allora-network[.]xyz
“Index of /”
allora-network.xyz — Неперевірений. Зведення доказів: VirusTotal 10/95 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); 1 external blocklist match (ScamSniffer); PhishDestroy score 80/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Allora-network.xyz was observed serving a web resource whose HTTP response returned the title “Index of /”, indicating an exposed directory listing rather than a dedicated landing page. The domain resolves to 95.214.235.117, an address owned by Virtual Systems LLC in Ukraine (AS30860). No TLS certificate is presented, meaning the site was only reachable over HTTP, which is typical for low‑effort phishing infrastructure. The registrar listed for the domain is NiceNIC International Group Co., Limited and the domain was created on 14 November 2025, less than a year before detection, a pattern consistent with fast‑flux or throwaway phishing sites.
Reputation services have flagged the domain: VirusTotal recorded detections by ten of ninety‑five scanners, PhishDestroy and ScamSniffer list it as blocked, and two additional blocklists contain the host. Gridinsoft assigned a trust score of 0 out of 100, reinforcing the malicious assessment. The authoritative name servers are ns13.v-sys.org and ns14.v-sys.org, both hosted by the same provider that supplies the hosting IP. The site’s current status is offline, but the historical evidence confirms that it was used for phishing activity.
Defenders should continue to deny any traffic to 95.214.235.117, add the domain and its IP to local deny lists, and monitor for re‑registration or similar aliases using the same name‑server pattern. Further investigation of request logs from the hosting provider may reveal additional malicious payloads or victim targets. At present, the lack of SSL, the directory‑listing page title, and the multiple vendor detections provide sufficient confidence to treat the domain as a confirmed phishing threat.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-13 02:53:02 UTC
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога