aimpowerment[.]com
Перевірка домену aimpowerment.com на фішинг і безпеку
“Plan, Save & Invest - AimPowerment”
aimpowerment.com — Останній відомий активний (HTTP 200). Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_SPAM; PhishDestroy score 80/100. Реєстратор: TuringSign.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain aimpowerment.com was registered on 23 April 2026 through the registrar TuringSign Inc. d/b/a Cosmotown. The public‑facing website presents a page titled “Plan, Save & Invest – AimPowerment”, which mimics financial planning services. HTTP requests to the site return status code 200, indicating the web server is actively serving content. Technical analysis shows that aimpowerment.com resolves to the IPv4 address 168.119.37.114, which geolocates to Germany and is hosted by Hetzner. The domain uses the authoritative name servers dns1.lytehosting.com through dns4.lytehosting.com. An active TLS certificate issued by Let’s Encrypt (R13) secures the site, confirming the presence of HTTPS. The registrar information and hosting details suggest a quickly provisioned infrastructure typical of short‑lived malicious campaigns. Open‑source intelligence indicates the domain appears on a single security blocklist and is actively blocked by PhishDestroy. AlienVault OTX references the domain in one threat‑intel pulse, linking it to credential‑harvesting activity. Despite the lack of detections on VirusTotal (0/95 scanners), the collective indicators classify the site as a generic phishing infrastructure and its status is marked as active and under investigation. Given the current evidence, defenders should treat aimpowerment.com as a high‑confidence phishing vector. Recommended mitigations include adding the domain and its associated IP address to outbound and inbound filtering rules, monitoring DNS queries for the listed LyteHosting name servers, and employing URL reputation services to block user access. Continuous re‑analysis is advised, as additional payloads or victim reports may emerge that could refine the risk assessment.
Сигнали безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога