Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@novatrend.ch.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
switchnet[.]ch
switchnet.ch için kimlik avı ve güvenlik kontrolü
“One moment, please...”
switchnet.ch — Gizlenmiş · ulaşılabilir (HTTP 200). Marka kimliğine bürünme: Google; Dolandırıcılık türü: Tech Support Scam. Kanıt özeti: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 1 alert; cloaking observed; PhishDestroy score 100/100. Kayıt kuruluşu: Novatrend.ch.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
switchnet.ch is currently active and has been classified as a high‑risk Google brand‑impersonation campaign. The site returns HTTP 200 with the page title “One moment, please…”, indicating an attempt to hold the visitor while further actions are prepared. The domain was created on 28 February 2026 and is hosted in Switzerland under ASN 35206 (NovaTrend Services GmbH). The domain was registered through Novatrend.ch and resolves to IP 193.33.128.139. DNS resolution uses the top‑host nameservers ns9.tophost.ch and ns10.tophost.ch. The server presents a Let’s Encrypt R12 certificate and runs Nginx with the OpenResty module, a stack commonly observed in malicious hosting environments. Reputation data shows significant concern: VirusTotal records 7 out of 95 scanners flagging the domain, Scamadviser assigns a trust score of 1 / 100, Gridinsoft reports 0 / 100, and the domain appears on at least one public blocklist. The MX records point to mx01.tophost.ch and mx02.tophost.ch, and the site is listed as a tech‑support scam in the intelligence feed. Publicly available information does not include a detailed content analysis beyond the generic page title, nor any observed credential‑capture elements. Consequently, the exact phishing workflow, payload delivery method, or victim interaction steps remain unknown. Continued monitoring of the URL and associated infrastructure is required to capture any evolving tactics. Defenders should immediately block switchnet.ch and its resolve IP 193.33.128.139 at network perimeter and DNS filtering layers. Email gateways should be configured to reject messages originating from the listed MX hosts. Security teams should add the domain and IP to threat‑intel feeds and monitor for any related sub‑domains or similar certificate usages. Users should be warned about unsolicited Google‑related support calls that reference this domain.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | switchnet.ch |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 2 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of switchnet.ch · checked Mar 2, 2026
Kanıtlar ve Dış Raporlar
PD-20260228-A35F63 Recipient: abuse@novatrend.ch Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin