Güvenlik raporuna geç
Checked 09.08.2026 Ref C0044EB5

MALICIOUS — CRITICAL

sp5usder[.]com

The domain sp5usder.com has been identified as a generic phishing threat, currently taken offline.

76/100 evidence score · Critical
VirusTotal
4/91
Blocklists
No stored match
Kullanılabilirlik
Bilinen son aktif · HTTP 301
Report / Add Evidence Appeal this listing
2026-04-28 15:27 UTCBilinen son aktif · HTTP 301

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Bu alan adı, zararlı olarak işaretlenmiştir
Güvenlik motorları bir algılama bildiriyor: 4. Çok dikkatli olun — kimlik bilgilerini veya kişisel bilgileri girmeyin.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@trustname.com. The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
3 months
Reports sent
1
Latest case ID
PD-20260428-C34293
Current status
HTTP 301 at latest stored check
Jump to section
Rapor özeti

sp5usder.com — Bilinen son aktif (HTTP 301). Kanıt özeti: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 76/100. Kayıt kuruluşu: Fewmoretaps OU d/b/a T….

Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.

Evidence Analysis

Ref C0044EB5

The domain sp5usder.com has been identified as a generic phishing threat, currently taken offline. The page title, "Администрирование FreePBX," suggests it impersonated the FreePBX administration interface, likely to harvest credentials or sensitive data from system administrators. This type of phishing attack targets users managing VoIP systems, posing as a legitimate login portal to steal authentication details.

According to security intelligence, sp5usder.com was flagged by 1 of 95 VirusTotal vendors, indicating limited but confirmed malicious detection. The domain was created on April 28, 2026, and registered through Fewmoretaps OU d/b/a Trustname.com. It resolves to IP address 185.185.49.152 and uses SSL certificate NLDW3-6-30-37. AlienVault OTX recorded the domain in one threat intelligence pulse, and it appears on a single security blocklist. These technical indicators, combined with the phishing-oriented page title, confirm the domain's malicious intent.

As the domain is now offline, the immediate risk is mitigated, but users who may have interacted with it should change passwords and enable multi-factor authentication on affected accounts. PhishDestroy recommends verifying any suspicious links through its platform before engaging. Always access FreePBX or similar services directly via official URLs, and avoid clicking unsolicited links in emails or messages. Stay vigilant against social engineering tactics that mimic trusted administrative interfaces.

VirusTotal
VirusTotal
4 det.
OTX references
URLScan
URLScan
TLS sertifikası
NLDW3-6-30-37
Yaş
3 mo
Gözlemlenen durum
Bilinen son aktif 301
PhishDestroy
DestroyList
Listede
Reports Sent
1
Veri kapsamı12 recorded checks
VirusTotal 4 / 91 URLQuery checked — no detections recorded PhishStats kontrol edilmedi OTX 1 community reference CF Radarı no data URLScan capture saklanan rapor URLScan verdict Analiz tamamlandı DNS engellemeleri kontrol edilmedi TLS valid certificate, 3538d WHOIS 3 mo old Ekran görüntüsü 2 captures · 2 sources Yönlendirme zinciri araştırılmadı
Ağ Güvenliği İstihbaratı Registrar context
Registrar context Trustname
Stored registration data identifies Trustname / Fewmoretaps OÜ (IANA 4318) as the registrar. PhishDestroy maintains a separate registrar investigation; that material is contextual and is not an independent detection for this domain.
Trustname Investigation

Tehdit Müdahale Pipeline

Keşif
Checks
Reports
Kullanılabilirlik
11/12

Genel Engelleme Listesi Durumu

Kaydedilen görüntü

Sayfa başlığı
Администрирование FreePBX
TLS sertifikası
Valid transport encryption · Düzenleyen NLDW3-6-30-37 · valid for 3538 days

Etki Alanı Analizi

Alan adı
URLScan Verdict Analiz tamamlandı score 0 report ↗
Sunucu / ASN Apache · AS49981 WorldStream B.V.
IP itibarı abuse score 0/100 0 reports checked 13.07.2026
IP adresi 185.185.49.152 NL
Coğrafi konumNL Naaldwijk, NL
AS49981 · Worldstream
KayıtOluşturuldu 28.04.2026 (102d)
HTTP Durumu301 Moved Permanently
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
İlk Kez Tespit Edildi28.04.2026
IoC Extractionscanned 29.07.20260 wallet · 0 Telegram IoCs
Ad sunucularıkeaton.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 20.04.2026scanned 28.04.2026
TLS SAN Domainsnldw3-6-30-37
Case ID
ICANN OVERSIGHT

Akreditasyon ve RAA bağlamı

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Hiçbir şey otomatik olarak gönderilmez.
Bu Alan Adını Bildir Kanıt sunun ve başkalarını korumaya yardımcı olun

VirusTotal Analizi

4 / 91 güvenlik sağlayıcıları bu alanı işaretledi
View on VT
Last analyzed Previous stored snapshot: 4 detections
alphaMountain.ai
CRDF
Gridinsoft
SOCRadar
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.

Europol
AB ülkeniz için resmi raporlama kanalını bulun
National police directory
Kurtarma dolandırıcılarına dikkat edin! Suçlular, araştırmacı, avukat veya kurtarma görevlisi gibi davranarak mağdurlarla tekrar iletişime geçebilir. Peşin ücret ödemeyin veya kimlik bilgilerinizi paylaşmayın. Geri ödeme dolandırıcılığı hakkında daha fazla bilgi edinin →

Yerel Yetkililere Bildirin

resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.

97 ülke rehberi
Yapay zeka destekli taslak — olay ayrıntıları yapay zeka sağlayıcısı tarafından işlenir Kendiniz inceleyin ve gönderin
Bu Raporu YerleştirRead-only HTML widget
HTML · IFRAME

Bu Raporu Yerleştir

Bu tehdit bilgisini web sitenizde veya blogunuzda paylaşın

embed.html
<iframe
  src="https://phishdestroy.io/tr/embed/domain/sp5usder.com"
  title="PhishDestroy threat report for sp5usder.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Çok İçten Bir Teşekkür Mektubu

Hicivli taslak oluşturucu

Alıcı
Ücret bağlamı

Hicivli taslak. Ücret rakamları tahminidir; bu alan adına kesin olarak atfedildikleri iddia edilmez.