly for a gaming, finance, or e-commerce platform. By mimicking a legitimate login interface, the site aims to trick administrators or users into entering sensitive information, which then gets harvested by cybercriminals. The threat is classified as generic phishing, but the specific targeting of admin panels makes it especially dangerous — compromised credentials could lead to full account takeovers, data breaches, or financial loss.
PhishDestroy's analysis uncovered several red flags. The domain was registered just days ago on May 27, 2025, through GoDaddy.com, LLC, a common registrar for both legitimate and malicious sites. Its SSL certificate comes from Let's Encrypt (E7), which is free and often abused by phishers. The site resolves to IP address 54.179.238.221, hosted on infrastructure that may be shared with other malicious domains. Alarmingly, VirusTotal reports that 9 out of 95 security vendors flag this domain as malicious, and it appears on three separate security blocklists. Google Safe Browsing also explicitly flags it for phishing, confirming the high risk. The domain is currently offline, but that doesn't mean it's gone for good — phishers frequently rotate domains or bring them back under different names.
If you visited server.852852.vip, do not enter any information. Change passwords for any accounts you may have used on similar platforms immediately, and enable two-factor authentication where possible. Run a full antivirus scan on your device to check for any malware that might have been downloaded. Monitor your financial accounts and online services for unusual activity. If you suspect credentials were stolen, report the incident to the affected service's support team. Stay vigilant — phishing sites like this one are constantly evolving, and the best defense is skepticism toward unsolicited login pages and double-checking URLs before entering sensitive data.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | server.852852.vip |
malicious | Sinkholed |
| DNS4EU | server.852852.vip |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Registration: 852852.vip
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain 852852.vip behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Kanıtlar ve Dış Raporlar
PD-20260523-ACC791 Recipient: abuse@godaddy.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin