MALICIOUS — HIGH
Перевірка домену auth-xserver.online на фішинг і безпеку
auth-xserver[.]
This site, auth-xserver.online, presents itself as a Plesk Obsidian 18.0.75 control panel interface.
- VirusTotal
- 6 detections
- Blocklists
- No stored match
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
auth-xserver.online — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 6 detections (engine total unavailable) (Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_PHISH; PhishDestroy score 68/100. Реєстратор: Go Daddy.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
This site, auth-xserver.online, presents itself as a Plesk Obsidian 18.0.75 control panel interface. It poses a threat as a phishing site designed to harvest login credentials from users expecting a legitimate Plesk server administration portal.
Technically, the domain was created on 2026-02-21 and is registered through Go Daddy, LLC. It resolves to IP address 188.114.96.3 (United States), hosted on AS13395 (Cloudflare, Inc.). The site has no SSL certificate. VirusTotal reports 6 out of 95 security vendors flagged it as malicious, with specific detections from Fortinet, Gridinsoft, and SOCRadar. It appears on 3 blocklists. The domain uses nameservers jose.ns.cloudflare.com and zainab.ns.cloudflare.com.
The site is currently offline and inaccessible. Gridinsoft assigns it a trust score of 0 out of 100. The overall risk level is high due to active detections, recent creation, and the explicit phishing nature of the Plesk login page.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Обсяг даних12 recorded checks
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.