135461223[.]site
“Nimblr Security Awareness”
135461223.site — Неперевірений. Уособлення бренду: Microsoft; Тип шахрайства: Tech Support Scam. Зведення доказів: VirusTotal 8/91 (ADMINUSLabs, Chong Lua Dao, Gridinsoft, Lionic, SafeToOpen); PhishDestroy score 84/100. Реєстратор: Abion AB.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain 135461223.site is currently listed as active and classified as a high‑risk Microsoft brand impersonation campaign. The site presents the page title “Nimblr Security Awareness” and is associated with a tech‑support scam. The domain was registered on 30 April 2020 through Abion AB and continues to resolve to the IPv4 address 116.203.212.240.
Infrastructure analysis shows the host is served by Nginx with HTTP Strict Transport Security enabled and protected by a Let’s Encrypt R12 certificate. The server resides in Germany and is announced by ASN 24940 (Hetzner Online GmbH). DNS resolution uses the authoritative name servers a.portsdns.se and b.portsdns.net, and the domain publishes an MX record pointing to mail.co-service.site with priority 10.
Reputation services assign extremely low trust scores: Gridinsoft reports 1/100 and Scamadviser also reports 1/100. VirusTotal records 14 of 95 security vendors flagging the domain, and AlienVault OTX lists the domain in 20 threat‑intelligence pulses. The domain is presently blocked by PhishDestroy and PhishingDB and appears on two additional blocklists.
Given the confirmed Microsoft impersonation, the active status, and the low trust metrics, defenders should block DNS resolution for 135461223.site, enforce TLS inspection to detect the HTTP 302 redirect, and monitor outbound connections to the associated IP and mail server. Incident response teams should also update email filtering rules to reject messages from mail.co-service.site and consider adding the observed name servers to threat‑intel watchlists.
Сигнали безпеки
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 2 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of 135461223.site · checked Mar 2, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога