MALICIOUS — CRITICAL
smartexpressauctions[.]com
3 of 91 security engines flagged the domain; the latest stored check returned HTTP 301.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- Kullanılabilirlik
- Bilinen son aktif · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
smartexpressauctions.com — Bilinen son aktif (HTTP 301). Kanıt özeti: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 76/100. Kayıt kuruluşu: Fewmoretaps OU d/b/a T….
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Digest
smartexpressauctions.com is classified critical with an evidence score of 76/100. 3 of 91 security engines flagged the domain. Registered 28 Apr 2026 via Fewmoretaps OU d/b/a Trustname.com, hosted on 172.67.205.191 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 301.
Stored generated summary (templated)cerebras · 13.07.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Analysis of smartexpressauctions.com shows a newly registered domain (created 28 April 2026) that resolves to the Cloudflare‑protected IP 172.67.205.191 and uses Cloudflare’s joan.ns.cloudflare.com and marek.ns.cloudflare.com name servers. The site returns an HTTP 301 status and presents a valid Let’s Encrypt certificate (CN E8). Reputation data is poor: Gridinsoft assigns a trust score of 0 / 100, two of 91 VirusTotal scanners flag the domain, and it appears in one AlienVault OTX pulse and one public blocklist. The registration record lists Fewmoretaps OU d/b/a Trustname.com as the registrar. The domain is currently blocked by PhishDestroy and remains active. No content‑level analysis (e.g., page markup or credential‑stealing forms) is available, so the exact phishing vector cannot be confirmed beyond the classification in existing threat feeds. Defenders should add the domain to DNS and URL filtering rules, monitor traffic to the associated Cloudflare IP for anomalous patterns, and consider sinkholing the address space if broader abuse is observed. Continuous re‑evaluation is advised as additional intelligence (e.g., payload samples or victim reports) may emerge.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı Registrar context
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.