uk[.]paying-vs[.]vip
“Welcome to GOV.UK”
Kanıt özeti
Analysis of the domain uk.paying-vs.vip indicates it was actively impersonating the UK Government's official GOV.UK platform, as evidenced by the page title 'Welcome to GOV.UK' captured during infrastructure assessment. The domain, registered on December 17, 2025, through Alibaba Cloud Computing Ltd. (HiChina), was hosted on IP address 151.101.128.144, geolocated in the United States under AS54113 (Fastly, Inc.). The infrastructure relied on nameservers dns31.hichina.com and dns32.hichina.com, consistent with Alibaba Cloud's DNS services. At the time of reporting, the domain was taken offline, though it had already been flagged by at least one security blocklist (PhishDestroy) and detected by 13 of 95 security vendors on VirusTotal, reflecting elevated risk classification.
No SSL certificate was observed, which is atypical for legitimate government services and further supports the phishing assessment. The domain's Gridinsoft trust score of 0/100 aligns with its malicious designation. While the exact phishing kit or payload remains unconfirmed due to the site's offline status, the combination of GOV.UK branding, absence of encryption, and hosting on a content delivery network (CDN) commonly exploited for fast-flux or bulletproof hosting suggests a deliberate attempt to evade detection while targeting UK citizens or entities.
Defenders should treat this domain as compromised infrastructure and prioritize blocking both the domain and its resolved IP in perimeter security controls. Further investigation into associated Alibaba Cloud-hosted domains registered during the same period may uncover related phishing clusters. No additional brand-specific artifacts or scam categorization (e.g., tax refund, benefits fraud) were present in the available data.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Registration: paying-vs.vip
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain paying-vs.vip behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin