vavada[.]vavadabacks[.]com
“Registration - VAVADA TEAM Panel”
Kanıt özeti
Analysis indicates that the domain vavada.vavadabacks.com was registered on 21 February 2026 and resolves to the IPv4 address 5.61.54.124, which is announced by AS58061 belonging to Scalaxy B.V. in the Netherlands. The site presented the page title “Registration – VAVADA TEAM Panel” and is classified as a brand‑impersonation campaign targeting the Telegram brand. The infrastructure was flagged by the PhishDestroy blocklist and appears on one additional security blocklist. VirusTotal recorded a single positive detection out of 93 scanners, confirming that at least one security vendor identified malicious activity associated with the host. The SSL certificate is identified as “R13”, suggesting a potentially self‑signed or low‑trust certificate, which further reduces the credibility of the site.
The domain is currently reported as offline, and no active HTTP response was observed at the time of assessment. Defenders should note that the combination of a recent registration date, a Dutch hosting location tied to a known abuse‑hosting ASN, and the presence of a brand‑impersonation page title aligns with typical phishing‑kit deployments. The single VirusTotal detection indicates that some scanners have already incorporated the indicator, but broader detection coverage may still be limited. As the domain is already listed on blocklists, automated URL filtering solutions that ingest these feeds will likely block client access.
However, organizations should still incorporate the domain into internal block or allow‑list policies, especially for email gateways and web proxies that reference host‑based reputation. Continuous monitoring of the IP address 5.61.54.124 and the associated ASN for any re‑activation or new sub‑domains is advised. If the domain reappears, a full content fetch should be performed to verify whether the registration panel collects credentials or redirects to a Telegram login replica.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin