aimmaqket[.]com
“Моментальная продажа и покупка.”
Зведення доказів
This domain, aimmaqket.com, has been confirmed as a credential theft phishing site targeting users through deceptive login interfaces. Analysis indicates the site mimics legitimate authentication portals to harvest usernames, passwords, and session tokens. No specific brand impersonation or cryptocurrency drainer kit signatures were identified in available telemetry, though the credential harvesting methodology aligns with broader phishing campaigns observed in Q1 2024. The domain exhibits characteristics consistent with automated phishing infrastructure, including rapid deployment and short operational lifespans. Infrastructure analysis reveals the domain was registered on March 27, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. It resolves to the IP address 188.114.97.3, which has been linked to other transient phishing campaigns. Detection metrics show 4 out of 95 security vendors on VirusTotal flagged the domain as malicious, while AlienVault OTX recorded its presence in one threat intelligence pulse. The domain appears on a single security blocklist and is assigned a trust score of 0/100 by Gridinsoft. No detections were reported by Google Safe Browsing at the time of analysis, though this may reflect the domain's short-lived nature rather than benign intent. The domain is currently offline, likely taken down following detection or as part of the threat actor's operational cycle. However, the infrastructure remains a residual risk, as the registrar and hosting provider have not been confirmed to have implemented preventive measures against re-registration or IP reuse. Users who may have interacted with the domain are advised to revoke any active sessions, rotate credentials for potentially compromised accounts, and monitor for unauthorized access. Organizations should update blocklists to include the domain and associated IP, while security teams should investigate correlated indicators such as the registrar and hosting patterns for proactive threat hunting.
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260327-125986- Заголовок збереженої сторінки
- Моментальная продажа и покупка.
- PDF-файл
- PDF із доказами
Повний текст доказів
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Збережені докази результату
Результат і атрибуція блокування
- Результат
held- Доступність
unreachable- Причина
registrar_client_hold- Учасник
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Механізм
client_hold- Упевненість
- 95%
- Перше спостереження
- Останнє спостереження
Оцінка часу недоступності
Час до недоступності: 0 hSHA-256 доказу d48d239b9b2a
Хронологія виявлення
-
VirusTotal
7 → 4
-
Доступність
Перше збережене значення: DNS неактивний
f93a11f87e4d -
Доступність
DNS неактивний → Невідомо
b2db626922b1 -
Доступність
Невідомо → DNS неактивний
35b0c129775e -
Доступність
DNS неактивний → Утримується
983a4e6032be -
Доступність
Утримується → DNS неактивний
f52d526b76a1 -
Доступність
DNS неактивний → Невідомо
8a36329ed28d -
Доступність
Невідомо → Утримується
4559f5f9f739 -
Доступність
Утримується → Невідомо
17a99d0b89bd -
Доступність
Невідомо → DNS неактивний
6dfe9145995c
Показати всі (7)
-
Доступність
DNS неактивний → Утримується
a7b21148bf0b -
Доступність
Утримується → DNS неактивний
641ed81dc4d5 -
Доступність
DNS неактивний → Невідомо
b9ac7419dc8e -
Доступність
Невідомо → Утримується
78e585e028f5 -
Доступність
Утримується → Невідомо
79df09f1cf32 -
Доступність
Невідомо → DNS неактивний
d0b7046e8c2f -
Доступність
DNS неактивний → Утримується
d48d239b9b2a
Повідомлення спільноти
Повідомив 1 учасник спільноти; уперше помічено 27.03.2026
- Збережені повідомлення
- 1
- Унікальні URL
- 1
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of aimmaqket.com · checked Jun 26, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога