tyjghf[.]duckdns[.]org
“Nightlife”
tyjghf.duckdns.org — Doğrulanmamış. Kanıt özeti: VirusTotal 10/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLQuery 1 alert; PhishDestroy score 88/100. Kayıt kuruluşu: GANDI SAS.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain tyjghf.duckdns.org is currently flagged as a high‑risk generic phishing site. Analysis classifies it as active as of the report date, July 12, 2026, and assigns a high risk level based on multiple intelligence sources. The site is listed on one security blocklist and is actively blocked by a dedicated phishing mitigation service.
Infrastructure analysis reveals that the domain was registered on March 04, 2026 through GANDI SAS. DNS resolution points to the IP address 185.80.128.26, which resides in Lithuania under autonomous system AS61053 operated by UAB ESNET. The host presents a valid TLS certificate issued by Let’s Encrypt (R13), indicating the use of automated certificate provisioning. HTTP traffic returns a 303 status code, suggesting a redirection behavior. The underlying web stack comprises WordPress, Plesk, MySQL, PHP, and Nginx, a combination commonly observed in compromised or malicious hosting environments.
Threat intelligence shows that the domain appears on a single blocklist and is blocked by PhishDestroy. VirusTotal reports that 12 of 95 scanned security vendors flagged the domain, reinforcing the suspicion of malicious activity. The page title observed is “Nightlife,” though no further content analysis is available. A Gridinsoft trust score of 0 out of 100 underscores the low reputation of the host. These concrete indicators collectively support the phishing classification.
Uncertainty remains regarding the specific payload or credential‑harvesting mechanisms employed, as no visual or content inspection has been performed. Defenders should prioritize blocking the domain at network perimeter controls, monitoring DNS queries for the associated IP, and enforcing TLS inspection to detect potential redirects. Continuous re‑evaluation is advised, given the active status and recent creation date, to capture any evolution of the campaign.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | tyjghf.duckdns.org |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 5 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of tyjghf.duckdns.org · checked Mar 4, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin