xchallengers[.]pro
xchallengers.pro için kimlik avı ve güvenlik kontrolü
“Global | eSports and Gaming Community”
xchallengers.pro — Doğrulanmamış. Marka kimliğine bürünme: Celer; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 16/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Ermes); URLScan malicious verdict; Spamhaus DBL_SPAM; PhishDestroy score 95/100. Kayıt kuruluşu: PDR.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain xchallengers.pro was registered through PDR Ltd. d/b/a PublicDomainRegistry.com and is currently listed as offline. Infrastructure analysis shows the domain resolves to IP 91.214.78.102, which belongs to AS205775 NEON CORE NETWORK LLC and is geolocated in the Netherlands. The authoritative nameservers are dns1.regway.com, dns2.regway.com, dns3.regway.com, and dns4.regway.com, indicating use of the RegWay DNS service. A Let's Encrypt certificate issued under the E7 identifier secures the site, a common choice for rapidly deployed malicious sites.
The page title returned by the web server is "Global | eSports and Gaming Community," but no further content has been captured; the site is therefore not directly observable for visual phishing indicators. The domain is flagged as a brand impersonation targeting the brand celer, and it has been classified as a "Brand Impersonation" scam type by threat intelligence sources. Detection metrics show that 16 of 93 security vendors on VirusTotal have flagged the domain as malicious, and it appears on a single security blocklist. Independent verification by PhishDestroy confirms the domain is blocked, and a Gridinsoft trust score of 0 / 100 reflects an extremely low reputation.
While the domain is offline, its recent activity demonstrates a typical short‑lived phishing infrastructure that leverages compromised or rented DNS and hosting resources. Defenders should continue to block the domain at perimeter filters, ensure that any internal indicators of compromise referencing the IP 91.214.78.102 are investigated, and monitor for re‑registration attempts or similar domains using the same registrar or DNS provider. Ongoing threat hunting should include checking for celer‑related credential harvesting attempts and correlating user reports with the observed page title and host infrastructure.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin